2026 CVE Vulnerabilities
65,063 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84676 | MEDIUM | 4.3 | 0.1% | Sep 2, 2026 | Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml files on the J... |
| CVE-2026-84674 | MEDIUM | 5.4 | 0.1% | Sep 2, 2026 | Missing permission checks in Jenkins XebiaLabs XL Deploy Plugin 26.1.0 and earlier allow attackers with Overall/Read per... |
| CVE-2026-84666 | MEDIUM | 5.4 | 0.1% | Sep 2, 2026 | Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier allows overwriting the plugin's history record... |
| CVE-2026-84664 | MEDIUM | 5.4 | 0.1% | Sep 2, 2026 | Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global GitLab connection configuration through Stapler d... |
| CVE-2026-84663 | MEDIUM | 5.4 | 0.1% | Sep 2, 2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 798.v5cc688825312 and ear... |
| CVE-2026-84662 | MEDIUM | 4.3 | 0.2% | Sep 2, 2026 | Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allows connecting to a specified URL through Stapler data binding... |
| CVE-2026-84661 | MEDIUM | 5.4 | 0.2% | Sep 2, 2026 | A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes downstream bui... |
| CVE-2026-84660 | MEDIUM | 5.4 | 0.2% | Sep 2, 2026 | A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes downstream bui... |
| CVE-2026-84659 | MEDIUM | 4.3 | 0.2% | Sep 2, 2026 | Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enforce a permission check in the method that co... |
| CVE-2026-84658 | MEDIUM | 4.3 | 0.2% | Sep 2, 2026 | Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@DataBoundConstructor` annotation on a construc... |
| CVE-2026-84657 | MEDIUM | 4.2 | 0.2% | Sep 2, 2026 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission w... |
| CVE-2026-84656 | MEDIUM | 4.3 | 0.2% | Sep 2, 2026 | A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attackers with Item/Read permiss... |
| CVE-2026-84655 | MEDIUM | 4.3 | 0.2% | Sep 2, 2026 | Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python ... |
| CVE-2026-84654 | MEDIUM | 5.4 | 0.2% | Sep 2, 2026 | In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS ... |
| CVE-2026-84651 | MEDIUM | 6.3 | 0.2% | Sep 2, 2026 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for updating agent configuration d... |
| CVE-2026-84646 | MEDIUM | 4.3 | 0.2% | Sep 2, 2026 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deseriali... |
| CVE-2026-53600 | MEDIUM | 6.3 | 0.3% | Sep 2, 2026 | async-tar is a tar archive reading/writing library for async Rust. Prior to version 0.6.1, async-tar mis-applies a buffe... |
| CVE-2026-19475 | MEDIUM | 6.5 | 0.4% | Sep 2, 2026 | An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the ... |
| CVE-2026-12704 | MEDIUM | 6.8 | 0.3% | Sep 2, 2026 | When SAML IdP-initiated login is enabled in Grafana Enterprise, the SAML library skips validation of the InResponseTo fi... |
| CVE-2026-8151 | MEDIUM | 5.4 | 0.1% | Sep 2, 2026 | The Simple Membership MailChimp Integration WordPress plugin before 1.9.8 does not have CSRF checks in its settings page... |
| CVE-2026-83547 | MEDIUM | 6.8 | 0.2% | Sep 2, 2026 | The Xpro Addons WordPress plugin before 1.7.4 does not properly escape some of its widgets' settings before outputting t... |
| CVE-2026-83533 | MEDIUM | 5.3 | 0.1% | Sep 2, 2026 | The WP Express Checkout WordPress plugin before 2.4.9 does not verify server-side that a payment was actually completed ... |
| CVE-2026-82884 | MEDIUM | 6.8 | 0.2% | Sep 2, 2026 | The All in One SEO WordPress plugin before 5.0.0.1 does not sanitise and escape some content stored in posts before rend... |
| CVE-2026-82293 | MEDIUM | 4.3 | 0.2% | Sep 2, 2026 | Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption v... |
| CVE-2026-81571 | MEDIUM | 4.8 | 0.2% | Sep 2, 2026 | The Brave WordPress plugin before 0.8.8 does not prevent a URL parameter used to pre-fill a form field from being passed... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now