2026 CVE Vulnerabilities

45,110 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-57294MEDIUM5.4A missing permission check in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers with Overal...
CVE-2026-57293MEDIUM4.3An incorrect permission check in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers with global Ite...
CVE-2026-57292MEDIUM5.4A cross-site request forgery (CSRF) vulnerability in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attac...
CVE-2026-57291MEDIUM5.4Missing permission checks in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allow attackers with Overall/Read pe...
CVE-2026-57290MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Priority Sorter Plugin 936.v2c01c6b_84449 and earlier allow...
CVE-2026-57289MEDIUM4.8Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostna...
CVE-2026-57287MEDIUM4.3Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secret...
CVE-2026-57286MEDIUM4.3A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_ and earlier allows attackers with Item/Rea...
CVE-2026-57285MEDIUM4.3A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v205fd594c821 and earlier allows attackers w...
CVE-2026-57284MEDIUM4.3Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated thro...
CVE-2026-57283MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier allo...
CVE-2026-57282MEDIUM5Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded i...
CVE-2026-56761MEDIUM4.3hono before 4.12.14 contains an html injection vulnerability in jsx server-side rendering that allows attackers to injec...
CVE-2026-56358MEDIUM5.4n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site sc...
CVE-2026-56338MEDIUM6.9Capgo before 12.128.2 contains a denial of service vulnerability in the /auth/v1/otp endpoint that prevents email verifi...
CVE-2026-56337MEDIUM5.3Capgo before 12.128.2 contains an information disclosure vulnerability in the public.exist_app_v2 RPC function that allo...
CVE-2026-56310MEDIUM5.3Cap-go before 12.128.2 contains an authorization bypass vulnerability in the GET /organization/members endpoint that all...
CVE-2026-56302MEDIUM6.9Capgo before 12.128.2 contains an unsecured images bucket lacking any row level security controls, allowing unauthentica...
CVE-2026-56272MEDIUM5.6Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instead of the OWASP-recom...
CVE-2026-56269MEDIUM4.6Flowise before 3.1.0 (npm package flowise, versions 3.0.13 and earlier) uses a weak hardcoded default value 'Secre$t' fo...
CVE-2026-56262MEDIUM6.5Crawl4AI before 0.8.7 contains an authentication bypass vulnerability in the monitor router endpoints that allows unauth...
CVE-2026-13163MEDIUM5.3Open redirect vulnerability (CWE-601) in the _safe_redirect function of the click-tracking endpoint (/c/<token>/) in Mai...
CVE-2026-13150MEDIUM6.9Server-Side Request Forgery (SSRF) (CWE-918) in the PDF generation endpoint GET /api/reports/{id}/pdf (backend/main.py) ...
CVE-2026-52944MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix FSCTL permission bypass by adding a perm...
CVE-2026-11968MEDIUM5.5Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary File Write in TortoiseGit

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now