2026 CVE Vulnerabilities
45,110 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-57294 | MEDIUM | 5.4 | 0.1% | Jun 24, 2026 | A missing permission check in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers with Overal... |
| CVE-2026-57293 | MEDIUM | 4.3 | 0.2% | Jun 24, 2026 | An incorrect permission check in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers with global Ite... |
| CVE-2026-57292 | MEDIUM | 5.4 | 0.1% | Jun 24, 2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attac... |
| CVE-2026-57291 | MEDIUM | 5.4 | 0.1% | Jun 24, 2026 | Missing permission checks in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allow attackers with Overall/Read pe... |
| CVE-2026-57290 | MEDIUM | 4.3 | 0.1% | Jun 24, 2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Priority Sorter Plugin 936.v2c01c6b_84449 and earlier allow... |
| CVE-2026-57289 | MEDIUM | 4.8 | 0.1% | Jun 24, 2026 | Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostna... |
| CVE-2026-57287 | MEDIUM | 4.3 | 0.1% | Jun 24, 2026 | Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secret... |
| CVE-2026-57286 | MEDIUM | 4.3 | 0.2% | Jun 24, 2026 | A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_ and earlier allows attackers with Item/Rea... |
| CVE-2026-57285 | MEDIUM | 4.3 | 0.2% | Jun 24, 2026 | A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v205fd594c821 and earlier allows attackers w... |
| CVE-2026-57284 | MEDIUM | 4.3 | 0.2% | Jun 24, 2026 | Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated thro... |
| CVE-2026-57283 | MEDIUM | 4.3 | 0.1% | Jun 24, 2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier allo... |
| CVE-2026-57282 | MEDIUM | 5 | 0.2% | Jun 24, 2026 | Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded i... |
| CVE-2026-56761 | MEDIUM | 4.3 | 0.2% | Jun 24, 2026 | hono before 4.12.14 contains an html injection vulnerability in jsx server-side rendering that allows attackers to injec... |
| CVE-2026-56358 | MEDIUM | 5.4 | 0.1% | Jun 24, 2026 | n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site sc... |
| CVE-2026-56338 | MEDIUM | 6.9 | 0.3% | Jun 24, 2026 | Capgo before 12.128.2 contains a denial of service vulnerability in the /auth/v1/otp endpoint that prevents email verifi... |
| CVE-2026-56337 | MEDIUM | 5.3 | 0.3% | Jun 24, 2026 | Capgo before 12.128.2 contains an information disclosure vulnerability in the public.exist_app_v2 RPC function that allo... |
| CVE-2026-56310 | MEDIUM | 5.3 | 0.2% | Jun 24, 2026 | Cap-go before 12.128.2 contains an authorization bypass vulnerability in the GET /organization/members endpoint that all... |
| CVE-2026-56302 | MEDIUM | 6.9 | 0.2% | Jun 24, 2026 | Capgo before 12.128.2 contains an unsecured images bucket lacking any row level security controls, allowing unauthentica... |
| CVE-2026-56272 | MEDIUM | 5.6 | 0.1% | Jun 24, 2026 | Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instead of the OWASP-recom... |
| CVE-2026-56269 | MEDIUM | 4.6 | 0.1% | Jun 24, 2026 | Flowise before 3.1.0 (npm package flowise, versions 3.0.13 and earlier) uses a weak hardcoded default value 'Secre$t' fo... |
| CVE-2026-56262 | MEDIUM | 6.5 | 0.4% | Jun 24, 2026 | Crawl4AI before 0.8.7 contains an authentication bypass vulnerability in the monitor router endpoints that allows unauth... |
| CVE-2026-13163 | MEDIUM | 5.3 | 0.3% | Jun 24, 2026 | Open redirect vulnerability (CWE-601) in the _safe_redirect function of the click-tracking endpoint (/c/<token>/) in Mai... |
| CVE-2026-13150 | MEDIUM | 6.9 | 0.3% | Jun 24, 2026 | Server-Side Request Forgery (SSRF) (CWE-918) in the PDF generation endpoint GET /api/reports/{id}/pdf (backend/main.py) ... |
| CVE-2026-52944 | MEDIUM | 5.5 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix FSCTL permission bypass by adding a perm... |
| CVE-2026-11968 | MEDIUM | 5.5 | 0.1% | Jun 24, 2026 | Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary File Write in TortoiseGit |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now