2026 CVE Vulnerabilities

48,561 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-70611MEDIUM6.9Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9,...
CVE-2026-70610MEDIUM5.4Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9,...
CVE-2026-70609MEDIUM5.7Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7,...
CVE-2026-70608HIGH7.2Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10...
CVE-2026-70448HIGH7.1Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks...
CVE-2026-70447MEDIUM4.3Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Overall/Read permission ...
CVE-2026-70446MEDIUM4.3Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to ...
CVE-2026-70445MEDIUM4.3Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read permissio...
CVE-2026-70444MEDIUM4.3A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overa...
CVE-2026-70443MEDIUM4.3Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context for credentials looku...
CVE-2026-70442MEDIUM4.3Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate context for credenti...
CVE-2026-70441MEDIUM5.4Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pag...
CVE-2026-70440MEDIUM5.4Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-controlled field values in a...
CVE-2026-70439MEDIUM6.5Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers lacking appr...
CVE-2026-70438MEDIUM4.3A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers with Overal...
CVE-2026-70437LOW3.7Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison...
CVE-2026-70436MEDIUM4.3Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or p...
CVE-2026-70435MEDIUM4.2A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Overall/Read permissio...
CVE-2026-70434MEDIUM4.2A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers to c...
CVE-2026-70433MEDIUM4.3Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission t...
CVE-2026-70432HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows atta...
CVE-2026-70431HIGH8.8Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Sc...
CVE-2026-70430LOW2.7Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as pa...
CVE-2026-70429HIGH8.1Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistent...
CVE-2026-70428MEDIUM4.3Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file pa...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now