CVE Vulnerability Database

Search and browse 397,857 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-9712LOW3.8When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, ra...
CVE-2026-9674MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 662.vd2e0001f6b_b_d and earlier allows atta...
CVE-2026-6957MEDIUM4.9Mattermost Plugins versions <=1.1.5 fail to sanitize filenames received from federated peers before using them to constr...
CVE-2026-49103CRITICAL9.4Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. Thi...
CVE-2026-49102MEDIUM6.1Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes compo...
CVE-2026-49059MEDIUM4.7URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Facebook Facebook for WooCommerce allows Phishing. ...
CVE-2026-49053MEDIUM5.3Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured ...
CVE-2026-49052MEDIUM4.3Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured ...
CVE-2026-49051MEDIUM4.3Missing Authorization vulnerability in Prasad Kirpekar WP Meta and Date Remover allows Exploiting Incorrectly Configured...
CVE-2026-49047MEDIUM4.3Missing Authorization vulnerability in DearHive DearFlip allows Exploiting Incorrectly Configured Access Control Securit...
CVE-2026-49046HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arjun Thakur Dupli...
CVE-2026-49045MEDIUM4.3Missing Authorization vulnerability in WP Media Adminimize allows Exploiting Incorrectly Configured Access Control Secur...
CVE-2026-49044MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Kruit Advan...
CVE-2026-48973MEDIUM4.3Missing Authorization vulnerability in Benbodhi SVG Support allows Exploiting Incorrectly Configured Access Control Secu...
CVE-2026-48927MEDIUM5.5Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting...
CVE-2026-48926MEDIUM4.3Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint, allow...
CVE-2026-48925MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Integration Plugin 0.7.3 and earlier allows attacker...
CVE-2026-48924MEDIUM4.3Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to pe...
CVE-2026-48923MEDIUM4.3Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation...
CVE-2026-48922HIGH7.5Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file and zip...
CVE-2026-48921HIGH7.5Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared l...
CVE-2026-48920HIGH8.8Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by set...
CVE-2026-48919MEDIUM6.6Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.
CVE-2026-48918MEDIUM6.6Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default.
CVE-2026-48917MEDIUM6.6Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation.