CVE Vulnerability Database
Search and browse 397,857 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9712 | LOW | 3.8 | 0.2% | May 27, 2026 | When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, ra... |
| CVE-2026-9674 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 662.vd2e0001f6b_b_d and earlier allows atta... |
| CVE-2026-6957 | MEDIUM | 4.9 | 0.3% | May 27, 2026 | Mattermost Plugins versions <=1.1.5 fail to sanitize filenames received from federated peers before using them to constr... |
| CVE-2026-49103 | CRITICAL | 9.4 | 0.3% | May 27, 2026 | Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. Thi... |
| CVE-2026-49102 | MEDIUM | 6.1 | 0.2% | May 27, 2026 | Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes compo... |
| CVE-2026-49059 | MEDIUM | 4.7 | 0.2% | May 27, 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Facebook Facebook for WooCommerce allows Phishing. ... |
| CVE-2026-49053 | MEDIUM | 5.3 | 0.2% | May 27, 2026 | Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured ... |
| CVE-2026-49052 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured ... |
| CVE-2026-49051 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | Missing Authorization vulnerability in Prasad Kirpekar WP Meta and Date Remover allows Exploiting Incorrectly Configured... |
| CVE-2026-49047 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | Missing Authorization vulnerability in DearHive DearFlip allows Exploiting Incorrectly Configured Access Control Securit... |
| CVE-2026-49046 | HIGH | 8.5 | 0.3% | May 27, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arjun Thakur Dupli... |
| CVE-2026-49045 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | Missing Authorization vulnerability in WP Media Adminimize allows Exploiting Incorrectly Configured Access Control Secur... |
| CVE-2026-49044 | MEDIUM | 6.5 | 0.2% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Kruit Advan... |
| CVE-2026-48973 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | Missing Authorization vulnerability in Benbodhi SVG Support allows Exploiting Incorrectly Configured Access Control Secu... |
| CVE-2026-48927 | MEDIUM | 5.5 | 0.2% | May 27, 2026 | Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting... |
| CVE-2026-48926 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint, allow... |
| CVE-2026-48925 | MEDIUM | 4.3 | 0.1% | May 27, 2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Integration Plugin 0.7.3 and earlier allows attacker... |
| CVE-2026-48924 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to pe... |
| CVE-2026-48923 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation... |
| CVE-2026-48922 | HIGH | 7.5 | 0.4% | May 27, 2026 | Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file and zip... |
| CVE-2026-48921 | HIGH | 7.5 | 0.3% | May 27, 2026 | Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared l... |
| CVE-2026-48920 | HIGH | 8.8 | 0.3% | May 27, 2026 | Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by set... |
| CVE-2026-48919 | MEDIUM | 6.6 | 0.3% | May 27, 2026 | Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation. |
| CVE-2026-48918 | MEDIUM | 6.6 | 0.2% | May 27, 2026 | Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default. |
| CVE-2026-48917 | MEDIUM | 6.6 | 0.3% | May 27, 2026 | Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation. |
