|
71
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of cred…
New
|
CWE-269
Improper Privilege Management
|
CVE-2026-48926
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
72
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Integration Plugin 0.7.3 and earlier allows attackers to attackers to trigger a build for a pull request.
New
|
CWE-352
Origin Validation Error
|
CVE-2026-48925
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
73
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.
New
|
CWE-601
Open Redirect
|
CVE-2026-48924
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
74
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to connect to an attacker-spe…
New
|
CWE-269
Improper Privilege Management
|
CVE-2026-48923
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
75
|
8.8 |
HIGH
Network
|
-
|
-
|
Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image URLs that c…
New
|
CWE-73
External Control of File Name or Path
|
CVE-2026-48920
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
76
|
6.6 |
MEDIUM
Network
|
-
|
-
|
Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-48919
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
77
|
6.6 |
MEDIUM
Network
|
-
|
-
|
Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default.
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-48918
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
78
|
6.6 |
MEDIUM
Network
|
-
|
-
|
Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals.
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-48916
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
79
|
6.8 |
MEDIUM
Network
|
-
|
-
|
Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Space session fixation by exploiting a shared module-level HTTP client used across…
New
|
CWE-384
Session Fixation
|
CVE-2026-48545
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
80
|
- |
|
-
|
-
|
Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available…
New
|
CWE-506
Embedded Malicious Code
|
CVE-2026-48027
|
2026-05-28 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|