Total
397465 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-70446 | 2026-08-31 | N/A | 4.3 MEDIUM | ||
| Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |||||
| CVE-2026-70432 | 2026-08-31 | N/A | 8.8 HIGH | ||
| A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute arbitrary code in the context of the Jenkins controller JVM. | |||||
| CVE-2026-70448 | 2026-08-31 | N/A | 7.1 HIGH | ||
| Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when processing Ivy report files. | |||||
| CVE-2026-70447 | 2026-08-31 | N/A | 4.3 MEDIUM | ||
| Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |||||
| CVE-2026-70431 | 2026-08-31 | N/A | 8.8 HIGH | ||
| Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugin, allowing attackers with Item/Create or Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM. | |||||
| CVE-2026-70442 | 2026-08-31 | N/A | 4.3 MEDIUM | ||
| Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to use. | |||||
| CVE-2026-70426 | 2026-08-31 | N/A | 9.0 CRITICAL | ||
| In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserialization implementation, allowing agent processes, code running on agents, and attackers with Agent/Connect permission to bypass the JEP-200 deserialization filter for classes on the Jenkins core classpath. | |||||
| CVE-2026-18064 | 2026-08-31 | N/A | 7.5 HIGH | ||
| An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause the HS application to crash, resulting in a denial-of-service condition and processor reset. | |||||
| CVE-2026-67973 | 2026-08-31 | N/A | 7.5 HIGH | ||
| An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs. | |||||
| CVE-2026-67979 | 2026-08-31 | N/A | 9.1 CRITICAL | ||
| Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shared object on target storage. | |||||
| CVE-2026-67978 | 2026-08-31 | N/A | 7.5 HIGH | ||
| An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN frame. | |||||
| CVE-2026-67975 | 2026-08-31 | N/A | 7.5 HIGH | ||
| Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/remove subscription commands. | |||||
| CVE-2026-67970 | 2026-08-31 | N/A | 7.5 HIGH | ||
| Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal. | |||||
| CVE-2026-67969 | 2026-08-31 | N/A | 7.5 HIGH | ||
| An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a crafted HS.AppMon_Tbl entry. | |||||
| CVE-2026-67974 | 2026-08-31 | N/A | 7.5 HIGH | ||
| A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via sending a crafted packet. | |||||
| CVE-2026-67972 | 2026-08-31 | N/A | 7.5 HIGH | ||
| An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attackers to contrl where received content and data is stored, possibly leading to an information disclosure. | |||||
| CVE-2026-67869 | 2026-08-31 | N/A | 7.5 HIGH | ||
| Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata | |||||
| CVE-2025-59323 | 2026-08-31 | N/A | 8.4 HIGH | ||
| CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partitioned filesystem, responsible for storing configuration and cryptographic details. Crafted DataStore contents can impact service availability and/or allow for code execution in the context of high privilege. | |||||
| CVE-2026-67976 | 2026-08-31 | N/A | 7.5 HIGH | ||
| The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allowing attackers to cause a Denial of Service (DoS) via inputting unsafe parameters. | |||||
| CVE-2026-67871 | 2026-08-31 | N/A | 7.5 HIGH | ||
| Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the AddNodes, address_space_bs.c, sopc_node_mgt_helper_internal.c, and toolkit_test_server | |||||
