0.0

CVE-2026-7111 - Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend t…

Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption. The Parse, print, getline, and getline_all methods invoke registered callbacks (for example after_parse, before_print, or…

πŸ“… Published: April 29, 2026, 2:22 p.m. πŸ”„ Last Modified: April 29, 2026, 2:22 p.m.

8.8

CVSS3.1

CVE-2026-5141 - Improper Access Control in TUBITAK BILGEM's Pardus Software Center

Improper Privilege Management, Improper Access Control, Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software Center allows Hijacking a privileged process. This issue affects Pardus Software Center: before 1.0.3.

πŸ“… Published: April 29, 2026, 2:18 p.m. πŸ”„ Last Modified: April 29, 2026, 2:18 p.m.

7.8

CVSS3.0

CVE-2026-41220 -

Local privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.93212, Acronis Cyber Protect Cloud Agent (Windows) before build 42183.

πŸ“… Published: April 29, 2026, 1:43 p.m. πŸ”„ Last Modified: April 29, 2026, 1:43 p.m.

7.8

CVSS3.0

CVE-2026-41952 -

Local privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.93212, Acronis Cyber Protect Cloud Agent (Windows) before build 42183.

πŸ“… Published: April 29, 2026, 1:42 p.m. πŸ”„ Last Modified: April 29, 2026, 1:42 p.m.

6.7

CVSS3.0

CVE-2026-25852 -

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.93212.

πŸ“… Published: April 29, 2026, 1:42 p.m. πŸ”„ Last Modified: April 29, 2026, 1:42 p.m.

4.3

CVSS3.1

CVE-2026-42525 -

Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

πŸ“… Published: April 29, 2026, 1:31 p.m. πŸ”„ Last Modified: April 29, 2026, 2:08 p.m.

0.0

CVE-2026-42524 -

Jenkins HTML Publisher Plugin 427 and earlier does not escape job name and URL in the legacy wrapper file, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

πŸ“… Published: April 29, 2026, 1:31 p.m. πŸ”„ Last Modified: April 29, 2026, 1:31 p.m.

0.0

CVE-2026-42523 -

Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITScm polling", resulting in a stored cross-site scripting (XSS) vulnerability exploitable by non-anonymous attackers with Overall…

πŸ“… Published: April 29, 2026, 1:31 p.m. πŸ”„ Last Modified: April 29, 2026, 1:31 p.m.

0.0

CVE-2026-42522 -

A missing permission check in Jenkins GitHub Branch Source Plugin 1967.vdea_d580c1a_b_a_ and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL with attacker-specified GitHub App credentials.

πŸ“… Published: April 29, 2026, 1:31 p.m. πŸ”„ Last Modified: April 29, 2026, 1:31 p.m.

6.5

CVSS3.1

CVE-2026-42521 -

Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructors of classes specified in configuration when deserializing inheritance strategies, without restricting the classes that can be instantiated, allowing attackers with Item/Configure…

πŸ“… Published: April 29, 2026, 1:31 p.m. πŸ”„ Last Modified: April 29, 2026, 1:58 p.m.
Total resulsts: 347252
Page 15 of 34,726
Β« previous page Β» next page
Filters