Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2026-44020

Docling: Unsafe XML Entity Expansion in USPTO Patent Backend_CVE-2026-44020

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.13.0 until 2....

docling-project docling >= 2.13.0, < 2.74.0 CVE
HIGH 7.5 CVE-2026-44017

Docling: Unsafe Zip Extraction in EasyOCR Model Download_CVE-2026-44017

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.91.0, the...

docling-project docling < 2.91.0 CVE
HIGH 8.2 CVE-2026-44016

Docling: Unsafe Playwright-based HTML Rendering_CVE-2026-44016

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. FIn versions >= 2.82...

docling-project docling >= 2.82.0, < 2.91.0 CVE
HIGH 7.6 CVE-2025-71361

picklescan – Remote Code Execution via Undetected idlelib.calltip.Calltip.fetch_tip_CVE-2025-71361

picklescan before 0.0.29 fails to detect malicious idlelib.calltip.Calltip.fetch_tip calls in pickle files, allowing remote code execution. Attacke...

picklescan picklescan CVE
MEDIUM 4.2 CVE-2026-57307

CVE-2026-57307_CVE-2026-57307

A missing permission check in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier allows attackers with Overall/Read permission to con...

Jenkins Project Jenkins Zowe zDevOps Plugin CVE
MEDIUM 4.2 CVE-2026-57306

CVE-2026-57306_CVE-2026-57306

A cross-site request forgery (CSRF) vulnerability in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier allows attackers to connect t...

Jenkins Project Jenkins Zowe zDevOps Plugin CVE
MEDIUM 5.4 CVE-2026-57305

CVE-2026-57305_CVE-2026-57305

A cross-site request forgery (CSRF) vulnerability in Jenkins Assembla Plugin 1.4 and earlier allows attackers to connect to an attacker-specified U...

Jenkins Project Jenkins Assembla Plugin CVE
MEDIUM 5.4 CVE-2026-57304

CVE-2026-57304_CVE-2026-57304

A missing permission check in Jenkins Assembla Plugin 1.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-speci...

Jenkins Project Jenkins Assembla Plugin CVE
HIGH 7.1 CVE-2026-57303

CVE-2026-57303_CVE-2026-57303

Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers able to ...

Jenkins Project Jenkins Assembla Plugin CVE
MEDIUM 4.3 CVE-2026-57302

CVE-2026-57302_CVE-2026-57302

Jenkins FitNesse Plugin 1.36 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed b...

Jenkins Project Jenkins FitNesse Plugin 1.36 CVE