Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.6 CVE-2025-71361

picklescan – Remote Code Execution via Undetected idlelib.calltip.Calltip.fetch_tip_CVE-2025-71361

picklescan before 0.0.29 fails to detect malicious idlelib.calltip.Calltip.fetch_tip calls in pickle files, allowing remote code execution. Attacke...

picklescan picklescan CVE
HIGH 7.1 CVE-2026-57303

CVE-2026-57303_CVE-2026-57303

Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers able to ...

Jenkins Project Jenkins Assembla Plugin CVE
HIGH 8.8 CVE-2026-57301

CVE-2026-57301_CVE-2026-57301

Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attackers w...

Jenkins Project Jenkins OWASP ZAP Plugin 1.0.7 CVE
HIGH 8.8 CVE-2026-57296

CVE-2026-57296_CVE-2026-57296

Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided to the e...

Jenkins Project Jenkins External Workspace Manager Plugin 1.3.2 CVE
HIGH 7.5 CVE-2026-57281

CVE-2026-57281_CVE-2026-57281

Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, ...

Jenkins Project Jenkins Script Security Plugin CVE
HIGH 8.8 CVE-2026-57280

CVE-2026-57280_CVE-2026-57280

Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each ...

Jenkins Project Jenkins Script Security Plugin CVE
HIGH 7.3 CVE-2026-12986

CVE-2026-12986_CVE-2026-12986

A critical vulnerability in Admin GUI in Payara Server Full 4.x, 5.x, 6.x, 7.x, 7.2026.x, 6.2025.x, 6.2024.x on All platforms that allows the attac...

Payara Payara Server 7.2025.1 CVE
HIGH 8.2 CVE-2026-11878

Reflected Cross-Site Scripting vulnerability in OpenText Access Manager_CVE-2026-11878

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Manager allows Cross-Site Scr...

OpenText Access Manager 5.1 CVE
HIGH 8.3 CVE-2026-56111

Marlin Firmware 2.1.2.7 Out-of-Bounds Write via M421 G-code Handler_CVE-2026-56111

Marlin Firmware through 2.1.2.7, fixed in commit 1f255d1, when built with MESH_BED_LEVELING enabled, contains an out-of-bounds write vulnerability ...

MarlinFirmware Marlin CVE
HIGH 7.7 CVE-2026-55488

motionEye’s Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read_CVE-2026-55488

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Versi...

motioneye-project motioneye < 0.44.0 CVE