Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.8 CVE-2026-57289

CVE-2026-57289_CVE-2026-57289

Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connectio...

Jenkins Project Jenkins Bitbucket Push and Pull Request Plugin CVE
MEDIUM 4.3 CVE-2026-57287

CVE-2026-57287_CVE-2026-57287

Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secrets when displaying historica...

Jenkins Project Jenkins Job Configuration History Plugin CVE
MEDIUM 4.3 CVE-2026-57286

CVE-2026-57286_CVE-2026-57286

A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_ and earlier allows attackers with Item/Read permission to obtain info...

Jenkins Project Jenkins Git Parameter Plugin CVE
MEDIUM 4.3 CVE-2026-57285

CVE-2026-57285_CVE-2026-57285

A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v205fd594c821 and earlier allows attackers with Overall/Read permission...

Jenkins Project Jenkins GitHub Branch Source Plugin CVE
MEDIUM 4.3 CVE-2026-57284

CVE-2026-57284_CVE-2026-57284

Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through the Pipeline Snippet Ge...

Jenkins Project Jenkins Pipeline: Groovy Plugin CVE
MEDIUM 4.3 CVE-2026-57283

CVE-2026-57283_CVE-2026-57283

A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier allows attackers to instantiate...

Jenkins Project Jenkins Pipeline: Groovy Plugin CVE
MEDIUM 5 CVE-2026-57282

CVE-2026-57282_CVE-2026-57282

Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH wrapper...

Jenkins Project Jenkins Git client Plugin CVE
MEDIUM 4.6 CVE-2026-50699

Frappe Framework 17.0.0-dev – Stored XSS in Auto Repeat dashboard schedule rendering_CVE-2026-50699

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev. An authenticated attacker with write access to Aut...

Frappe Frappe Framework 17.0.0-dev CVE
MEDIUM 4.6 CVE-2026-50698

Frappe Framework 17.0.0-dev – Stored XSS in Audit Trail template rendering_CVE-2026-50698

A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled i...

Frappe Frappe Framework 17.0.0-dev CVE
MEDIUM 6.3 CVE-2026-11877

Missing Authorization Vulnerability in OpenText Access Manager_CVE-2026-11877

An unauthorized user can modify configuration through API calls that affects the OpenText Access Manager. This issue affects Access Manager before ...

OpenText Access Manager 5.1 CVE