|
551
|
8.8 |
HIGH
Network
|
dell
|
wyse_management_suite
|
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker …
New
|
CWE-89
SQL Injection
|
CVE-2026-44272
|
2026-06-27 04:13 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
552
|
4.4 |
MEDIUM
Local
|
dell
|
wyse_management_suite
|
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use of Default Credentials vulnerability. A high privileged attacker with local access could potentially exploit this vulnerabi…
New
|
CWE-1392
Use of Default Credentials
|
CVE-2026-44273
|
2026-06-27 04:13 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
553
|
4.3 |
MEDIUM
Network
|
jenkins
|
git_parameter
|
A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_ and earlier allows attackers with Item/Read permission to obtain information about the SCM repository used by a job, such…
New
|
CWE-862
Missing Authorization
|
CVE-2026-57286
|
2026-06-27 04:09 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
554
|
4.3 |
MEDIUM
Network
|
jenkins
|
job_configuration_history
|
Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secrets when displaying historical job and agent configurations, allowing attackers w…
New
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2026-57287
|
2026-06-27 04:09 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
555
|
3.7 |
LOW
Network
|
jenkins
|
active_directory
|
Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI) authentication path, allowing unauthenticated atta…
New
|
CWE-90
LDAP Injection
|
CVE-2026-57288
|
2026-06-27 04:08 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
556
|
4.3 |
MEDIUM
Network
|
jenkins
|
priority_sorter
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Priority Sorter Plugin 936.v2c01c6b_84449 and earlier allows attackers to overwrite the global job priority configuration.
New
|
CWE-352
Origin Validation Error
|
CVE-2026-57290
|
2026-06-27 04:08 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
557
|
5.4 |
MEDIUM
Network
|
jenkins
|
ec2_fleet
|
A missing permission check in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specif…
New
|
CWE-862
Missing Authorization
|
CVE-2026-57294
|
2026-06-27 04:07 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
558
|
5.4 |
MEDIUM
Network
|
jenkins
|
ec2_fleet
|
A cross-site request forgery (CSRF) vulnerability in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified cr…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-57295
|
2026-06-27 04:06 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
559
|
4.3 |
MEDIUM
Network
|
jenkins
|
mcp_server
|
A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier allows attackers with Item/Read permission to read the Pipeline replay scripts of jobs they can access.
New
|
CWE-862
Missing Authorization
|
CVE-2026-57300
|
2026-06-27 04:06 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
560
|
8.8 |
HIGH
Network
|
jenkins
|
official_owasp_zap
|
Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attackers with Item/Configure permission to execute arbitrary c…
New
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2026-57301
|
2026-06-27 04:06 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|