Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Official Owasp Zap HIGH 8.8
CVE-2026-57301

Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attackers wit…

Fix: after 1.0.7
Fix from $1,950 2026-06-24
Assembla HIGH 7.1
CVE-2026-57303

Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers able to co…

Fix: after 1.4
Fix from $1,950 2026-06-24
Assembla MEDIUM 5.4
CVE-2026-57304

A missing permission check in Jenkins Assembla Plugin 1.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specifi…

Fix: after 1.4
Fix from $1,600 2026-06-24
Assembla MEDIUM 5.4
CVE-2026-57305

A cross-site request forgery (CSRF) vulnerability in Jenkins Assembla Plugin 1.4 and earlier allows attackers to connect to an attacker-specified URL…

Fix: after 1.4
Fix from $1,600 2026-06-24
Ec2 Fleet MEDIUM 5.4
CVE-2026-57294

A missing permission check in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers with Overall/Read permission to connect …

Fix: after 4.2.3.539.v8fedff2a_81c3
Fix from $1,600 2026-06-24
Ec2 Fleet MEDIUM 5.4
CVE-2026-57295

A cross-site request forgery (CSRF) vulnerability in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers to connect to an …

Fix: after 4.2.3.539.v8fedff2a_81c3
Fix from $1,600 2026-06-24
Script Security HIGH 7.5
CVE-2026-57281

Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, al…

Fix: after 1402.v94c9ce464861
Fix from $1,950 2026-06-24
Git Client MEDIUM 5.0
CVE-2026-57282

Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH wrapper s…

Fix: 6.6.1+
Fix from $1,600 2026-06-24
Script Security HIGH 8.8
CVE-2026-57280

Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each lo…

Fix: after 1402.v94c9ce464861
Fix from $1,950 2026-06-24
Jenkins MEDIUM 5.4
CVE-2026-53441

Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of a generic…

Fix: 2.555.3 / 2.568+
Fix from $1,600 2026-06-10
Jenkins MEDIUM 5.3
CVE-2026-53442

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before storing them in job configuration…

Fix: 2.555.3 / 2.568+
Fix from $1,600 2026-06-10
Jenkins HIGH 8.8
CVE-2026-53435EPSS 19%

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins co…

Fix: 2.555.3 / 2.568+
Fix from $1,950 2026-06-10
Buildgraph View MEDIUM 5.5
CVE-2026-48927

Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting (XSS) vulnerability exploita…

Fix: after 1.8
Fix from $1,600 2026-05-27
Email Extension HIGH 8.8
CVE-2026-48920

Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attrib…

Fix: after 1925.v1598902b_58dd
Fix from $1,950 2026-05-27
Pipeline\ HIGH 7.5
CVE-2026-48921

Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers …

Fix: 798.v5cc688825312+
Fix from $1,950 2026-05-27
Credentials Binding HIGH 7.5
CVE-2026-48922

Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file and zip file credentials, allowing a…

Fix: 725.ve52b_2328a_fde+
Fix from $1,950 2026-05-27
Ldap MEDIUM 6.6
CVE-2026-48916

Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals.

Fix: after 793.v754d6b_41b_ea_4
Fix from $1,600 2026-05-27
Ldap MEDIUM 6.6
CVE-2026-48917

Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation.

Fix: after 793.v754d6b_41b_ea_4
Fix from $1,600 2026-05-27
Active Directory MEDIUM 6.6
CVE-2026-48918

Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default.

Fix: after 2.41
Fix from $1,600 2026-05-27
Active Directory MEDIUM 6.6
CVE-2026-48919

Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.

Fix: after 2.41
Fix from $1,600 2026-05-27
GitHub CRITICAL 9.0
CVE-2026-42523

Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHu…

Fix: 1.46.0.1+
Fix from $2,300 2026-04-29
Html Publisher HIGH 8.0
CVE-2026-42524

Jenkins HTML Publisher Plugin 427 and earlier does not escape job name and URL in the legacy wrapper file, resulting in a stored cross-site scripting…

Fix: after 427
Fix from $1,950 2026-04-29
Credentials Binding HIGH 7.5
CVE-2026-42520

Jenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanitize file names for file and zip file credentials, allowing attackers …

Fix: after 719.v80e905ef14eb
Fix from $1,950 2026-04-29
Matrix Authorization Strategy MEDIUM 6.5
CVE-2026-42521

Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructors of classes specified in con…

Fix: 3.2.10+
Fix from $1,600 2026-04-29
Jenkins HIGH 8.8
CVE-2026-33001

Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing…

Fix: 2.541.3 / 2.555+
Fix from $1,950 2026-03-18
Jenkins HIGH 7.5
CVE-2026-33002

Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made through th…

Fix: 2.541.3 / 2.555+
Fix from $1,950 2026-03-18
Jenkins HIGH 8.0
CVE-2026-27099

Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of the "Mark…

Fix: 2.541.2 / 2.551+
Fix from $1,950 2026-02-18
Coverage MEDIUM 5.4
CVE-2025-67641

Jenkins Coverage Plugin 2.3054.ve1ff7b_a_a_123b_ and earlier does not validate the configured coverage results ID when creating coverage results, onl…

Fix: after 2.3054.ve1ff7b_a_a_123b
Fix from $1,600 2025-12-10
Git Client MEDIUM 5.0
CVE-2025-67640

Jenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the path to the workspace directory as part of an argument in a temporary s…

Fix: 6.4.1+
Fix from $1,600 2025-12-10
Jenkins HIGH 7.5
CVE-2025-67635

Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connection stream becomes corrupted, a…

Fix: 2.528.3 / 2.541+
Fix from $1,950 2025-12-10