Vulnerability index

Browse CVEs

87 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2025-53666 Jenkins Dead Man's Snitch Plugin 0.1 stores Dead Man's Snitch tokens unencrypted in job config.xml files on the Jenkins controller, where they can be… Dead Man\'s Snitch Mitigation only Fix from $1,6002025-07-09 MEDIUM 6.5 CVE-2025-53673 Jenkins Sensedia Api Platform tools Plugin 1.0 stores the Sensedia API Manager integration token unencrypted in its global configuration file on the … Sensedia Api Platform Tools Mitigation only Fix from $1,6002025-07-09 MEDIUM 5.3 CVE-2025-53667 Jenkins Dead Man's Snitch Plugin 0.1 does not mask Dead Man's Snitch tokens displayed on the job configuration form, increasing the potential for att… Dead Man\'s Snitch Mitigation only Fix from $1,6002025-07-09 MEDIUM 5.3 CVE-2025-53674 Jenkins Sensedia Api Platform tools Plugin 1.0 does not mask the Sensedia API Manager integration token on the global configuration form, increasing … Sensedia Api Platform Tools Mitigation only Fix from $1,6002025-07-09 MEDIUM 6.5 CVE-2024-9453 A vulnerability was found in Red Hat OpenShift Jenkins. The bearer token is not obfuscated in the logs and potentially carries a high risk if those l… Jenkins Mitigation only Fix from $1,6002025-07-04 CRITICAL 9.1 CVE-2025-32755 In jenkins/ssh-slave Docker images based on Debian, SSH host keys are generated on image creation for images based on Debian, causing all containers … Ssh Slave Mitigation only Fix from $2,3002025-04-10 MEDIUM 5.5 CVE-2025-31725 Jenkins monitor-remote-job Plugin 1.0 stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by user… Monitor Remote Job Mitigation only Fix from $1,6002025-04-02 MEDIUM 6.5 CVE-2025-30196 Jenkins AnchorChain Plugin 1.0 does not limit URL schemes for links it creates based on workspace content, allowing the `javascript:` scheme, resulti… Anchorchain Mitigation only Fix from $1,6002025-03-19 MEDIUM 5.3 CVE-2024-28161 In Jenkins Delphix Plugin 3.0.1, a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) … Delphix Mitigation only Fix from $1,6002024-03-06 HIGH 8.1 CVE-2023-50774 A cross-site request forgery (CSRF) vulnerability in Jenkins HTMLResource Plugin 1.02 and earlier allows attackers to delete arbitrary files on the J… Html Resource Mitigation only Fix from $1,9502023-12-13 MEDIUM 5.3 CVE-2023-46658 Jenkins MSTeams Webhook Trigger Plugin 0.1.1 and earlier uses a non-constant time comparison function when checking whether the provided and expected… Msteams Webhook Trigger Mitigation only Fix from $1,6002023-10-25 MEDIUM 6.5 CVE-2023-39152 Always-incorrect control flow implementation in Jenkins Gradle Plugin 2.8 may result in credentials not being masked (i.e., replaced with asterisks) … Gradle Mitigation only Fix from $1,6002023-07-26 CRITICAL 9.6 CVE-2023-27905 Jenkins update-center2 3.13 and 3.14 renders the required Jenkins core version on plugin download index pages without sanitization, resulting in a st… Update Center2 Mitigation only Fix from $2,3002023-03-10 MEDIUM 6.5 CVE-2023-24450 Jenkins view-cloner Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by… View Cloner Mitigation only Fix from $1,6002023-01-26 MEDIUM 6.5 CVE-2015-5298 The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are suppo… Google Login Mitigation only Fix from $1,6002022-07-07 MEDIUM 6.5 CVE-2022-34816 Jenkins HPE Network Virtualization Plugin 1.0 stores passwords unencrypted in its global configuration file on the Jenkins controller where they can … Hpe Network Virtualization Mitigation only Fix from $1,6002022-06-30 MEDIUM 5.4 CVE-2022-34784 Jenkins build-metrics Plugin 1.3 does not escape the build description on one of its views, resulting in a stored cross-site scripting (XSS) vulnerab… Build Metrics Mitigation only Fix from $1,6002022-06-30 MEDIUM 6.1 CVE-2022-34178 Jenkins Embeddable Build Status Plugin 2.0.3 allows specifying a 'link' query parameter that build status badges will link to, without restricting po… Embeddable Build Status Mitigation only Fix from $1,6002022-06-23 HIGH 7.5 CVE-2020-2232 Jenkins Email Extension Plugin 2.72 and 2.73 transmits and displays the SMTP password in plain text as part of the global Jenkins configuration form,… Email Extension Mitigation only Fix from $1,9502020-08-12 HIGH 8.8 CVE-2019-10448 Jenkins Extensive Testing Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with … Extensive Testing Mitigation only Fix from $1,9502019-10-16 MEDIUM 6.5 CVE-2019-1010241 Jenkins Credentials Binding Plugin Jenkins 1.17 is affected by: CWE-257: Storing Passwords in a Recoverable Format. The impact is: Authenticated user… Credentials Binding No fix yet Fix from $1,6002019-07-19 CRITICAL 9.3 CVE-2019-10309 Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not prevent XML External Entity p… Self Organizing Swarm Modules Mitigation only Fix from $2,3002019-04-30 HIGH 8.8 CVE-2019-10294 Jenkins Kmap Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read… Kmap Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10295 Jenkins crittercism-dsym Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with E… Crittercism Dsym Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10296 Jenkins Serena SRA Deploy Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by us… Serena Sra Deploy Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10297 Jenkins Sametime Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with … Sametime Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10298 Jenkins Koji Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with acce… Koji Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10299 Jenkins CloudCoreo DeployTime Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed b… Cloudcoreo Deploytime Mitigation only Fix from $1,9502019-04-04 MEDIUM 6.5 CVE-2019-10292 A cross-site request forgery vulnerability in Jenkins Kmap Plugin in KmapJenkinsBuilder.DescriptorImpl form validation methods allows attackers to in… Kmap Mitigation only Fix from $1,6002019-04-04 MEDIUM 6.5 CVE-2019-10293 A missing permission check in Jenkins Kmap Plugin in KmapJenkinsBuilder.DescriptorImpl form validation methods allows attackers with Overall/Read per… Kmap Mitigation only Fix from $1,6002019-04-04