Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2022-41246
A missing permission check in Jenkins Worksoft Execution Manager Plugin 10.0.3.503 and earlier allows attackers with Overall/Read permission to conne…
Worksoft Execution Manager
after 10.0.3.503
MEDIUM 6.5
CVE-2022-41250
A missing permission check in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-s…
Scm Httpclient
after 1.5
MEDIUM 6.5
CVE-2022-41254
Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allow attackers with Overall/Read permission to connect to an attacker-specifie…
Cons3rt
after 1.0.0
MEDIUM 6.5
CVE-2022-41255
Jenkins CONS3RT Plugin 1.0.0 and earlier stores Cons3rt API token unencrypted in job config.xml files on the Jenkins controller where it can be viewe…
Cons3rt
after 1.0.0
MEDIUM 5.3
CVE-2022-41248
Jenkins BigPanda Notifier Plugin 1.4.0 and earlier does not mask the BigPanda API key on the global configuration form, increasing the potential for …
Bigpanda Notifier
after 1.4.0
CRITICAL 9.8
CVE-2022-41237
Jenkins DotCi Plugin 2.40.00 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote co…
Dotci
after 2.40.00
CRITICAL 9.8
CVE-2022-41238
A missing permission check in Jenkins DotCi Plugin 2.40.00 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to th…
Dotci
after 2.40.00
CRITICAL 9.1
CVE-2022-41241
Jenkins RQM Plugin 2.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Rqm
after 2.8
HIGH 8.8
CVE-2022-41227
A cross-site request forgery (CSRF) vulnerability in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers to…
Ns Nd Integration Performance Publisher
4.8.0.130+
HIGH 8.8
CVE-2022-41228
A missing permission check in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers with Overall/Read permiss…
Ns Nd Integration Performance Publisher
4.8.0.130+
HIGH 8.8
CVE-2022-41234
Jenkins Rundeck Plugin 3.6.11 and earlier does not protect access to the /plugin/rundeck/webhook/ endpoint, allowing users with Overall/Read permissi…
Rundeck
after 3.6.11
HIGH 8.8
CVE-2022-41236
A cross-site request forgery (CSRF) vulnerability in Jenkins Security Inspector Plugin 117.v6eecc36919c2 and earlier allows attackers to replace the …
Security Inspector
after 117.v6eecc36919c2
HIGH 8.1
CVE-2022-41243
Jenkins SmallTest Plugin 1.0.4 and earlier does not perform hostname validation when connecting to the configured View26 server that could be abused …
Smalltest
after 1.0.4
HIGH 8.0
CVE-2022-41232
A cross-site request forgery (CSRF) vulnerability in Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers to replace any config.xml file …
Build Publisher
after 1.22
MEDIUM 5.7
CVE-2022-41231
Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers with Item/Configure permission to create or replace any config.xml file on the Jenki…
Build Publisher
after 1.22
MEDIUM 5.4
CVE-2022-41229
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.134 and earlier does not escape configuration options of the Execute NetStorm/NetCloud T…
Ns Nd Integration Performance Publisher
after 4.8.0.134
MEDIUM 5.4
CVE-2022-41239
Jenkins DotCi Plugin 2.40.00 and earlier does not escape the GitHub user name parameter provided to commit notifications when displaying them in a bu…
Dotci
after 2.40.00
MEDIUM 5.4
CVE-2022-41240
Jenkins Walti Plugin 1.0.1 and earlier does not escape the information provided by the Walti API, resulting in a stored cross-site scripting (XSS) vu…
Walti
after 1.0.1
MEDIUM 5.4
CVE-2022-41242
A missing permission check in Jenkins extreme-feedback Plugin 1.7 and earlier allows attackers with Overall/Read permission to discover information a…
Extreme Feedback
after 1.7
MEDIUM 5.3
CVE-2022-41235
Jenkins WildFly Deployer Plugin 1.0.2 and earlier implements functionality that allows agent processes to read arbitrary files on the Jenkins control…
Wildfly Deployer
after 1.0.2
CRITICAL 9.8
CVE-2022-41226
Jenkins Compuware Common Configuration Plugin 1.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Compuware Common Configuration
1.0.15+
MEDIUM 5.4
CVE-2022-41224
Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help icons on the Jenkins web UI, …
Jenkins
2.370+
MEDIUM 5.4
CVE-2022-41225
Jenkins Anchore Container Image Scanner Plugin 1.0.24 and earlier does not escape content provided by the Anchore engine API, resulting in a stored c…
Anchore Container Image Scanner
1.0.25+
MEDIUM 6.5
CVE-2022-38663
Jenkins Git Plugin 4.11.4 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log provided by the Git Username…
Git
after 4.11.4
MEDIUM 6.5
CVE-2022-38665
Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration file on the Jenkins controller …
Collabnet
after 2.0.8
MEDIUM 5.4
CVE-2022-38664
Jenkins Job Configuration History Plugin 1165.v8cc9fd1f4597 and earlier does not escape the job name on the System Configuration History page, result…
Job Configuration History
after 1165.v8cc9fd1f4597
HIGH 8.8
CVE-2022-36920
A cross-site request forgery (CSRF) vulnerability in Jenkins Coverity Plugin 1.11.4 and earlier allows attackers to connect to an attacker-specified …
Coverity
after 1.11.4
HIGH 8.1
CVE-2022-36921
A missing permission check in Jenkins Coverity Plugin 1.11.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-spec…
Coverity
after 1.11.4
MEDIUM 6.1
CVE-2022-36922
Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not escape the search query parameter displayed on the 'search' result page, resultin…
Lucene Search
after 370.v62a5f618cd3a
HIGH 8.0
CVE-2022-36916
A cross-site request forgery (CSRF) vulnerability in Jenkins Google Cloud Backup Plugin 0.6 and earlier allows attackers to request a manual backup.
Google Cloud Backup
after 0.6