Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2025-64149 A cross-site request forgery (CSRF) vulnerability in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers to connect to an attacker-s… Publish To Bitbucket after 0.4 Fix from $1,6002025-10-29 MEDIUM 5.4 CVE-2025-64150 A missing permission check in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers with Overall/Read permission to connect to an atta… Publish To Bitbucket after 0.4 Fix from $1,6002025-10-29 HIGH 8.8 CVE-2025-64140 Jenkins Azure CLI Plugin 0.9 and earlier does not restrict which commands it executes on the Jenkins controller, allowing attackers with Item/Configu… Azure Cli after 0.9 Fix from $1,9502025-10-29 HIGH 7.5 CVE-2025-64131 Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtain information about the SAML … Saml 4.583.585.v22ccc1139f55+ Fix from $1,9502025-10-29 HIGH 7.1 CVE-2025-64134 Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML e… Jdepend after 1.3.1 Fix from $1,9502025-10-29 MEDIUM 5.9 CVE-2025-64135 Jenkins Eggplant Runner Plugin 0.0.1.301.v963cffe8ddb_8 and earlier sets the Java system property `jdk.http.auth.tunneling.disabledSchemes` to an emp… Eggplant Runner after 0.0.1.301.v963cffe8ddb_8 Fix from $1,6002025-10-29 MEDIUM 5.4 CVE-2025-64132 Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in multiple MCP tools, allowing attackers to trigger bui… Mcp Server 0.86.v7d3355e6a_a_18+ Fix from $1,6002025-10-29 MEDIUM 5.4 CVE-2025-64133 A cross-site request forgery (CSRF) vulnerability in Jenkins Extensible Choice Parameter Plugin 239.v5f5c278708cf and earlier allows attackers to exe… Extensible Choice Parameter after 239.v5f5c278708cf Fix from $1,6002025-10-29 MEDIUM 5.3 CVE-2025-59474 Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users l… Jenkins 2.516.3 / 2.528+ Fix from $1,6002025-09-17 MEDIUM 5.3 CVE-2025-59476 Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in … Jenkins 2.516.3 / 2.528+ Fix from $1,6002025-09-17 MEDIUM 6.5 CVE-2025-53675 Jenkins Warrior Framework Plugin 1.2 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller, where they can be vi… Warrior Framework after 1.2 Fix from $1,6002025-07-09 MEDIUM 6.5 CVE-2025-53676 Jenkins Xooa Plugin 0.0.7 and earlier stores the Xooa Deployment Token unencrypted in its global configuration file on the Jenkins controller, where … Xooa after 0.0.7 Fix from $1,6002025-07-09 MEDIUM 6.5 CVE-2025-53678 Jenkins User1st uTester Plugin 1.1 and earlier stores the uTester JWT token unencrypted in its global configuration file on the Jenkins controller, w… User1st Utester after 1.1 Fix from $1,6002025-07-09 MEDIUM 6.5 CVE-2025-53742 Jenkins Applitools Eyes Plugin 1.16.5 and earlier stores Applitools API keys unencrypted in job config.xml files on the Jenkins controller, where the… Applitools Eyes 1.16.6+ Fix from $1,6002025-07-09 MEDIUM 5.3 CVE-2025-53677 Jenkins Xooa Plugin 0.0.7 and earlier does not mask the Xooa Deployment Token on the global configuration form, increasing the potential for attacker… Xooa after 0.0.7 Fix from $1,6002025-07-09 MEDIUM 5.3 CVE-2025-53743 Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not mask Applitools API keys displayed on the job configuration form, increasing the potential… Applitools Eyes 1.16.6+ Fix from $1,6002025-07-09 MEDIUM 6.5 CVE-2025-53666 Jenkins Dead Man's Snitch Plugin 0.1 stores Dead Man's Snitch tokens unencrypted in job config.xml files on the Jenkins controller, where they can be… Dead Man\'s Snitch Mitigation only Fix from $1,6002025-07-09 MEDIUM 6.5 CVE-2025-53668 Jenkins VAddy Plugin 1.2.8 and earlier stores Vaddy API Auth Keys unencrypted in job config.xml files on the Jenkins controller, where they can be vi… Vaddy after 1.2.8 Fix from $1,6002025-07-09 MEDIUM 6.5 CVE-2025-53670 Jenkins Nouvola DiveCloud Plugin 1.08 and earlier stores DiveCloud API Keys and Credentials Encryption Keys unencrypted in job config.xml files on th… Nouvola Divecloud after 1.08 Fix from $1,6002025-07-09 MEDIUM 6.5 CVE-2025-53671 Jenkins Nouvola DiveCloud Plugin 1.08 and earlier does not mask DiveCloud API Keys and Credentials Encryption Keys displayed on the job configuration… Nouvola Divecloud after 1.08 Fix from $1,6002025-07-09 MEDIUM 6.5 CVE-2025-53672 Jenkins Kryptowire Plugin 0.2 and earlier stores the Kryptowire API key unencrypted in its global configuration file on the Jenkins controller, where… Kryptowire after 0.2 Fix from $1,6002025-07-09 MEDIUM 6.5 CVE-2025-53673 Jenkins Sensedia Api Platform tools Plugin 1.0 stores the Sensedia API Manager integration token unencrypted in its global configuration file on the … Sensedia Api Platform Tools Mitigation only Fix from $1,6002025-07-09 MEDIUM 5.3 CVE-2025-53667 Jenkins Dead Man's Snitch Plugin 0.1 does not mask Dead Man's Snitch tokens displayed on the job configuration form, increasing the potential for att… Dead Man\'s Snitch Mitigation only Fix from $1,6002025-07-09 MEDIUM 5.3 CVE-2025-53674 Jenkins Sensedia Api Platform tools Plugin 1.0 does not mask the Sensedia API Manager integration token on the global configuration form, increasing … Sensedia Api Platform Tools Mitigation only Fix from $1,6002025-07-09 MEDIUM 6.5 CVE-2025-53656 Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier stores SLM License Access Keys, client secrets, and passwords unencrypted in job config.x… Readyapi Functional Testing after 1.11 Fix from $1,6002025-07-09 MEDIUM 6.5 CVE-2025-53659 Jenkins QMetry Test Management Plugin 1.13 and earlier stores Qmetry Automation API Keys unencrypted in job config.xml files on the Jenkins controlle… Qmetry Test Management after 1.13 Fix from $1,6002025-07-09 MEDIUM 6.5 CVE-2025-53662 Jenkins IFTTT Build Notifier Plugin 1.2 and earlier stores IFTTT Maker Channel Keys unencrypted in job config.xml files on the Jenkins controller, wh… Ifttt Build Notifier after 1.2 Fix from $1,6002025-07-09 MEDIUM 6.5 CVE-2025-53663 Jenkins IBM Cloud DevOps Plugin 2.0.16 and earlier stores SonarQube authentication tokens unencrypted in job config.xml files on the Jenkins controll… Ibm Cloud Devops after 2.0.16 Fix from $1,6002025-07-09 MEDIUM 6.5 CVE-2025-53664 Jenkins Apica Loadtest Plugin 1.10 and earlier stores Apica Loadtest LTP authentication tokens unencrypted in job config.xml files on the Jenkins con… Apica Loadtest after 1.10 Fix from $1,6002025-07-09 MEDIUM 5.4 CVE-2025-53658 Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not escape the Applitools URL on the build page, resulting in a stored cross-site scripting (X… Applitools Eyes 1.16.6+ Fix from $1,6002025-07-09