Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.4
CVE-2025-64149
A cross-site request forgery (CSRF) vulnerability in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers to connect to an attacker-s…
Publish To Bitbucket
after 0.4
MEDIUM 5.4
CVE-2025-64150
A missing permission check in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers with Overall/Read permission to connect to an atta…
Publish To Bitbucket
after 0.4
HIGH 8.8
CVE-2025-64140
Jenkins Azure CLI Plugin 0.9 and earlier does not restrict which commands it executes on the Jenkins controller, allowing attackers with Item/Configu…
Azure Cli
after 0.9
HIGH 7.5
CVE-2025-64131
Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtain information about the SAML …
Saml
4.583.585.v22ccc1139f55+
HIGH 7.1
CVE-2025-64134
Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML e…
Jdepend
after 1.3.1
MEDIUM 5.9
CVE-2025-64135
Jenkins Eggplant Runner Plugin 0.0.1.301.v963cffe8ddb_8 and earlier sets the Java system property `jdk.http.auth.tunneling.disabledSchemes` to an emp…
Eggplant Runner
after 0.0.1.301.v963cffe8ddb_8
MEDIUM 5.4
CVE-2025-64132
Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in multiple MCP tools, allowing attackers to trigger bui…
Mcp Server
0.86.v7d3355e6a_a_18+
MEDIUM 5.4
CVE-2025-64133
A cross-site request forgery (CSRF) vulnerability in Jenkins Extensible Choice Parameter Plugin 239.v5f5c278708cf and earlier allows attackers to exe…
Extensible Choice Parameter
after 239.v5f5c278708cf
MEDIUM 5.3
CVE-2025-59474
Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users l…
Jenkins
2.516.3 / 2.528+
MEDIUM 5.3
CVE-2025-59476
Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in …
Jenkins
2.516.3 / 2.528+
MEDIUM 6.5
CVE-2025-53675
Jenkins Warrior Framework Plugin 1.2 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller, where they can be vi…
Warrior Framework
after 1.2
MEDIUM 6.5
CVE-2025-53676
Jenkins Xooa Plugin 0.0.7 and earlier stores the Xooa Deployment Token unencrypted in its global configuration file on the Jenkins controller, where …
Xooa
after 0.0.7
MEDIUM 6.5
CVE-2025-53678
Jenkins User1st uTester Plugin 1.1 and earlier stores the uTester JWT token unencrypted in its global configuration file on the Jenkins controller, w…
User1st Utester
after 1.1
MEDIUM 6.5
CVE-2025-53742
Jenkins Applitools Eyes Plugin 1.16.5 and earlier stores Applitools API keys unencrypted in job config.xml files on the Jenkins controller, where the…
Applitools Eyes
1.16.6+
MEDIUM 5.3
CVE-2025-53677
Jenkins Xooa Plugin 0.0.7 and earlier does not mask the Xooa Deployment Token on the global configuration form, increasing the potential for attacker…
Xooa
after 0.0.7
MEDIUM 5.3
CVE-2025-53743
Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not mask Applitools API keys displayed on the job configuration form, increasing the potential…
Applitools Eyes
1.16.6+
MEDIUM 6.5
CVE-2025-53666
Jenkins Dead Man's Snitch Plugin 0.1 stores Dead Man's Snitch tokens unencrypted in job config.xml files on the Jenkins controller, where they can be…
Dead Man\'s Snitch
Mitigation only
MEDIUM 6.5
CVE-2025-53668
Jenkins VAddy Plugin 1.2.8 and earlier stores Vaddy API Auth Keys unencrypted in job config.xml files on the Jenkins controller, where they can be vi…
Vaddy
after 1.2.8
MEDIUM 6.5
CVE-2025-53670
Jenkins Nouvola DiveCloud Plugin 1.08 and earlier stores DiveCloud API Keys and Credentials Encryption Keys unencrypted in job config.xml files on th…
Nouvola Divecloud
after 1.08
MEDIUM 6.5
CVE-2025-53671
Jenkins Nouvola DiveCloud Plugin 1.08 and earlier does not mask DiveCloud API Keys and Credentials Encryption Keys displayed on the job configuration…
Nouvola Divecloud
after 1.08
MEDIUM 6.5
CVE-2025-53672
Jenkins Kryptowire Plugin 0.2 and earlier stores the Kryptowire API key unencrypted in its global configuration file on the Jenkins controller, where…
Kryptowire
after 0.2
MEDIUM 6.5
CVE-2025-53673
Jenkins Sensedia Api Platform tools Plugin 1.0 stores the Sensedia API Manager integration token unencrypted in its global configuration file on the …
Sensedia Api Platform Tools
Mitigation only
MEDIUM 5.3
CVE-2025-53667
Jenkins Dead Man's Snitch Plugin 0.1 does not mask Dead Man's Snitch tokens displayed on the job configuration form, increasing the potential for att…
Dead Man\'s Snitch
Mitigation only
MEDIUM 5.3
CVE-2025-53674
Jenkins Sensedia Api Platform tools Plugin 1.0 does not mask the Sensedia API Manager integration token on the global configuration form, increasing …
Sensedia Api Platform Tools
Mitigation only
MEDIUM 6.5
CVE-2025-53656
Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier stores SLM License Access Keys, client secrets, and passwords unencrypted in job config.x…
Readyapi Functional Testing
after 1.11
MEDIUM 6.5
CVE-2025-53659
Jenkins QMetry Test Management Plugin 1.13 and earlier stores Qmetry Automation API Keys unencrypted in job config.xml files on the Jenkins controlle…
Qmetry Test Management
after 1.13
MEDIUM 6.5
CVE-2025-53662
Jenkins IFTTT Build Notifier Plugin 1.2 and earlier stores IFTTT Maker Channel Keys unencrypted in job config.xml files on the Jenkins controller, wh…
Ifttt Build Notifier
after 1.2
MEDIUM 6.5
CVE-2025-53663
Jenkins IBM Cloud DevOps Plugin 2.0.16 and earlier stores SonarQube authentication tokens unencrypted in job config.xml files on the Jenkins controll…
Ibm Cloud Devops
after 2.0.16
MEDIUM 6.5
CVE-2025-53664
Jenkins Apica Loadtest Plugin 1.10 and earlier stores Apica Loadtest LTP authentication tokens unencrypted in job config.xml files on the Jenkins con…
Apica Loadtest
after 1.10
MEDIUM 5.4
CVE-2025-53658
Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not escape the Applitools URL on the build page, resulting in a stored cross-site scripting (X…
Applitools Eyes
1.16.6+