Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.5
CVE-2021-21681
Jenkins Nomad Plugin 0.7.4 and earlier stores Docker passwords unencrypted in the global config.xml file on the Jenkins controller where they can be …
Nomad
after 0.7.4
MEDIUM 6.5
CVE-2021-21675
A cross-site request forgery (CSRF) vulnerability in Jenkins requests-plugin Plugin 2.2.12 and earlier allows attackers to create requests and/or hav…
Requests
after 2.2.12
MEDIUM 6.1
CVE-2021-21673
Jenkins CAS Plugin 1.6.0 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to…
Cas
after 1.6.0
HIGH 7.5
CVE-2021-21671
Jenkins 2.299 and earlier, LTS 2.289.1 and earlier does not invalidate the previous session on login.
Jenkins
2.289.2 / 2.300+
CRITICAL 9.8
CVE-2021-21669EPSS 26%
Jenkins Generic Webhook Trigger Plugin 1.72 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Generic Webhook Trigger
after 1.72
MEDIUM 5.4
CVE-2021-21667EPSS 76%
Jenkins Scriptler Plugin 3.2 and earlier does not escape parameter names shown in job configuration forms, resulting in a stored cross-site scripting…
Scriptler
after 3.2
MEDIUM 5.4
CVE-2021-21668EPSS 76%
Jenkins Scriptler Plugin 3.1 and earlier does not escape script content, resulting in a stored cross-site scripting (XSS) vulnerability exploitable b…
Scriptler
after 3.1
MEDIUM 6.1
CVE-2021-21666
Jenkins Kiuwan Plugin 1.6.0 and earlier does not escape query parameters in an error message for a form validation endpoint, resulting in a reflected…
Kiuwan
after 1.6.0
HIGH 8.8
CVE-2021-21665
A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers to connect to an attacker…
Xebialabs Xl Deploy
after 10.0.1
MEDIUM 6.5
CVE-2021-21664
An incorrect permission check in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers with Generic Create permission to connect to …
Xebialabs Xl Deploy
after 10.0.1
CRITICAL 9.1
CVE-2021-21658
Jenkins Nuget Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Nuget
after 1.0
HIGH 8.8
CVE-2021-21657
Jenkins Filesystem Trigger Plugin 0.40 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Filesystem Trigger
after 0.40
HIGH 8.1
CVE-2021-21659EPSS 67%
Jenkins URLTrigger Plugin 0.48 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Urltrigger
after 0.48
MEDIUM 5.4
CVE-2021-21660
Jenkins Markdown Formatter Plugin 0.1.0 and earlier does not sanitize crafted link target URLs, resulting in a stored cross-site scripting (XSS) vuln…
Markdown Formatter
after 0.1.0
HIGH 7.1
CVE-2021-21652
A cross-site request forgery (CSRF) vulnerability in Jenkins Xray - Test Management for Jira Plugin 2.4.0 and earlier allows attackers to connect to …
Xray Test Management For Jira
after 2.4.0
HIGH 7.1
CVE-2021-21655
A cross-site request forgery (CSRF) vulnerability in Jenkins P4 Plugin 1.11.4 and earlier allows attackers to connect to an attacker-specified Perfor…
P4
after 1.11.4
HIGH 7.1
CVE-2021-21656
Jenkins Xcode integration Plugin 2.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Xcode Integration
after 2.0.14
MEDIUM 6.1
CVE-2021-21648EPSS 11%
Jenkins Credentials Plugin 2.3.18 and earlier does not escape user-controlled information on a view it provides, resulting in a reflected cross-site …
Credentials
after 2.3.18
MEDIUM 5.4
CVE-2021-21649EPSS 73%
Jenkins Dashboard View Plugin 2.15 and earlier does not escape URLs referenced in Image Dashboard Portlets, resulting in a stored cross-site scriptin…
Dashboard View
after 2.15
HIGH 8.8
CVE-2021-21646
Jenkins Templating Engine Plugin 2.1 and earlier does not protect its pipeline configurations using Script Security Plugin, allowing attackers with J…
Templating Engine
after 2.1
HIGH 8.1
CVE-2021-21642EPSS 38%
Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Config File Provider
after 3.7.0
MEDIUM 6.5
CVE-2021-21643
Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpoints, allowing attackers with…
Config File Provider
after 3.7.0
MEDIUM 5.4
CVE-2021-21644
A cross-site request forgery (CSRF) vulnerability in Jenkins Config File Provider Plugin 3.7.0 and earlier allows attackers to delete configuration f…
Config File Provider
after 3.7.0
HIGH 7.5
CVE-2021-28165EPSS 54%
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS f…
Jenkins
2.277.3 / 2.286+
HIGH 8.8
CVE-2021-21629
A cross-site request forgery (CSRF) vulnerability in Jenkins Build With Parameters Plugin 1.5 and earlier allows attackers to build a project with at…
Build With Parameters
after 1.5
HIGH 8.8
CVE-2021-21633
A cross-site request forgery (CSRF) vulnerability in Jenkins OWASP Dependency-Track Plugin 3.1.0 and earlier allows attackers to connect to an attack…
Owasp Dependency Track
after 3.1.0
HIGH 8.8
CVE-2021-21638
A cross-site request forgery (CSRF) vulnerability in Jenkins Team Foundation Server Plugin 5.157.1 and earlier allows attackers to connect to an atta…
Team Foundation Server
after 5.157.1
MEDIUM 6.5
CVE-2021-21632
A missing permission check in Jenkins OWASP Dependency-Track Plugin 3.1.0 and earlier allows attackers with Overall/Read permission to connect to an …
Owasp Dependency Track
after 3.1.0
MEDIUM 6.5
CVE-2021-21634
Jenkins Jabber (XMPP) notifier and control Plugin 1.41 and earlier stores passwords unencrypted in its global configuration file on the Jenkins contr…
Jabber \(xmpp\) Notifier And Control
after 1.41
MEDIUM 6.5
CVE-2021-21637
A missing permission check in Jenkins Team Foundation Server Plugin 5.157.1 and earlier allows attackers with Overall/Read permission to connect to a…
Team Foundation Server
after 5.157.1