Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2021-21628EPSS 81%
Jenkins Build With Parameters Plugin 1.5 and earlier does not escape parameter names and descriptions, resulting in a stored cross-site scripting (XS…
Build With Parameters
after 1.5
MEDIUM 5.4
CVE-2021-21630EPSS 72%
Jenkins Extra Columns Plugin 1.22 and earlier does not escape parameter values in the build parameters column, resulting in a stored cross-site scrip…
Extra Columns
after 1.22
MEDIUM 5.4
CVE-2021-21635EPSS 9%
Jenkins REST List Parameter Plugin 1.3.0 and earlier does not escape a parameter name reference in embedded JavaScript, resulting in a stored cross-s…
Rest List Parameter
after 1.3.0
HIGH 8.8
CVE-2021-21627
A cross-site request forgery (CSRF) vulnerability in Jenkins Libvirt Agents Plugin 1.9.0 and earlier allows attackers to stop hypervisor domains.
Libvirt Agents
after 1.9.0
MEDIUM 6.5
CVE-2021-21623
An incorrect permission check in Jenkins Matrix Authorization Strategy Plugin 2.6.5 and earlier allows attackers with Item/Read permission on nested …
Matrix Authorization Strategy
after 2.6.5
MEDIUM 5.4
CVE-2021-21622EPSS 9%
Jenkins Artifact Repository Parameter Plugin 1.0.0 and earlier does not escape parameter names and descriptions, resulting in a stored cross-site scr…
Artifact Repository Parameter
after 1.0.0
MEDIUM 5.3
CVE-2021-21621
Jenkins Support Core Plugin 2.72 and earlier provides the serialized user authentication as part of the "About user (basic authentication details onl…
Support Core
after 2.72
HIGH 8.8
CVE-2021-21617
A cross-site request forgery (CSRF) vulnerability in Jenkins Configuration Slicing Plugin 1.51 and earlier allows attackers to apply different slice …
Configuration Slicing
after 1.51
MEDIUM 5.4
CVE-2021-21618EPSS 82%
Jenkins Repository Connector Plugin 2.0.2 and earlier does not escape parameter names and descriptions for past builds, resulting in a stored cross-s…
Repository Connector
after 2.0.2
MEDIUM 5.4
CVE-2021-21619EPSS 9%
Jenkins Claim Plugin 2.18.1 and earlier does not escape the user display name, resulting in a stored cross-site scripting (XSS) vulnerability exploit…
Claim
after 2.18.1
MEDIUM 5.3
CVE-2021-21615
Jenkins 2.275 and LTS 2.263.2 allows reading arbitrary files using the file browser for workspaces and archived artifacts due to a time-of-check to t…
Jenkins
2.263.3 / 2.276+
MEDIUM 6.1
CVE-2021-21610
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not implement any restrictions for the URL rendering a formatted preview of markup passed as …
Jenkins
after 2.274
MEDIUM 6.1
CVE-2021-21613
Jenkins TICS Plugin 2020.3.0.6 and earlier does not escape TICS service responses, resulting in a cross-site scripting (XSS) vulnerability exploitabl…
Tics
after 2020.3.0.6
MEDIUM 5.5
CVE-2021-21612
Jenkins TraceTronic ECU-TEST Plugin 2.23.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller wher…
Tracetronic Ecu Test
after 2.23.1
MEDIUM 5.5
CVE-2021-21614
Jenkins Bumblebee HP ALM Plugin 4.1.5 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where the…
Bumblebee Hp Alm
after 4.1.5
MEDIUM 5.4
CVE-2021-21611
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape display names and IDs of item types shown on the New Item page, resulting in a sto…
Jenkins
after 2.274
HIGH 8.0
CVE-2021-21604
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows attackers with permission to create or configure various objects to inject crafted content …
Jenkins
after 2.274
HIGH 8.0
CVE-2021-21605
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows users with Agent/Configure permission to choose agent names that cause Jenkins to override …
Jenkins
after 2.274
MEDIUM 6.5
CVE-2021-21602
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows reading arbitrary files using the file browser for workspaces and archived artifacts by fol…
Jenkins
after 2.274
MEDIUM 6.5
CVE-2021-21607
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not limit sizes provided as query parameters to graph-rendering URLs, allowing attackers to r…
Jenkins
after 2.274
MEDIUM 5.4
CVE-2021-21603
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape notification bar response contents, resulting in a cross-site scripting (XSS) vuln…
Jenkins
after 2.274
MEDIUM 5.4
CVE-2021-21608
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape button labels in the Jenkins UI, resulting in a cross-site scripting (XSS) vulnera…
Jenkins
after 2.274
MEDIUM 5.3
CVE-2021-21609
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not correctly match requested URLs to the list of always accessible paths, allowing attackers…
Jenkins
after 2.274
CRITICAL 9.8
CVE-2020-2320
Jenkins Plugin Installation Manager Tool 2.1.3 and earlier does not verify plugin downloads.
Installation Manager Tool
after 2.1.3
HIGH 8.1
CVE-2020-2321
A cross-site request forgery (CSRF) vulnerability in Jenkins Shelve Project Plugin 3.0 and earlier allows attackers to shelve, unshelve, or delete a …
Shelve Project
after 3.0
HIGH 7.5
CVE-2020-2324
Jenkins CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Cvs
after 2.16
MEDIUM 6.5
CVE-2020-2312
Jenkins SQLPlus Script Runner Plugin 2.0.12 and earlier does not mask a password provided as command line argument in build logs.
Sqlplus Script Runner
after 2.0.12
MEDIUM 6.5
CVE-2020-2315
Jenkins Visualworks Store Plugin 1.1.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Visualworks Store
after 1.1.3
MEDIUM 6.5
CVE-2020-2318
Jenkins Mail Commander Plugin for Jenkins-ci Plugin 1.0.0 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller …
Mail Commander
after 1.0.0
MEDIUM 6.5
CVE-2020-2319
Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier stores a password unencrypted in the global config.xml file on the Jenkins controller wher…
Vmware Lab Manager Slaves
after 0.2.8