Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2020-2261
Jenkins Perfecto Plugin 1.17 and earlier executes a command on the Jenkins controller, allowing attackers with Job/Configure permission to run arbitr…
Perfecto
after 1.17
MEDIUM 6.5
CVE-2020-2254
Jenkins Blue Ocean Plugin 1.23.2 and earlier provides an undocumented feature flag that, when enabled, allows an attacker with Job/Configure or Job/C…
Blue Ocean
after 1.23.2
MEDIUM 5.4
CVE-2020-2256
Jenkins Pipeline Maven Integration Plugin 3.9.2 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting…
Pipeline Maven Integration
after 3.9.2
MEDIUM 5.4
CVE-2020-2257
Jenkins Validating String Parameter Plugin 2.4 and earlier does not escape various user-controlled fields, resulting in a stored cross-site scripting…
Validating String Parameter
after 2.4
MEDIUM 5.4
CVE-2020-2259
Jenkins computer-queue-plugin Plugin 1.5 and earlier does not escape the agent name in tooltips, resulting in a stored cross-site scripting (XSS) vul…
Computer Queue
after 1.5
MEDIUM 5.4
CVE-2020-2262
Jenkins Android Lint Plugin 2.6 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vuln…
Android Lint
after 2.6
MEDIUM 5.4
CVE-2020-2263
Jenkins Radiator View Plugin 1.29 and earlier does not escape the full name of the jobs in tooltips, resulting in a stored cross-site scripting (XSS)…
Radiator View
after 1.29
MEDIUM 5.4
CVE-2020-2264
Jenkins Custom Job Icon Plugin 0.2 and earlier does not escape the job descriptions in tooltips, resulting in a stored cross-site scripting (XSS) vul…
Custom Job Icon
after 0.2
MEDIUM 5.4
CVE-2020-2265
Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not escape the method information in tooltips, resulting in a stored cross-sit…
Coverage\/complexity Scatter Plot
after 1.1.1
MEDIUM 5.4
CVE-2020-2266
Jenkins Description Column Plugin 1.3 and earlier does not escape the job description in the column tooltip, resulting in a stored cross-site scripti…
Description Column
after 1.3
HIGH 7.1
CVE-2020-2245
Jenkins Valgrind Plugin 0.28 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Valgrind
after 0.28
MEDIUM 6.5
CVE-2020-2247
Jenkins Klocwork Analysis Plugin 2020.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Klocwork Analysis
after 2020.2.1
MEDIUM 6.5
CVE-2020-2250
Jenkins SoapUI Pro Functional Testing Plugin 1.3 and earlier stores project passwords unencrypted in job config.xml files on the Jenkins controller w…
Soapui Pro Functional Testing
after 1.3
MEDIUM 6.1
CVE-2020-2248
Jenkins JSGames Plugin 0.2 and earlier evaluates part of a URL as code, resulting in a reflected cross-site scripting (XSS) vulnerability.
Jsgames
after 0.2
MEDIUM 5.4
CVE-2020-2246
Jenkins Valgrind Plugin 0.28 and earlier does not escape content in Valgrind XML reports, resulting in a stored cross-site scripting (XSS) vulnerabil…
Valgrind
after 0.28
HIGH 8.8
CVE-2020-2240
A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows attackers to execute arbitrary SQL scripts.
Database
after 1.6
HIGH 8.8
CVE-2020-2241
A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows attackers to connect to an attacker-specified dat…
Database
after 1.6
MEDIUM 6.5
CVE-2020-2242
A missing permission check in Jenkins database Plugin 1.6 and earlier allows attackers with Overall/Read access to Jenkins to connect to an attacker-…
Database
after 1.6
MEDIUM 5.4
CVE-2020-2238
Jenkins Git Parameter Plugin 0.9.12 and earlier does not escape the repository field on the 'Build with Parameters' page, resulting in a stored cross…
Git Parameter
after 0.9.12
MEDIUM 5.4
CVE-2020-2243
Jenkins Cadence vManager Plugin 3.0.4 and earlier does not escape build descriptions in tooltips, resulting in a stored cross-site scripting (XSS) vu…
Cadence Vmanager
after 3.0.4
MEDIUM 5.4
CVE-2020-2244
Jenkins Build Failure Analyzer Plugin 1.27.0 and earlier does not escape matching text in a form validation response, resulting in a cross-site scrip…
Build Failure Analyzer
after 1.27.0
HIGH 7.5
CVE-2020-2232
Jenkins Email Extension Plugin 2.72 and 2.73 transmits and displays the SMTP password in plain text as part of the global Jenkins configuration form,…
Email Extension
Mitigation only
MEDIUM 6.5
CVE-2020-2233
A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read access to enumerate credenti…
Pipeline Maven Integration
after 3.8.2
MEDIUM 6.5
CVE-2020-2234
A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read access to connect to an atta…
Pipeline Maven Integration
after 3.8.2
MEDIUM 6.5
CVE-2020-2235
A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows attackers to connect to an at…
Pipeline Maven Integration
after 3.8.2
MEDIUM 5.4
CVE-2020-2229EPSS 7%
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS…
Jenkins
after 2.251
MEDIUM 5.4
CVE-2020-2230EPSS 83%
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scriptin…
Jenkins
after 2.251
MEDIUM 5.4
CVE-2020-2231EPSS 5%
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', res…
Jenkins
after 2.251
MEDIUM 5.4
CVE-2020-2236
Jenkins Yet Another Build Visualizer Plugin 1.11 and earlier does not escape tooltip content, resulting in a stored cross-site scripting (XSS) vulner…
Yet Another Build Visualizer
after 1.11
HIGH 8.8
CVE-2020-2228
Jenkins Gitlab Authentication Plugin 1.5 and earlier does not perform group authorization checks properly, resulting in a privilege escalation vulner…
Gitlab Authentication
after 1.5