Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.2
CVE-2025-53652
Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the…
Git Parameter
444.vca_b_84d3703c2+
HIGH 7.3
CVE-2025-53650
Jenkins Credentials Binding Plugin 687.v619cb_15e923f and earlier does not properly mask (i.e., replace with asterisks) credentials present in except…
Credentials Binding
after 687.689.v1a_f775332fc
MEDIUM 6.5
CVE-2025-53654
Jenkins Statistics Gatherer Plugin 2.0.3 and earlier stores the AWS Secret Key unencrypted in its global configuration file on the Jenkins controller…
Statistics Gatherer
after 2.0.3
MEDIUM 6.3
CVE-2025-53651
Jenkins HTML Publisher Plugin 425 and earlier displays log messages that include the absolute paths of files archived during the Publish HTML reports…
Html Publisher
427+
MEDIUM 5.3
CVE-2025-53655
Jenkins Statistics Gatherer Plugin 2.0.3 and earlier does not mask the AWS Secret Key on the global configuration form, increasing the potential for …
Statistics Gatherer
after 2.0.3
MEDIUM 6.5
CVE-2024-9453
A vulnerability was found in Red Hat OpenShift Jenkins. The bearer token is not obfuscated in the logs and potentially carries a high risk if those l…
Jenkins
Mitigation only
HIGH 8.0
CVE-2025-5806
Jenkins Gatling Plugin 136.vb_9009b_3d33a_e serves Gatling reports in a manner that bypasses the Content-Security-Policy protection introduced in Jen…
Gatling
after 136.vb_9009b_3d33a_e
CRITICAL 9.8
CVE-2025-47889
In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing unau…
Wso2 Oauth
after 1.0
CRITICAL 9.1
CVE-2025-47884
In Jenkins OpenID Connect Provider Plugin 96.vee8ed882ec4d and earlier the generation of build ID Tokens uses potentially overridden values of enviro…
Openid Connect Provider
after 96.vee8ed882ec4d
HIGH 8.8
CVE-2025-47885
Jenkins Health Advisor by CloudBees Plugin 374.v194b_d4f0c8c8 and earlier does not escape responses from the Jenkins Health Advisor server, resulting…
Health Advisor By Cloudbees
after 374.v194b_d4f0c8c8
MEDIUM 5.9
CVE-2025-47888
Jenkins DingTalk Plugin 2.7.3 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections to the configured Ding…
Dingtalk
after 2.7.3
CRITICAL 9.1
CVE-2025-32754
In jenkins/ssh-agent Docker images 6.11.1 and earlier, SSH host keys are generated on image creation for images based on Debian, causing all containe…
Ssh Agent
6.11.2+
CRITICAL 9.1
CVE-2025-32755
In jenkins/ssh-slave Docker images based on Debian, SSH host keys are generated on image creation for images based on Debian, causing all containers …
Ssh Slave
Mitigation only
MEDIUM 5.5
CVE-2025-31725
Jenkins monitor-remote-job Plugin 1.0 stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by user…
Monitor Remote Job
Mitigation only
MEDIUM 5.5
CVE-2025-31726
Jenkins Stack Hammer Plugin 1.0.6 and earlier stores Stack Hammer API keys unencrypted in job config.xml files on the Jenkins controller where they c…
Stack Hammer
after 1.0.6
MEDIUM 5.5
CVE-2025-31727
Jenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in job config.xml files on the Jenkins controller wher…
Asakusasatellite
after 0.1.1
MEDIUM 5.5
CVE-2025-31728
Jenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed on the job configuration form, increasing the pot…
Asakusasatellite
after 0.1.1
HIGH 8.8
CVE-2025-31722
In Jenkins Templating Engine Plugin 2.5.3 and earlier, libraries defined in folders are not subject to sandbox protection, allowing attackers with It…
Templating Engine
2.5.4+
MEDIUM 6.5
CVE-2025-30196
Jenkins AnchorChain Plugin 1.0 does not limit URL schemes for links it creates based on workspace content, allowing the `javascript:` scheme, resulti…
Anchorchain
Mitigation only
MEDIUM 5.4
CVE-2025-27624
A cross-site request forgery (CSRF) vulnerability in Jenkins 2.499 and earlier, LTS 2.492.1 and earlier allows attackers to have users toggle their c…
Jenkins
2.492.2 / 2.500+
MEDIUM 6.8
CVE-2025-24401
Jenkins Folder-based Authorization Strategy Plugin 217.vd5b_18537403e and earlier does not verify that permissions configured to be granted are enabl…
Folder Based Authorization Strategy
after 217.vd5b_18537403e
HIGH 8.8
CVE-2025-24398
Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection…
Bitbucket Server Integration
4.1.4+
HIGH 8.8
CVE-2025-24399
Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats usernames as case-insensitive,…
Openid Connect Authentication
4.438.440.v3f5f201de5dc / 4.453.v4d7765c854f4+
HIGH 8.0
CVE-2024-54003EPSS 80%
Jenkins Simple Queue Plugin 1.4.4 and earlier does not escape the view name, resulting in a stored cross-site scripting (XSS) vulnerability exploitab…
Simple Queue
after 1.4.4
HIGH 8.8
CVE-2024-52553
Jenkins OpenId Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier does not invalidate the previous session on login.
Openid Connect Authentication
4.421.v5422614eb_e0a+
HIGH 8.8
CVE-2024-52554
Jenkins Shared Library Version Override Plugin 17.v786074c9fce7 and earlier declares folder-scoped library overrides as trusted, so that they're not …
Shared Library Version Override
after 17.v786074c9fce7
HIGH 8.0
CVE-2024-52550
Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main (Jenkinsfile) script …
Pipeline\
3975.3977.v478dd9e956c3+
HIGH 8.0
CVE-2024-52551
Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a bui…
Pipeline\
after 2.2214.vb_b_34b_2ea_9b_83
HIGH 8.0
CVE-2024-52552
Jenkins Authorize Project Plugin 1.7.2 and earlier evaluates a string containing the job name with JavaScript on the Authorization view, resulting in…
Authorize Project
after 1.7.2
HIGH 8.1
CVE-2024-47806
Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim of an ID Token, allowing atta…
Openid Connect Authentication
4.355.v3a_fb_fca_b_96d4+