Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2019-16550
A cross-site request forgery vulnerability in a connection test form method in Jenkins Maven Release Plugin 0.16.1 and earlier allows attackers to ha…
Maven
after 0.16.1
HIGH 8.8
CVE-2019-16551
A cross-site request forgery vulnerability in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers to connect to an attacker-specified H…
Gerrit Trigger
after 2.30.1
MEDIUM 5.4
CVE-2019-16552
A missing permission check in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers with Overall/Read permission to connect to an attacke…
Gerrit Trigger
after 2.30.1
HIGH 8.1
CVE-2019-16549
Jenkins Maven Release Plugin 0.16.1 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks, allowing man-in-the-m…
Maven
after 0.16.1
CRITICAL 9.9
CVE-2019-16541
Jenkins JIRA Plugin 3.0.10 and earlier does not declare the correct (folder) scope for per-folder Jira site definitions, allowing users to select and…
Jira
after 3.0.10
HIGH 8.8
CVE-2019-16548
A cross-site request forgery vulnerability in Jenkins Google Compute Engine Plugin 4.1.1 and earlier in ComputeEngineCloud#doProvision could be used …
Google Compute Engine
4.2.0+
MEDIUM 6.5
CVE-2019-16539
A missing permission check in Jenkins Support Core Plugin 2.63 and earlier allows attackers with Overall/Read permission to delete support bundles.
Support Core
after 2.63
MEDIUM 6.5
CVE-2019-16540
A path traversal vulnerability in Jenkins Support Core Plugin 2.63 and earlier allows attackers with Overall/Read permission to delete arbitrary file…
Support Core
after 2.63
MEDIUM 6.5
CVE-2019-16542
Jenkins Anchore Container Image Scanner Plugin 1.0.19 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where …
Anchore Container Image Scanner
after 1.0.19
MEDIUM 5.9
CVE-2019-16546
Jenkins Google Compute Engine Plugin 4.1.1 and earlier does not verify SSH host keys when connecting agents created by the plugin, enabling man-in-th…
Google Compute Engine
4.2.0+
MEDIUM 5.5
CVE-2019-16543
Jenkins Spira Importer Plugin 3.2.2 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can …
Spira Importer
after 3.2.2
HIGH 8.8
CVE-2019-16538
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.67 and earlier related to the handling of default parameter expressions in closure…
Script Security
after 1.67
MEDIUM 6.1
CVE-2012-4441
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the …
Jenkins
1.466.2 / 1.482+
MEDIUM 6.1
CVE-2012-4440
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the …
Jenkins
1.466.2 / 1.482+
HIGH 8.8
CVE-2012-4438
Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers with read access and HTTP access to Jenkins master to insert data and execut…
Jenkins
1.466.2 / 1.482+
MEDIUM 6.1
CVE-2012-4439
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML via a c…
Jenkins
1.466.2 / 1.482+
HIGH 8.8
CVE-2019-10471
A cross-site request forgery vulnerability in Jenkins Libvirt Slaves Plugin allows attackers to connect to an attacker-specified SSH server using att…
Libvirt Slaves
after 1.8.5
HIGH 7.8
CVE-2019-10476
Jenkins Zulip Plugin 1.1.0 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be view…
Zulip
after 1.1.0
MEDIUM 6.5
CVE-2019-10469
A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers with Overall/Read permission to connect to an attac…
Kubernetes Ci
after 1.3
MEDIUM 6.5
CVE-2019-10470
A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin in form-related methods allowed users with Overall/Read access to en…
Kubernetes Ci
after 1.3
MEDIUM 6.5
CVE-2019-10472
A missing permission check in Jenkins Libvirt Slaves Plugin allows attackers with Overall/Read permission to connect to an attacker-specified SSH ser…
Libvirt Slaves
after 1.8.5
MEDIUM 6.1
CVE-2019-10475EPSS 58%
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web page…
Build Metrics
after 1.3
HIGH 8.8
CVE-2019-10464
A cross-site request forgery vulnerability in Jenkins Deploy WebLogic Plugin allows attackers to connect to an attacker-specified URL using attacker-…
Deploy Weblogic
after 4.1
HIGH 8.8
CVE-2019-10468
A cross-site request forgery vulnerability in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers to connect to an attacker-specified…
Kubernetes Ci
after 1.3
HIGH 8.1
CVE-2019-10462
A cross-site request forgery vulnerability in Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier allowed attackers to connect to an at…
Dynatrace Application Monitoring
after 2.1.3
HIGH 8.1
CVE-2019-10466
An XML external entities (XXE) vulnerability in Jenkins 360 FireLine Plugin allows attackers with Overall/Read access to have Jenkins resolve externa…
360 Fireline
after 1.7.2
HIGH 7.8
CVE-2019-10460
Jenkins Bitbucket OAuth Plugin 0.9 and earlier stored credentials unencrypted in the global config.xml configuration file on the Jenkins master where…
Bitbucket Oauth
after 0.9
HIGH 7.8
CVE-2019-10461
Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier stored credentials unencrypted in its global configuration file on the Jenkins mast…
Dynatrace Application Monitoring
after 2.1.3
MEDIUM 6.5
CVE-2019-10459
Jenkins Mattermost Notification Plugin 2.7.0 and earlier stored webhook URLs containing a secret token unencrypted in its global configuration file a…
Mattermost Notification
after 2.7.0
MEDIUM 6.5
CVE-2019-10463
A missing permission check in Jenkins Dynatrace Application Monitoring Plugin allows attackers with Overall/Read permission to connect to an attacker…
Dynatrace Application Monitoring
after 2.1.4