Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.1
CVE-2024-47807
Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token, allowing attack…
Openid Connect Authentication
4.355.v3a_fb_fca_b_96d4+
HIGH 7.5
CVE-2024-47805
Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using…
Credentials
1371.1373.v4eb_fa_b_7161e9 / 1380.va_435002fa_924+
HIGH 8.8
CVE-2024-43044EPSS 29%
Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using th…
Jenkins
2.452.4 / 2.471+
MEDIUM 6.3
CVE-2024-43045
Jenkins 2.470 and earlier, LTS 2.452.3 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read perm…
Jenkins
2.452.4 / 2.471+
CRITICAL 9.8
CVE-2024-34144EPSS 48%
A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attacker…
Script Security
after 1335.vf07d9ce377a_e
HIGH 8.8
CVE-2024-34145
A sandbox bypass vulnerability involving sandbox-defined classes that shadow specific non-sandbox-defined classes in Jenkins Script Security Plugin 1…
Script Security
after 1335.vf07d9ce377a_e
MEDIUM 6.8
CVE-2024-34148
Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically disables the fix for CVE-2016-3721 whenever a build is triggered…
Subversion Partial Release Manager
after 1.0.1
MEDIUM 6.5
CVE-2024-34146
Jenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git repository over SSH, allowing a…
Git Server
after 114.v068a_c7cc2574
HIGH 8.8
CVE-2024-28160
Jenkins iceScrum Plugin 1.1.6 and earlier does not sanitize iceScrum project URLs on build views, resulting in a stored cross-site scripting (XSS) vu…
Icescrum
after 1.1.6
HIGH 8.8
CVE-2024-2216
A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers with Overall/Read permission to …
Docker Build Step
after 2.11
MEDIUM 6.1
CVE-2024-2215
A cross-site request forgery (CSRF) vulnerability in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers to connect to an attacker-spe…
Docker Build Step
after 2.11
MEDIUM 5.3
CVE-2024-28161
In Jenkins Delphix Plugin 3.0.1, a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) …
Delphix
Mitigation only
HIGH 8.0
CVE-2024-28157
Jenkins GitBucket Plugin 0.8 and earlier does not sanitize Gitbucket URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerabil…
Gitbucket
after 0.8
MEDIUM 6.5
CVE-2024-28149
Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers with Item/Configure permission …
Html Publisher
1.32.1+
MEDIUM 6.5
CVE-2024-28154
Jenkins MQ Notifier Plugin 1.4.0 and earlier logs potentially sensitive build parameters as part of debug information in build logs by default.
Mq Notifier
1.4.1+
MEDIUM 6.3
CVE-2024-28152
In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks…
Bitbucket Branch Source
848.850.v6a_a_2a_234a_c81+
MEDIUM 5.4
CVE-2024-28153
Jenkins OWASP Dependency-Check Plugin 5.4.5 and earlier does not escape vulnerability metadata from Dependency-Check reports, resulting in a stored c…
Owasp Dependency Check
5.4.6+
MEDIUM 5.4
CVE-2024-28156EPSS 80%
Jenkins Build Monitor View Plugin 1.14-860.vd06ef2568b_3f and earlier does not escape Build Monitor View names, resulting in a stored cross-site scri…
Build Monitor View
after 1.14-860.vd06ef2568b_3f
CRITICAL 9.8
CVE-2024-23897 KEVEPSS 100%
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a …
Jenkins
2.426.3 / 2.442+
HIGH 8.8
CVE-2024-23898EPSS 67%
Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made throug…
Jenkins
after 2.441
HIGH 7.5
CVE-2024-23904
Jenkins Log Command Plugin 1.0.2 and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file path …
Log Command
after 1.0.2
MEDIUM 6.5
CVE-2024-23899
Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable a feature of its command parser that replaces an '@' character followed b…
Git Server
after 99.va_0826a_b_cdfa_d
MEDIUM 6.5
CVE-2024-23901
Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier unconditionally discovers projects that are shared with the configured owner grou…
Github Branch Source
after 684.vea_fa_7c1e2fe3
MEDIUM 5.4
CVE-2024-23905
Jenkins Red Hat Dependency Analytics Plugin 0.7.1 and earlier programmatically disables Content-Security-Policy protection for user-generated content…
Red Hat Dependency Analytics
after 0.7.1
MEDIUM 5.3
CVE-2024-23903
Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier uses a non-constant time comparison function when checking whether the provided a…
Github Branch Source
after 684.vea_fa_7c1e2fe3
HIGH 8.8
CVE-2023-50778
A cross-site request forgery (CSRF) vulnerability in Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier allows attackers to connect to an attacker-sp…
Paaslane Estimate
after 1.0.4
HIGH 8.1
CVE-2023-50774
A cross-site request forgery (CSRF) vulnerability in Jenkins HTMLResource Plugin 1.02 and earlier allows attackers to delete arbitrary files on the J…
Html Resource
Mitigation only
MEDIUM 6.7
CVE-2023-50770
Jenkins OpenId Connect Authentication Plugin 2.6 and earlier stores a password of a local user account used as an anti-lockout feature in a recoverab…
Openid
after 2.6
MEDIUM 6.1
CVE-2023-50771
Jenkins OpenId Connect Authentication Plugin 2.6 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkin…
Openid Connect Authentication
after 2.6
HIGH 8.8
CVE-2023-50766
A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allows attackers to send an HTTP request to …
Nexus Platform
after 3.18.0-03