Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2023-32997
Jenkins CAS Plugin 1.6.2 and earlier does not invalidate the previous session on login.
Cas
after 1.6.2
HIGH 8.8
CVE-2023-32998
A cross-site request forgery (CSRF) vulnerability in Jenkins AppSpider Plugin 1.0.15 and earlier allows attackers to connect to an attacker-specified…
Appspider
after 1.0.15
HIGH 7.5
CVE-2023-33000
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier does not mask credentials displayed on the configuration form, increasin…
Ns Nd Integration Performance Publisher
after 4.8.0.149
HIGH 7.5
CVE-2023-33001
Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when…
Hashicorp Vault
after 360.v0a_1c04cf807d
MEDIUM 5.4
CVE-2023-33002
Jenkins TestComplete support Plugin 2.8.1 and earlier does not escape the TestComplete project name, resulting in a stored cross-site scripting (XSS)…
Testcomplete Support
after 2.8.1
MEDIUM 5.4
CVE-2023-33005
Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the previous session on login.
Wso2 Oauth
after 1.0
MEDIUM 5.4
CVE-2023-33006
A cross-site request forgery (CSRF) vulnerability in Jenkins WSO2 Oauth Plugin 1.0 and earlier allows attackers to trick users into logging in to the…
Wso2 Oauth
after 1.0
MEDIUM 5.4
CVE-2023-33007
Jenkins LoadComplete support Plugin 1.0 and earlier does not escape the LoadComplete test name, resulting in a stored cross-site scripting (XSS) vuln…
Loadcomplete Support
after 1.0
HIGH 8.8
CVE-2023-32991
A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allows attackers to send an HTTP reque…
Saml Single Sign On
after 2.0.2
HIGH 8.8
CVE-2023-32992
Missing permission checks in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allow attackers with Overall/Read permission to send an HTTP r…
Saml Single Sign On
after 2.0.2
HIGH 8.8
CVE-2023-32995
A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.0 and earlier allows attackers to send an HTTP POST …
Saml Single Sign On
after 2.0.0
MEDIUM 6.5
CVE-2023-32990
A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overall/Read permission to connect …
Azure Vm Agents
after 852.v8d35f0960a_43
HIGH 8.8
CVE-2023-32986EPSS 61%
Jenkins File Parameter Plugin 285.v757c5b_67a_c25 and earlier does not restrict the name (and resulting uploaded file name) of Stashed File Parameter…
File Parameters
after 285.287.v4b_7b_29d3469d
HIGH 8.8
CVE-2023-32987
A cross-site request forgery (CSRF) vulnerability in Jenkins Reverse Proxy Auth Plugin 1.7.4 and earlier allows attackers to connect to an attacker-s…
Reverse Proxy Auth
after 1.7.4
HIGH 8.8
CVE-2023-32989
A cross-site request forgery (CSRF) vulnerability in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers to connect to an …
Azure Vm Agents
after 852.v8d35f0960a_43
MEDIUM 5.4
CVE-2023-32984
Jenkins TestNG Results Plugin 730.v4c5283037693 and earlier does not escape several values that are parsed from TestNG report files and displayed on …
Testng Results
after 730.v4c5283037693
HIGH 8.8
CVE-2023-32981
An arbitrary file write vulnerability in Jenkins Pipeline Utility Steps Plugin 2.15.2 and earlier allows attackers able to provide crafted archives a…
Pipeline Utility Steps
after 2.15.2
MEDIUM 5.4
CVE-2023-32977
Jenkins Pipeline: Job Plugin does not escape the display name of the build that caused an earlier build to be aborted, resulting in a stored cross-si…
Pipeline\
after 1292.v27d8cc3e2602
MEDIUM 5.3
CVE-2023-32983
Jenkins Ansible Plugin 204.v8191fd551eb_f and earlier does not mask extra variables displayed on the configuration form, increasing the potential for…
Ansible
after 204.v8191fd551eb_f
MEDIUM 6.5
CVE-2023-30531
Jenkins Consul KV Builder Plugin 2.0.13 and earlier does not mask the HashiCorp Consul ACL Token on the global configuration form, increasing the pot…
Consul Kv Builder
after 2.0.13
MEDIUM 6.5
CVE-2023-30532
A missing permission check in Jenkins TurboScript Plugin 1.3 and earlier allows attackers with Item/Read permission to trigger builds of jobs corresp…
Turboscript
after 1.3
MEDIUM 6.5
CVE-2023-30526
A missing permission check in Jenkins Report Portal Plugin 0.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-sp…
Report Portal
after 0.5
MEDIUM 6.5
CVE-2023-30528
Jenkins WSO2 Oauth Plugin 1.0 and earlier does not mask the WSO2 Oauth client secret on the global configuration form, increasing the potential for a…
Wso2 Oauth
after 1.0
HIGH 8.8
CVE-2023-30525
A cross-site request forgery (CSRF) vulnerability in Jenkins Report Portal Plugin 0.5 and earlier allows attackers to connect to an attacker-specifie…
Report Portal
after 0.5
MEDIUM 5.3
CVE-2023-30521
A missing permission check in Jenkins Assembla merge request builder Plugin 1.1.13 and earlier allows unauthenticated attackers to trigger builds of …
Assembla Merge Request Builder
after 1.1.13
MEDIUM 6.5
CVE-2023-30516
Jenkins Image Tag Parameter Plugin 2.0 improperly introduces an option to opt out of SSL/TLS certificate validation when connecting to Docker registr…
Image Tag Parameter
2.0+
MEDIUM 5.4
CVE-2023-30520
Jenkins Quay.io trigger Plugin 0.1 and earlier does not limit URL schemes for repository homepage URLs submitted via Quay.io trigger webhooks, result…
Quay.io Trigger
after 0.1
MEDIUM 5.3
CVE-2023-30517
Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier unconditionally disables SSL/TLS certificate and hostname validation when connecting …
Neuvector Vulnerability Scanner
after 1.22
MEDIUM 5.3
CVE-2023-30519
A missing permission check in Jenkins Quay.io trigger Plugin 0.1 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding…
Quay.io Trigger
after 0.1
HIGH 7.5
CVE-2023-30514
Jenkins Azure Key Vault Plugin 187.va_cd5fecd198a_ and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log whe…
Azure Key Vault
after 187.va_cd5fecd198a