Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.2
CVE-2024-47911
In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-memberships API endpoint that allo…
Sonarqube
10.6+
MEDIUM 6.5
CVE-2024-38460
In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part…
Sonarqube
9.9.4 / 10.4+
CRITICAL 9.8
CVE-2020-35193
The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user. System using the sonarqube docker cont…
Sonarqube Docker Image
Mitigation only
MEDIUM 5.3
CVE-2020-28002
In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner. With an empty value for the -D sonar.login opt…
Sonarqube
No fix yet
HIGH 7.5
CVE-2020-27986EPSS 16%
SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reported…
Sonarqube
Mitigation only
MEDIUM 6.1
CVE-2019-17579
SonarSource SonarQube before 7.8 has XSS in project links on account/projects.
Sonarqube
7.8+
HIGH 7.8
CVE-2018-1000425
An insufficiently protected credentials vulnerability exists in Jenkins SonarQube Scanner Plugin 2.8 and earlier in SonarInstallation.java that allow…
Sonarqube Scanner
after 2.8