Vulnerability index

Browse CVEs

87 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Dead Man\'s Snitch MEDIUM 6.5
CVE-2025-53666

Jenkins Dead Man's Snitch Plugin 0.1 stores Dead Man's Snitch tokens unencrypted in job config.xml files on the Jenkins controller, where they can be…

Mitigation only
Fix from $1,600 2025-07-09
Sensedia Api Platform Tools MEDIUM 6.5
CVE-2025-53673

Jenkins Sensedia Api Platform tools Plugin 1.0 stores the Sensedia API Manager integration token unencrypted in its global configuration file on the …

Mitigation only
Fix from $1,600 2025-07-09
Dead Man\'s Snitch MEDIUM 5.3
CVE-2025-53667

Jenkins Dead Man's Snitch Plugin 0.1 does not mask Dead Man's Snitch tokens displayed on the job configuration form, increasing the potential for att…

Mitigation only
Fix from $1,600 2025-07-09
Sensedia Api Platform Tools MEDIUM 5.3
CVE-2025-53674

Jenkins Sensedia Api Platform tools Plugin 1.0 does not mask the Sensedia API Manager integration token on the global configuration form, increasing …

Mitigation only
Fix from $1,600 2025-07-09
Jenkins MEDIUM 6.5
CVE-2024-9453

A vulnerability was found in Red Hat OpenShift Jenkins. The bearer token is not obfuscated in the logs and potentially carries a high risk if those l…

Mitigation only
Fix from $1,600 2025-07-04
Ssh Slave CRITICAL 9.1
CVE-2025-32755

In jenkins/ssh-slave Docker images based on Debian, SSH host keys are generated on image creation for images based on Debian, causing all containers …

Mitigation only
Fix from $2,300 2025-04-10
Monitor Remote Job MEDIUM 5.5
CVE-2025-31725

Jenkins monitor-remote-job Plugin 1.0 stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by user…

Mitigation only
Fix from $1,600 2025-04-02
Anchorchain MEDIUM 6.5
CVE-2025-30196

Jenkins AnchorChain Plugin 1.0 does not limit URL schemes for links it creates based on workspace content, allowing the `javascript:` scheme, resulti…

Mitigation only
Fix from $1,600 2025-03-19
Delphix MEDIUM 5.3
CVE-2024-28161

In Jenkins Delphix Plugin 3.0.1, a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) …

Mitigation only
Fix from $1,600 2024-03-06
Html Resource HIGH 8.1
CVE-2023-50774

A cross-site request forgery (CSRF) vulnerability in Jenkins HTMLResource Plugin 1.02 and earlier allows attackers to delete arbitrary files on the J…

Mitigation only
Fix from $1,950 2023-12-13
Msteams Webhook Trigger MEDIUM 5.3
CVE-2023-46658

Jenkins MSTeams Webhook Trigger Plugin 0.1.1 and earlier uses a non-constant time comparison function when checking whether the provided and expected…

Mitigation only
Fix from $1,600 2023-10-25
Gradle MEDIUM 6.5
CVE-2023-39152

Always-incorrect control flow implementation in Jenkins Gradle Plugin 2.8 may result in credentials not being masked (i.e., replaced with asterisks) …

Mitigation only
Fix from $1,600 2023-07-26
Update Center2 CRITICAL 9.6
CVE-2023-27905

Jenkins update-center2 3.13 and 3.14 renders the required Jenkins core version on plugin download index pages without sanitization, resulting in a st…

Mitigation only
Fix from $2,300 2023-03-10
View Cloner MEDIUM 6.5
CVE-2023-24450

Jenkins view-cloner Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by…

Mitigation only
Fix from $1,600 2023-01-26
Google Login MEDIUM 6.5
CVE-2015-5298

The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are suppo…

Mitigation only
Fix from $1,600 2022-07-07
Hpe Network Virtualization MEDIUM 6.5
CVE-2022-34816

Jenkins HPE Network Virtualization Plugin 1.0 stores passwords unencrypted in its global configuration file on the Jenkins controller where they can …

Mitigation only
Fix from $1,600 2022-06-30
Build Metrics MEDIUM 5.4
CVE-2022-34784

Jenkins build-metrics Plugin 1.3 does not escape the build description on one of its views, resulting in a stored cross-site scripting (XSS) vulnerab…

Mitigation only
Fix from $1,600 2022-06-30
Embeddable Build Status MEDIUM 6.1
CVE-2022-34178

Jenkins Embeddable Build Status Plugin 2.0.3 allows specifying a 'link' query parameter that build status badges will link to, without restricting po…

Mitigation only
Fix from $1,600 2022-06-23
Email Extension HIGH 7.5
CVE-2020-2232

Jenkins Email Extension Plugin 2.72 and 2.73 transmits and displays the SMTP password in plain text as part of the global Jenkins configuration form,…

Mitigation only
Fix from $1,950 2020-08-12
Extensive Testing HIGH 8.8
CVE-2019-10448

Jenkins Extensive Testing Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with …

Mitigation only
Fix from $1,950 2019-10-16
Credentials Binding MEDIUM 6.5
CVE-2019-1010241

Jenkins Credentials Binding Plugin Jenkins 1.17 is affected by: CWE-257: Storing Passwords in a Recoverable Format. The impact is: Authenticated user…

No fix yet
Fix from $1,600 2019-07-19
Self Organizing Swarm Modules CRITICAL 9.3
CVE-2019-10309

Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not prevent XML External Entity p…

Mitigation only
Fix from $2,300 2019-04-30
Kmap HIGH 8.8
CVE-2019-10294

Jenkins Kmap Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read…

Mitigation only
Fix from $1,950 2019-04-04
Crittercism Dsym HIGH 8.8
CVE-2019-10295

Jenkins crittercism-dsym Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with E…

Mitigation only
Fix from $1,950 2019-04-04
Serena Sra Deploy HIGH 8.8
CVE-2019-10296

Jenkins Serena SRA Deploy Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by us…

Mitigation only
Fix from $1,950 2019-04-04
Sametime HIGH 8.8
CVE-2019-10297

Jenkins Sametime Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with …

Mitigation only
Fix from $1,950 2019-04-04
Koji HIGH 8.8
CVE-2019-10298

Jenkins Koji Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with acce…

Mitigation only
Fix from $1,950 2019-04-04
Cloudcoreo Deploytime HIGH 8.8
CVE-2019-10299

Jenkins CloudCoreo DeployTime Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed b…

Mitigation only
Fix from $1,950 2019-04-04
Kmap MEDIUM 6.5
CVE-2019-10292

A cross-site request forgery vulnerability in Jenkins Kmap Plugin in KmapJenkinsBuilder.DescriptorImpl form validation methods allows attackers to in…

Mitigation only
Fix from $1,600 2019-04-04
Kmap MEDIUM 6.5
CVE-2019-10293

A missing permission check in Jenkins Kmap Plugin in KmapJenkinsBuilder.DescriptorImpl form validation methods allows attackers with Overall/Read per…

Mitigation only
Fix from $1,600 2019-04-04