Jenkins
Security Risk Profile
37
/100
lowSecurity Risk Score
Comprehensive risk assessment based on 1000 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from June 30, 2021 to present
1000
Total CVEs
314
Critical+High
2
Exploited
145
Unpatched
Threat Assessment
Avg CVSS
6.3
Base severity
Avg EPSS
1%
Exploit probability
Unpatched
145
Critical/High
Risk Level
37/100
low
⚠️ 2 Active Exploits⚡ 1 Zero-Days🆕 1Fresh (<7d)📈 20 in Last 30 Days
Severity Distribution
Critical
53High
261Medium
605Low
9Exploit Likelihood
>50% chance
020-50%
15-20%
0<5%
66Age Distribution
Common Weaknesses (CWE)
1
CSRF
180
2
XSS
151
3
Path Traversal
50
4
XEE
35
5
Infoleak
15
Most Affected Products
1. Jenkins Jenkins241
2. redhat/jenkins221
3. maven/org.jenkins-ci.main:jenkins-core119
4. Jenkins Jenkins LTS35
5. Jenkins Pipeline\32
Recent Vulnerabilities
See more →CVE-2026-19429
CVSS 8.8high
Jenkins - FilePath.untarFrom() Symlink Target Validation Bypass and Blank-Name Check Bypass (Arbitrary File Read)
8/10/2026🔧 No Patch
CVE-2026-70447
CVSS 4.3medium
8/5/2026🔧 No Patch
CVE-2026-70445
CVSS 4.3medium
8/5/2026🔧 No Patch
CVE-2026-70446
CVSS 4.3medium
8/5/2026🔧 No Patch
CVE-2026-70444
CVSS 4.3medium
8/5/2026🔧 No Patch
CVE-2026-70442
CVSS 4.3medium
8/5/2026🔧 No Patch
CVE-2026-70441
CVSS 5.4medium
8/5/2026🔧 No Patch
CVE-2026-70439
CVSS 6.5medium
8/5/2026🔧 No Patch
CVE-2026-70438
CVSS 4.3medium
8/5/2026🔧 No Patch
CVE-2026-70437
CVSS 3.7low
8/5/2026🔧 No Patch
Monitor Jenkins in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.