Filter
AND
-Infinity
0

maven/org.jenkins-ci.main:jenkins-coreIn Jenkins 2.499 and earlier, LTS 2.492.1 and earlier, redirects starting with backslash (`\`) chara…

EPSS
0.06%
First published (updated )

maven/org.jenkins-ci.main:jenkins-coreCSRF

EPSS
0.04%
First published (updated )

maven/org.jenkins-ci.main:jenkins-coreJenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when …

EPSS
0.04%
First published (updated )

maven/org.jenkins-ci.main:jenkins-coreJenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when …

EPSS
0.04%
First published (updated )

maven/org.jenkins-ci.plugins:jiraJenkins Jira Plugin 3.11 and earlier does not set the appropriate context for credentials lookup, al…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

maven/org.jenkins-ci.plugins:gogs-webhookJenkins Gogs Plugin 1.0.15 and earlier uses a non-constant time comparison function when checking wh…

First published (updated )

maven/org.jenkins-ci.plugins:lambdatest-automationJenkins lambdatest-automation Plugin 1.20.10 and earlier logs LAMBDATEST Credentials access token at…

First published (updated )

maven/org.jenkins-ci.plugins:lambdatest-automationA missing permission check in Jenkins lambdatest-automation Plugin 1.20.9 and earlier allows attacke…

First published (updated )

JenkinsArbitrary File Read in Fusion File Manager

First published (updated )

maven/org.jenkins-ci.plugins:gogs-webhookInfoleak

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

maven/org.jenkins-ci.plugins:gogs-webhookJenkins Gogs Plugin 1.0.15 and earlier improperly initializes an option to secure its webhook endpoi…

First published (updated )

maven/org.jenkins-ci.plugins:bazaarCSRF

First published (updated )

maven/org.jenkins-ci.plugins:sidebar-linkPath Traversal

First published (updated )

redhat/jenkinsXSS

First published (updated )

JenkinsJenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier stores the private keys unencry…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

JenkinsA missing permission check in Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier a…

First published (updated )

JenkinsJenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier transmits the private key in pl…

First published (updated )

maven/org.jenkins-ci.plugins:sonar-gerritCSRF

First published (updated )

maven/org.jenkins-ci.plugins:delete-log-pluginCSRF

First published (updated )

maven/org.jenkins-ci.plugins:delete-log-pluginA missing permission check in Jenkins Delete log Plugin 1.0 and earlier allows attackers with Item/R…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

JenkinsXSS

First published (updated )

maven/org.jenkins-ci.plugins:nunitJenkins NUnit Plugin 0.27 and earlier implements an agent-to-controller message that parses files in…

First published (updated )

JenkinsXSS

First published (updated )

JenkinsXSS

First published (updated )

JenkinsJenkins Rundeck Plugin 3.6.11 and earlier does not perform Run/Artifacts permission checks in multip…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

redhat/jenkinsJenkins GitHub Plugin 1.34.4 and earlier uses a non-constant time comparison function when checking …

First published (updated )

JenkinsXSS

First published (updated )

JenkinsXSS

First published (updated )

redhat/jenkinsXSS

First published (updated )

JenkinsA missing permission check in Jenkins SSH Plugin 2.6.1 and earlier allows attackers with Overall/Rea…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203