CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
5 results Clear all
CVE-2022-29038 5.4 MEDIUM EPSS 0.18
Jenkins Extended Choice Parameter Plugin <346.vd87693c5a_86c - XSS
Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier does not escape the name and description of Extended Choice parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
CWE-79 Apr 12, 2022
CVE-2022-27205 4.3 MEDIUM EPSS 0.00
Jenkins Extended Choice Parameter - Missing Authorization
A missing permission check in Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.
CWE-862 Mar 15, 2022
CVE-2022-27204 8.8 HIGH EPSS 0.00
Jenkins Extended Choice Parameter < 346.vd87693c5a_86c - CSRF
A cross-site request forgery vulnerability in Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers to connect to an attacker-specified URL.
CWE-352 Mar 15, 2022
CVE-2022-27203 6.5 MEDIUM EPSS 0.01
Jenkins Extended Choice Parameter - Path Traversal
Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers with Item/Configure permission to read values from arbitrary JSON and Java properties files on the Jenkins controller.
CWE-22 Mar 15, 2022
CVE-2022-27202 5.4 MEDIUM EPSS 0.05
Jenkins Extended Choice Parameter < 346.vd87693c5a_86c - XSS
Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier does not escape the value and description of extended choice parameters of radio buttons or check boxes type, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
CWE-79 Mar 15, 2022