CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
6 results Clear all
CVE-2023-24436 4.3 MEDIUM EPSS 0.00
Jenkins GitHub Pull Request Builder Plugin <1.42.2 - Info Disclosure
A missing permission check in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
CWE-862 Jan 26, 2023
CVE-2023-24435 6.5 MEDIUM EPSS 0.00
Jenkins GitHub Pull Request Builder Plugin <1.42.2 - SSRF
A missing permission check in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
CWE-862 Jan 26, 2023
CVE-2023-24434 8.8 HIGH EPSS 0.00
Jenkins GitHub Pull Request Builder Plugin <1.42.2 - CSRF
A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
CWE-352 Jan 26, 2023
CVE-2018-1000186 6.5 MEDIUM EPSS 0.00
Jenkins GitHub Pull Request Builder Plugin <1.41.0 - Info Disclosure
A exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin 1.41.0 and older in GhprbGitHubAuth.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
CWE-200 Jun 05, 2018
CVE-2018-1000143 6.7 MEDIUM EPSS 0.00
Jenkins GitHub Pull Request Builder Plugin <1.39.0 - Info Disclosure
An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 and older in GhprbCause.java that allows an attacker with local file system access to obtain GitHub credentials.
CWE-200 Apr 05, 2018
CVE-2018-1000142 7.8 HIGH EPSS 0.00
Jenkins GitHub Pull Request Builder Plugin <1.39.0 - Info Disclosure
An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 and older in GhprbCause.java that allows an attacker with local file system access to obtain GitHub credentials.
CWE-200 Apr 05, 2018