jenkins
1,755 tracked vulnerabilities.
CVE-2021-21661
MEDIUM
Jenkins Kubernetes CLI Plugin <1.10.0 - Info Disclosure
Jun 10, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-21660
MEDIUM
Jenkins Markdown Formatter Plugin < 0.1.0 - Stored Cross-Site Scripting via Crafted Link Target URLs
May 25, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-21659
HIGH
Jenkins URLTrigger Plugin < 0.48 - XML External Entity Injection
May 25, 2021
CVSS 8.1
EPSS 0.00
CVE-2021-21658
CRITICAL
Jenkins Nuget Plugin < 1.0 - XML External Entity Injection
May 25, 2021
CVSS 9.1
EPSS 0.01
CVE-2021-21657
HIGH
Jenkins Filesystem Trigger Plugin < 0.40 - XML External Entity Injection
May 25, 2021
CVSS 8.8
EPSS 0.00
CVE-2021-21656
HIGH
Jenkins Xcode integration Plugin < 2.0.14 - XML External Entity Injection
May 11, 2021
CVSS 7.1
EPSS 0.00
CVE-2021-21655
HIGH
Jenkins P4 Plugin < 1.11.4 - Cross-Site Request Forgery
May 11, 2021
CVSS 7.1
EPSS 0.00
CVE-2021-21654
MEDIUM
Jenkins P4 Plugin <1.11.4 - Privilege Escalation
May 11, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-21653
MEDIUM
Jenkins Xray - Test Management for Jira Plugin <2.4.0 - Info Disclo...
May 11, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-21652
HIGH
Jenkins Xray - Test Management for Jira < 2.4.0 - Cross-Site Request Forgery
May 11, 2021
CVSS 7.1
EPSS 0.00
CVE-2021-21651
MEDIUM
Jenkins S3 publisher Plugin <0.11.6 - Info Disclosure
May 11, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-21650
MEDIUM
Jenkins S3 publisher Plugin <0.11.6 - Info Disclosure
May 11, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-21649
MEDIUM
Jenkins Dashboard View Plugin < 2.15 - Stored Cross-Site Scripting via Image Dashboard Portlet URL
May 11, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-21648
MEDIUM
Jenkins Credentials Plugin < 2.3.18 - Reflected Cross-Site Scripting
May 11, 2021
CVSS 6.1
EPSS 0.00
CVE-2021-21647
MEDIUM
Jenkins CloudBees CD Plugin <1.1.21 - Privilege Escalation
Apr 21, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-21646
HIGH
Jenkins Templating Engine Plugin <2.1 - RCE
Apr 21, 2021
CVSS 8.8
EPSS 0.00
CVE-2021-21645
MEDIUM
Jenkins Config File Provider Plugin <3.7.0 - Info Disclosure
Apr 21, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-21644
MEDIUM
Jenkins Config File Provider Plugin < 3.7.0 - Cross-Site Request Forgery via Configuration File Deletion
Apr 21, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-21643
MEDIUM
Jenkins Config File Provider Plugin <3.7.0 - Info Disclosure
Apr 21, 2021
CVSS 6.5
EPSS 0.01
CVE-2021-21642
HIGH
Jenkins Config File Provider Plugin < 3.7.0 - XML External Entity Injection
Apr 21, 2021
CVSS 8.1
EPSS 0.00
CVE-2021-21641
MEDIUM
Jenkins promoted builds < 3.9 - Cross-Site Request Forgery
Apr 07, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-21640
MEDIUM
Jenkins <2.286-<2.277.1 - Info Disclosure
Apr 07, 2021
CVSS 4.3
EPSS 0.01
CVE-2021-21639
MEDIUM
Jenkins <2.286-<2.277.1 - Privilege Escalation
Apr 07, 2021
CVSS 4.3
EPSS 0.01
CVE-2021-28165
HIGH
Eclipse Jetty 7.2.2-9.4.38, 10.0.0.alpha0-10.0.1, 11.0.0.alpha0-11.0.1 - Denial of Service via Invalid TLS Frame
Apr 01, 2021
CVSS 7.5
EPSS 0.14
CVE-2021-21638
HIGH
Jenkins Team Foundation Server Plugin < 5.157.1 - Cross-Site Request Forgery
Mar 30, 2021
CVSS 8.8
EPSS 0.00
Products
jenkins 259
pipeline\ 37
script_security 33
blue_ocean 11
git 11
email_extension 10
active_directory 9
build_failure_analyzer 9
config_file_provider 9
configuration_as_code 9
ns-nd_integration_performance_publisher 8
credentials_binding 7
github_branch_source 7
html_publisher 7
kubernetes 7
openid_connect_authentication 7
openshift_deployer 7
rundeck 7
subversion 7
amazon_ec2 6
azure_ad 6
azure_vm_agents 6
deployment_dashboard 6
electricflow 6
gerrit_trigger 6
github 6
github_pull_request_builder 6
gitlab 6
google_compute_engine 6
hashicorp_vault 6
Quick Filters