org.jenkins-ci.plugins
1,024 tracked vulnerabilities.
CVE-2024-2215
MEDIUM
Jenkins docker-build-step Plugin <2.11 - CSRF
Mar 06, 2024
CVSS 6.1
EPSS 0.00
CVE-2024-28162
MEDIUM
Jenkins Delphix Plugin 3.0.1-3.1.0 - Improper Certificate Validation in Data Control Tower Connections
Mar 06, 2024
CVSS 4.2
EPSS 0.00
CVE-2024-28161
MEDIUM
Jenkins Delphix Plugin 3.0.1 - Improper Certificate Validation
Mar 06, 2024
CVSS 5.3
EPSS 0.00
CVE-2024-28160
HIGH
Jenkins iceScrum Plugin < 1.1.6 - Stored Cross-Site Scripting via Project URL
Mar 06, 2024
CVSS 8.8
EPSS 0.01
CVE-2024-28159
MEDIUM
Jenkins Subversion Partial Release Manager Plugin <= 1.0.1 - Missing Authorization
Mar 06, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-28158
MEDIUM
Jenkins Subversion Partial Release Manager Plugin < 1.0.1 - Cross-Site Request Forgery
Mar 06, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-28157
HIGH
Jenkins GitBucket Plugin <= 0.8 - Stored Cross-Site Scripting in Build Views
Mar 06, 2024
CVSS 8.0
EPSS 0.04
CVE-2024-28156
MEDIUM
Jenkins Build Monitor View Plugin < 1.14-860.vd06ef2568b_3f - Stored Cross-Site Scripting via Unescaped View Names
Mar 06, 2024
CVSS 5.4
EPSS 0.39
CVE-2024-28153
MEDIUM
Jenkins OWASP Dependency-Check Plugin < 5.4.6 - Stored Cross-Site Scripting via Unescaped Vulnerability Metadata
Mar 06, 2024
CVSS 5.4
EPSS 0.01
CVE-2024-28152
MEDIUM
Jenkins Bitbucket Branch Source Plugin <866.vdea_7dcd3008e - Info D...
Mar 06, 2024
CVSS 6.3
EPSS 0.00
CVE-2024-28151
MEDIUM
Jenkins HTML Publisher Plugin <= 1.32 - Path Traversal via Symbolic Link Handling
Mar 06, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-28150
MEDIUM
Jenkins HTML Publisher Plugin < 1.32.1 - Stored Cross-Site Scripting via Job Names and Report Titles
Mar 06, 2024
CVSS 4.7
EPSS 0.00
CVE-2024-28149
MEDIUM
Jenkins HTML Publisher Plugin 1.16-1.32 - Cross-Site Scripting via Improper Input Sanitization
Mar 06, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-23904
HIGH
Jenkins Log Command Plugin < 1.0.2 - Unauthenticated Arbitrary File Read via Command Parser
Jan 24, 2024
CVSS 7.5
EPSS 0.00
CVE-2024-23900
MEDIUM
Jenkins Matrix Project Plugin <822.v01b_8c85d16d2 - Privilege Escal...
Jan 24, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-23899
MEDIUM
Jenkins Git Server Plugin < 99.va_0826a_b_cdfa_d - Arbitrary File Read via Command Parser
Jan 24, 2024
CVSS 6.5
EPSS 0.00
CVE-2023-50775
MEDIUM
Jenkins Deployment Dashboard Plugin < 1.0.10 - Cross-Site Request Forgery
Dec 13, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-50774
HIGH
Jenkins HTMLResource Plugin 1.02 - Cross-Site Request Forgery
Dec 13, 2023
CVSS 8.1
EPSS 0.00
CVE-2023-50771
MEDIUM
Jenkins OpenId Connect Authentication Plugin < 2.6 - Open Redirect via Login Redirect URL
Dec 13, 2023
CVSS 6.1
EPSS 0.00
CVE-2023-50770
MEDIUM
Jenkins OpenId Connect Authentication Plugin < 2.6 - Insufficiently Protected Credentials
Dec 13, 2023
CVSS 6.7
EPSS 0.00
CVE-2023-50765
MEDIUM
Jenkins Scriptler Plugin < 342.v6a_89fd40f466 - Unauthorized Groovy Script Content Read via Script ID
Dec 13, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-50764
HIGH
Jenkins Scriptler Plugin <342.v6a_89fd40f466 - File Deletion
Dec 13, 2023
CVSS 8.1
EPSS 0.00
CVE-2023-49656
CRITICAL
Jenkins MATLAB Plugin < 2.11.1 - XML External Entity Injection
Nov 29, 2023
CVSS 9.8
EPSS 0.00
CVE-2023-49655
HIGH
Jenkins MATLAB Plugin < 2.11.1 - Cross-Site Request Forgery
Nov 29, 2023
CVSS 8.8
EPSS 0.00
CVE-2023-49654
CRITICAL
Jenkins MATLAB Plugin < 2.11.1 - Unauthenticated XML File Parsing via Missing Permission Checks
Nov 29, 2023
CVSS 9.8
EPSS 0.00
Products
script-security 35
git 13
email-ext 11
active-directory 9
config-file-provider 9
electricflow 9
ec2 8
oic-auth 8
subversion 8
artifactory 7
credentials-binding 7
htmlpublisher 7
jobConfigHistory 7
mercurial 7
openshift-deployer 7
rundeck 7
azure-ad 6
azure-vm-agents 6
ec2-deployment-dashboard 6
fortify-on-demand-uploader 6
ghprb 6
gitlab-oauth 6
gitlab-plugin 6
pipeline-maven 6
repository-connector 6
aws-codecommit-trigger 5
codedx 5
credentials 5
delphix 5
extended-choice-parameter 5
Quick Filters