CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2026-57288 LOW

Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI) authentica…

CVSS 3.7 EPSS 0.33% Jun 24, 2026
CVE-2026-48919 MEDIUM

Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.

CVSS 6.6 EPSS 0.43% May 27, 2026
CVE-2026-48918 MEDIUM

Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default.

CVSS 6.6 EPSS 0.37% May 27, 2026
CVE-2023-37943 MEDIUM

Jenkins Active Directory Plugin 2.30 and earlier ignores the "Require TLS" and "StartTls" options and always performs the connection test to Active directory u…

CVSS 5.9 EPSS 0.46% Jul 12, 2023
CVE-2022-23105 MEDIUM

Jenkins Active Directory Plugin 2.25 and earlier does not encrypt the transmission of data between the Jenkins controller and Active Directory servers in most…

CVSS 6.5 EPSS 0.45% Jan 12, 2022
CVE-2020-2303 MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins Active Directory Plugin 2.19 and earlier allows attackers to perform connection tests, connecting…

CVSS 4.3 EPSS 0.68% Nov 4, 2020
CVE-2020-2302 MEDIUM

A missing permission check in Jenkins Active Directory Plugin 2.19 and earlier allows attackers with Overall/Read permission to access the domain health check…

CVSS 4.3 EPSS 0.68% Nov 4, 2020
CVE-2020-2301 CRITICAL

Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user with any password while a successful authentication of that user is sti…

CVSS 9.8 EPSS 1.70% Nov 4, 2020
CVE-2020-2300 CRITICAL

Jenkins Active Directory Plugin 2.19 and earlier does not prohibit the use of an empty password in Windows/ADSI mode, which allows attackers to log in to Jenki…

CVSS 9.8 EPSS 1.67% Nov 4, 2020
CVE-2020-2299 CRITICAL

Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user if a magic constant is used as the password.

CVSS 9.8 EPSS 1.34% Nov 4, 2020
CVE-2019-1003009 HIGH

An improper certificate validation vulnerability exists in Jenkins Active Directory Plugin 2.10 and earlier in src/main/java/hudson/plugins/active_directory/Ac…

CVSS 7.4 EPSS 0.78% Feb 6, 2019
CVE-2017-2649 HIGH

It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby e…

CVSS 8.1 EPSS 0.96% Jul 27, 2018

Showing 1 to 12 CVEs · page 1