CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-92141 MEDIUM

Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

CVSS 4.3 EPSS 0.33% Sep 16, 2026
CVE-2026-92140 MEDIUM

Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in build causes, resulting in a stored cro…

CVSS 6.8 EPSS 0.43% Sep 16, 2026
CVE-2026-92139 MEDIUM

Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, including certain URLs, and uses configured Bit…

CVSS 6.5 EPSS 0.25% Sep 16, 2026
CVE-2026-92138 MEDIUM

The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `oauth_callback` URL from the submitted form rather…

CVSS 4.2 EPSS 0.11% Sep 16, 2026
CVE-2026-92137 HIGH

Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot Framework report files is contained within the…

CVSS 8.8 EPSS 0.83% Sep 16, 2026
CVE-2026-92136 HIGH

Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the Jenkins UI, resulting in a stored cross…

CVSS 8.0 EPSS 0.41% Sep 16, 2026
CVE-2026-92133 MEDIUM

Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API token credentials under a cache key deriv…

CVSS 5.4 EPSS 0.23% Sep 16, 2026
CVE-2026-92132 MEDIUM

Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected in the build log, even when a Develocity…

CVSS 5.4 EPSS 0.25% Sep 16, 2026
CVE-2026-92131 MEDIUM

Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to the library Pipeline step to a relative…

CVSS 4.2 EPSS 0.23% Sep 16, 2026
CVE-2026-92130 LOW

Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials lookup in the resolveScm Pipeline step…

CVSS 3.1 EPSS 0.22% Sep 16, 2026
CVE-2026-92129 HIGH

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods added dynamically to a class at runtime…

CVSS 7.5 EPSS 0.48% Sep 16, 2026
CVE-2026-92128 HIGH

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirming the approval of the first download and…

CVSS 7.5 EPSS 0.29% Sep 16, 2026
CVE-2026-92127 HIGH

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item configuration when a user with Overall…

CVSS 8.0 EPSS 0.61% Sep 16, 2026
CVE-2026-92126 HIGH

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrategy member names an arbitrary class, al…

CVSS 7.2 EPSS 0.62% Sep 16, 2026
CVE-2026-92125 HIGH

org.jenkins-ci.plugins/script-security: Jenkins Script Security Plugin: Arbitrary code execution via Groovy AST transformation bypass

CVSS 8.8 EPSS 0.56% Sep 16, 2026
CVE-2026-92124 HIGH

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elements it reads from a collection that a…

CVSS 8.8 EPSS 0.63% Sep 16, 2026
CVE-2026-92123 HIGH

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiver (method calls, property and attribu…

CVSS 8.8 EPSS 0.63% Sep 16, 2026
CVE-2026-92122 HIGH

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created when a sandboxed script coerces a v…

CVSS 8.8 EPSS 0.63% Sep 16, 2026
CVE-2026-84677 MEDIUM

Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided values (plugin names, descriptions, and version metadata) on plugin download index pa…

CVSS 5.4 EPSS 0.23% Sep 2, 2026
CVE-2026-84676 MEDIUM

Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be vie…

CVSS 4.3 EPSS 0.19% Sep 2, 2026
CVE-2026-84675 HIGH

OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control build environment variable values to execute ar…

CVSS 7.4 EPSS 1.16% Sep 2, 2026
CVE-2026-84674 MEDIUM

Missing permission checks in Jenkins XebiaLabs XL Deploy Plugin 26.1.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of…

CVSS 5.4 EPSS 0.23% Sep 2, 2026
CVE-2026-84673 HIGH

Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows overwriting the plugin's appearance configuration through Stapler data binding, allo…

CVSS 8.8 EPSS 0.51% Sep 2, 2026
CVE-2026-84672 HIGH

Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique object ID a…

CVSS 8.8 EPSS 0.42% Sep 2, 2026
CVE-2026-84671 HIGH

Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier allows writing files to arbitrary locations on the Jenkins controller file system through Stapler…

CVSS 8.8 EPSS 0.83% Sep 2, 2026

Showing 1 to 25 CVEs · page 1 (more available)