Vulnerabilities
Summary — last 7 days
New vulnerabilities2,856▼ 216 vs. last week
Critical / high1,332▼ 166 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)223▼ 98 vs. last week
3 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (5.3) | 1.5% | — | Checkstyle | 1/30/2020 | 6/17/2026 | All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to an incomplete fix for CVE-2019-9658. | |
| Modified | Medium (5.3) | 3.6% | — | CheckstyleDebian LinuxFedoraproject Fedora | 3/11/2019 | 6/17/2026 | Checkstyle before 8.18 loads external DTDs by default. | |
| Modified | High (8.8) | 0.95% | — | Jenkins Checkstyle | 1/23/2018 | 6/17/2026 | Jenkins Checkstyle Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forgery, or denial-of-service attacks. |