Vulnerabilities

Summary — last 7 days

New vulnerabilities2,856▼ 216 vs. last week
Critical / high1,332▼ 166 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)223▼ 98 vs. last week
–

3 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (5.3)1.5%—Checkstyle1/30/20206/17/2026
All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to an incomplete fix for CVE-2019-9658.
ModifiedMedium (5.3)3.6%—CheckstyleDebian LinuxFedoraproject Fedora3/11/20196/17/2026
Checkstyle before 8.18 loads external DTDs by default.
ModifiedHigh (8.8)0.95%—Jenkins Checkstyle1/23/20186/17/2026
Jenkins Checkstyle Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forgery, or denial-of-service attacks.