Vulnerabilities

Summary — last 7 days

New vulnerabilities2,751▼ 38 vs. last week
Critical / high1,262▼ 270 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)246▲ 209 vs. last week
–

2 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (8.5)1.1%—Jenkins Pipeline Classpath Step7/27/20186/17/2026
It was found that the use of Pipeline: Classpath Step Jenkins plugin enables a bypass of the Script Security sandbox for users with SCM commit access, as well as users with e.g. Job/Configure permission in Jenkins.
ModifiedHigh (7.5)3.3%💥 ExploitGNU Classpath12/17/20086/16/2026
The gnu.java.security.util.PRNG class in GNU Classpath 0.97.2 and earlier uses a predictable seed based on the system time, which makes it easier for context-dependent attackers to conduct brute force attacks against cryptographic routines that use this class for randomness, as demonstrated against DSA private keys.
Orbitaley — Vulnerabilities