Vulnerabilities

Summary — last 7 days

New vulnerabilities2,736▼ 336 vs. last week
Critical / high1,272▼ 222 vs. last week
New active exploitation (KEV)8→ no change vs. last week
Unscored (no CVSS)213▼ 108 vs. last week
–

1 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (7.5)1.1%—Jenkins Config Rotator11/15/20226/17/2026
Jenkins Config Rotator Plugin 2.0.1 and earlier does not restrict a file name query parameter in an HTTP endpoint, allowing unauthenticated attackers to read arbitrary files with '.xml' extension on the Jenkins controller file system.