Vulnerabilities
Summary — last 7 days
New vulnerabilities2,833▲ 79 vs. last week
Critical / high1,316▼ 206 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)246▲ 228 vs. last week
3 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (4.3) | 0.35% | — | Jenkins Dingding Json Pusher | 12/13/2023 | 6/17/2026 | Jenkins Dingding JSON Pusher Plugin 2.0 and earlier does not mask access tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them. | |
| Modified | Medium (4.3) | 0.35% | — | Jenkins Dingding Json Pusher | 12/13/2023 | 6/17/2026 | Jenkins Dingding JSON Pusher Plugin 2.0 and earlier stores access tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system. | |
| Modified | Low (3.3) | 0.41% | — | Jenkins Dingding | 10/1/2019 | 6/17/2026 | Jenkins Dingding[钉钉] Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system. |