Vulnerabilities

Summary — last 7 days

New vulnerabilities2,833▲ 192 vs. last week
Critical / high1,314▼ 122 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)250▲ 236 vs. last week
–

2 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedMedium (5.9)0.32%—Jenkins Eggplant Runner10/29/202510/8/2026
Jenkins Eggplant Runner Plugin 0.0.1.301.v963cffe8ddb_8 and earlier sets the Java system property `jdk.http.auth.tunneling.disabledSchemes` to an empty value, disabling a protection mechanism of the Java runtime.
ModifiedMedium (6.5)1.5%—Jenkins Eggplant8/7/20196/17/2026
Jenkins eggPlant Plugin 2.2 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
Orbitaley — Vulnerabilities