Vulnerabilities
Summary — last 7 days
New vulnerabilities2,833▲ 192 vs. last week
Critical / high1,314▼ 122 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)250▲ 236 vs. last week
2 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | Medium (5.9) | 0.32% | — | Jenkins Eggplant Runner | 10/29/2025 | 10/8/2026 | Jenkins Eggplant Runner Plugin 0.0.1.301.v963cffe8ddb_8 and earlier sets the Java system property `jdk.http.auth.tunneling.disabledSchemes` to an empty value, disabling a protection mechanism of the Java runtime. | |
| Modified | Medium (6.5) | 1.5% | — | Jenkins Eggplant | 8/7/2019 | 6/17/2026 | Jenkins eggPlant Plugin 2.2 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system. |