Vulnerabilities
Summary — last 7 days
New vulnerabilities2,950▲ 8 vs. last week
Critical / high1,450▲ 184 vs. last week
New active exploitation (KEV)5▼ 3 vs. last week
Unscored (no CVSS)272▼ 254 vs. last week
3 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (6.5) | 1.5% | — | Jenkins FTP Publisher | 4/4/2019 | 6/17/2026 | A missing permission check in Jenkins FTP publisher Plugin in the FTPPublisher.DescriptorImpl#doLoginCheck method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server. | |
| Modified | Medium (6.5) | 1.3% | — | Jenkins FTP Publisher | 4/4/2019 | 6/17/2026 | A cross-site request forgery vulnerability in Jenkins FTP publisher Plugin in the FTPPublisher.DescriptorImpl#doLoginCheck method allows attackers to initiate a connection to an attacker-specified server. | |
| Modified | High (8.8) | 1.3% | — | Jenkins FTP Publisher | 4/4/2019 | 6/17/2026 | Jenkins FTP publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. |