Vulnerabilities
Summary — last 7 days
New vulnerabilities3,338▲ 363 vs. last week
Critical / high1,493▲ 135 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 119 vs. last week
4 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | Medium (5.4) | 0.23% | — | Jenkins Gitlab PluginAI | 9/16/2026 | 9/18/2026 | Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API token credentials under a cache key derived from the credentials ID alone, omitting the folder in which the credentials are resolved, allowing attackers with Item/Configure permission to access GitLab… | |
| Awaiting Analysis | Medium (5.4) | 0.14% | — | Jenkins Gitlab PluginAI | 9/2/2026 | 9/3/2026 | Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global GitLab connection configuration through Stapler data binding, allowing attackers to connect to an attacker-specified URL using GitLab API tokens already configured by administrators. | |
| Awaiting Analysis | Medium (4.3) | 0.29% | — | MattermostAIMattermost Gitlab PluginAI | 8/17/2026 | 8/18/2026 | Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost GitLab plugin fails to verify channel permissions when processing API requests with a caller-supplied_ {{post_id}}_, and fails to validate the_ {{web_url}} _parameter against the configured GitLab instance, which allows an authenticated attacker to… | |
| Awaiting Analysis | Medium (4.3) | 0.29% | — | Jenkins Violation Comments TO Gitlab PluginAI | 8/5/2026 | 8/31/2026 | A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. |