Vulnerabilities
Summary — last 7 days
New vulnerabilities2,774▼ 324 vs. last week
Critical / high1,284▼ 239 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)214▼ 107 vs. last week
2 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Critical (9.8) | 3.9% | — | Get-npm-package-version Project Get-npm-package-version | 8/2/2022 | 6/17/2026 | The package get-npm-package-version before 1.0.7 are vulnerable to Command Injection via main function in index.js. | |
| Modified | Medium (5.4) | 0.64% | — | Jenkins Package Version | 6/23/2022 | 6/17/2026 | Jenkins Package Version Plugin 1.0.1 and earlier does not escape the name of Package version parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. |