Vulnerabilities
Summary — last 7 days
New vulnerabilities3,142▲ 566 vs. last week
Critical / high1,456▲ 54 vs. last week
New active exploitation (KEV)5▼ 1 vs. last week
Unscored (no CVSS)301▲ 287 vs. last week
1 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | High (8.8) | 0.68% | — | Jenkins Poll SCM | 10/5/2017 | 6/17/2026 | Poll SCM Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks. This allowed attackers to initiate polling of projects with a known name. While Jenkins in general does not consider polling to be a protection-worthy action as it's similar to cache… |