Vulnerabilities
Summary — last 7 days
New vulnerabilities3,185▲ 600 vs. last week
Critical / high1,508▲ 101 vs. last week
New active exploitation (KEV)5▼ 1 vs. last week
Unscored (no CVSS)238▲ 224 vs. last week
3 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | Medium (4.2) | 0.19% | — | Jenkins Scm-manager PluginAI | 8/5/2026 | 8/31/2026 | A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Awaiting Analysis | Medium (4.2) | 0.11% | — | Jenkins Scm-manager PluginAI | 8/5/2026 | 8/31/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modified | Medium (5.4) | 7.3% | 💥 Exploit | Cloudogu SCM Manager | 5/24/2023 | 6/17/2026 | A stored cross-site scripting (XSS) vulnerability in Cloudogu GmbH SCM Manager v1.2 to v1.60 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description text field. |