Vulnerabilities
Summary — last 7 days
New vulnerabilities2,628▼ 312 vs. last week
Critical / high1,351▲ 89 vs. last week
New active exploitation (KEV)5▼ 3 vs. last week
Unscored (no CVSS)64▼ 462 vs. last week
1 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | Low (3.7) | 0.27% | — | Jenkins Webhook Secret Credentials Provider PluginAI | 8/5/2026 | 8/31/2026 | Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison function when checking whether the provided and expected webhook bearer token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook bearer token. |