Export limit exceeded: 343843 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 75291 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (75291 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-2200 1 Jenkins 1 Play Framework 2024-11-21 8.8 High
Jenkins Play Framework Plugin 1.0.2 and earlier lets users specify the path to the `play` command on the Jenkins master for a form validation endpoint, resulting in an OS command injection vulnerability exploitable by users able to store such a file on the Jenkins master.
CVE-2020-2196 1 Jenkins 1 Selenium 2024-11-21 8.0 High
Jenkins Selenium Plugin 3.141.59 and earlier has no CSRF protection for its HTTP endpoints, allowing attackers to perform all administrative actions provided by the plugin.
CVE-2020-2189 1 Jenkins 1 Source Code Management Filter Jervis 2024-11-21 8.8 High
Jenkins SCM Filter Jervis Plugin 0.2.1 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
CVE-2020-2180 1 Jenkins 1 Amazon Web Services Serverless Application Model 2024-11-21 8.8 High
Jenkins AWS SAM Plugin 1.2.2 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
CVE-2020-2179 1 Jenkins 1 Yaml Axis 2024-11-21 8.8 High
Jenkins Yaml Axis Plugin 0.2.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
CVE-2020-2178 1 Jenkins 1 Parasoft Findings 2024-11-21 7.1 High
Jenkins Parasoft Findings Plugin 10.4.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2171 1 Jenkins 1 Rapiddeploy 2024-11-21 8.8 High
Jenkins RapidDeploy Plugin 4.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2168 1 Jenkins 1 Azure Container Service 2024-11-21 8.8 High
Jenkins Azure Container Service Plugin 1.0.1 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
CVE-2020-2167 2 Jenkins, Redhat 2 Openshift Pipeline, Openshift 2024-11-21 8.8 High
Jenkins OpenShift Pipeline Plugin 1.0.56 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
CVE-2020-2166 1 Jenkins 1 Pipeline\ 2024-11-21 8.8 High
Jenkins Pipeline: AWS Steps Plugin 1.40 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
CVE-2020-2165 1 Jfrog 1 Artifactory 2024-11-21 7.5 High
Jenkins Artifactory Plugin 3.6.0 and earlier transmits configured passwords in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
CVE-2020-2160 2 Jenkins, Redhat 2 Jenkins, Openshift 2024-11-21 8.8 High
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that allow bypassing CSRF protection of any target URL.
CVE-2020-2159 1 Jenkins 1 Cryptomove 2024-11-21 8.8 High
Jenkins CryptoMove Plugin 0.1.33 and earlier allows attackers with Job/Configure access to execute arbitrary OS commands on the Jenkins master as the OS user account running Jenkins.
CVE-2020-2158 1 Jenkins 1 Literate 2024-11-21 8.8 High
Jenkins Literate Plugin 1.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
CVE-2020-2146 1 Jenkins 1 Mac 2024-11-21 7.4 High
Jenkins Mac Plugin 1.1.0 and earlier does not validate SSH host keys when connecting agents created by the plugin, enabling man-in-the-middle attacks.
CVE-2020-2144 1 Jenkins 1 Rundeck 2024-11-21 7.1 High
Jenkins Rundeck Plugin 3.6.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2138 1 Jenkins 1 Cobertura 2024-11-21 7.1 High
Jenkins Cobertura Plugin 1.15 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2135 2 Jenkins, Redhat 2 Script Security, Openshift 2024-11-21 8.8 High
Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted method calls on objects that implement GroovyInterceptable.
CVE-2020-2134 2 Jenkins, Redhat 2 Script Security, Openshift 2024-11-21 8.8 High
Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted constructor calls and crafted constructor bodies.
CVE-2020-2123 1 Jenkins 1 Radargun 2024-11-21 8.8 High
Jenkins RadarGun Plugin 1.7 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.