VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 20 hours ago
Reset
More filters (1)
Columns
Oracle product: Oracle Communications / Alarms, KPI, and Measurements (Jenkins)
Overview 5 matches, all in RASP scope · 2 protected · 1 KEV · 2 public PoC · 1 CISA SSVC · 1 EPSS ≥ 0.5 · 0 disputed
5matches, all in RASP scope 2protected40.0% 1KEV20.0% 2public PoC40.0% 1CISA SSVC20.0% 1EPSS ≥ 0.520.0% 0disputed0.0%
Critical 1 20.0% High 2 40.0% Medium 2 40.0% Low 0 0.0% None 0 0.0% Unknown 0 0.0%
Protected by RASP 2 40.0% Rule in development 0 0.0% Mitigation candidate 0 0.0% No exploit published 3 60.0% No fix identified 0 0.0% Mitigated by environment configuration 0 0.0% Queued for review 0 0.0% Not applicable 0 0.0% Out of RASP scope 0 0.0% Rejected 0 0.0%
blocked by ARMR today 2 40.0% not blocked 3 60.0% not established 0 0.0% unrecorded 0 0.0%
split by peak 1 / quarter
Unknown: 0None: 0Low: 0Medium: 2High: 2Critical: 1 Rejected: 0Out of RASP scope: 0Not applicable: 0Queued for review: 0Mitigated by environment configuration: 0No fix identified: 0No exploit published: 3Mitigation candidate: 0Rule in development: 0Protected by RASP: 2 unrecorded: 0not established: 0not blocked: 3blocked by ARMR today: 2 No public exploit: 3Forecast only: 0Proof of concept only: 1Working exploit published: 0Exploited in the wild: 1 Q1 2024: 1 CVE Q2 2024: 0 CVEs Q3 2024: 1 CVE Q4 2024: 1 CVE Q1 2025: 0 CVEs Q2 2025: 1 CVE Q3 2025: 0 CVEs Q4 2025: 0 CVEs Q1 2026: 1 CVE
Q1 24Q2 24Q3 24Q4 24Q1 25Q2 25Q3 25Q4 25Q1 26
5 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2026-27099 High 2026-02-18 No exploit published No public exploit Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of the "Mark temporarily offline" offline cause, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure or Agent/Disconnect permission.
CVE-2025-31721 Medium 2025-04-02 No exploit published No public exploit A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Configure permission to copy an agent, gaining access to encrypted secrets in its configuration.
CVE-2024-47804 Medium 2024-10-02 No exploit published No public exploit If an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#isApplicableIn(ItemGroup)` through the Jenkins CLI or the REST API and either of these checks fail, Jenkins 2.478 and earlier, LTS 2.462.2 and earlier creates the item in memory, only deleting it from disk, allowing attackers with Item/Configure permission to save the item to persist it, effectively bypassing the item creation restriction.
CVE-2024-43044 High 2024-08-07 Protected by RASP Proof of concept only Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using the `ClassLoaderProxy#fetchJar` method in the Remoting library.
CVE-2024-23897 Critical 2024-01-24 Protected by RASP Exploited in the wild Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.