Skip to main content

Daily materialized evidence profile

Vendor jenkins

This factual profile is rebuilt from stored cvebuzz evidence each day. It is a timestamped snapshot, not an immutable publication.

Refreshed UTC

Stored evidence summary

Sample size
1,797
CVEs with mentions
138
Total mentions
231
CVEs with KEV
6
CVEs with PoC
0

Attack vector counts

Network
1,736
Adjacent network
2
Local
59
Physical
0

Top snapshot Buzz entries

Up to five denormalized entries captured by the same daily profile refresh.

CVE-2024-23897

Published Jan 24, 2024

Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with…

CVSS 9.8 · Critical
evidence mentions
16
Buzz score
72.8
KEV listed

CVE-2018-1000861

Published Dec 10, 2018

A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/Met…

CVSS 9.8 · Critical
evidence mentions
12
Buzz score
65.2
KEV listed

CVE-2017-1000353

Published Jan 29, 2018

Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerabil…

CVSS 9.8 · Critical
evidence mentions
7
Buzz score
58.8
KEV listed

CVE-2015-5317

Published Nov 25, 2015

The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information via a direct request.

CVSS 7.5 · High
evidence mentions
2
Buzz score
42.5
KEV listed

CVE-2026-33001

Published Mar 18, 2026

Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write fil…

CVSS 8.8 · High
evidence mentions
14
Buzz score
40.1