CVE Tools

Cd-foundation

144 CVEs tracked since 2019. Since Feb 2019, 1 of them reached CISA KEV.

Cd-foundation CVEs per month

Feb 2019 to Dec 2025. Point at a month, or focus the strip and use the arrow keys.
Cd-foundation CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2019-0220
2019-03null or fewer
2019-04null or fewer
2019-0520
2019-06null or fewer
2019-0740
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03110
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-09null or fewer
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11120
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-07420
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-0730
2023-08null or fewer
2023-0940
2023-1060
2023-11null or fewer
2023-12null or fewer
2024-0191
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04100
2025-05null or fewer
2025-06null or fewer
2025-07300
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-1290

Products

The products that kept showing up in Cd-foundation's monthly top three, with their CVEs summed over those months.

  1. Jenkins307 months
  2. Jenkins Deployer Framework Plugin41 month
  3. Jenkins Script Security42 months
  4. Applitools Eyes31 month
  5. Jenkins Coverity Plugin31 month
  6. Jenkins GitLab Branch Source Plugin31 month
  7. Jenkins Openshift Deployer Plugin31 month
  8. Apica Loadtest21 month
  9. Asakusasatellite21 month
  10. Dead Man's Snitch21 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Cd-foundation.

  1. CVE-2026-53435In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `confi...8.8
  2. CVE-2026-42523Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITScm polling", resulting in...9.0
  3. CVE-2026-33004Jenkins LoadNinja Plugin 2.1 and earlier does not mask LoadNinja API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.4.3
  4. CVE-2026-33002Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made through the CLI WebSocket endpoint by computing the expect...7.5
  5. CVE-2026-33003Jenkins LoadNinja Plugin 2.1 and earlier stores LoadNinja API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission...4.3
  6. CVE-2026-33001Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary lo...8.8
  7. CVE-2026-27100Jenkins 2.550 and earlier, LTS 2.541.1 and earlier accepts Run Parameter values that refer to builds the user submitting the build does not have access to, allowing attackers with Item/Build and It...4.3
  8. CVE-2026-27099Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of the "Mark temporarily offline" offline cause, resulting i...8.0
  9. CVE-2025-67642Jenkins HashiCorp Vault Plugin 371.v884a_4dd60fb_6 and earlier does not set the appropriate context for Vault credentials lookup, allowing attackers with Item/Configure permission to access and pot...4.3
  10. CVE-2025-67643Jenkins Redpen - Pipeline Reporter for Jira Plugin 1.054.v7b_9517b_6b_202 and earlier does not correctly perform path validation of the workspace directory while uploading artifacts to Jira, allowi...4.3
  11. CVE-2025-67641Jenkins Coverage Plugin 2.3054.ve1ff7b_a_a_123b_ and earlier does not validate the configured coverage results ID when creating coverage results, only when submitting the job configuration through ...5.4
  12. CVE-2025-67640Jenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the path to the workspace directory as part of an argument in a temporary shell script generated by the plugin, allowing at...5.0
  13. CVE-2025-67639A cross-site request forgery (CSRF) vulnerability in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers to trick users into logging in to the attacker's account.3.5
  14. CVE-2025-67638Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.4.3
  15. CVE-2025-67637Jenkins 2.540 and earlier, LTS 2.528.2 and earlier stores build authorization tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extend...4.3

The record

Peak rank
#20 in Jul 2022
Busiest month shown
Jul 2022, 42 CVEs
Months with a KEV entry
1 since Feb 2019
Monthly snapshots
13 since 2019
Cd-foundation's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store