8.8

CVSS3.1

CVE-2024-52553 -

Jenkins OpenId Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier does not invalidate the previous session on login.

πŸ“… Published: Nov. 13, 2024, 8:53 p.m. πŸ”„ Last Modified: May 7, 2025, 2:15 p.m.

8

CVSS3.1

CVE-2024-52552 -

Jenkins Authorize Project Plugin 1.7.2 and earlier evaluates a string containing the job name with JavaScript on the Authorization view, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

πŸ“… Published: Nov. 13, 2024, 8:53 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 12:56 a.m.

8

CVSS3.1

CVE-2024-52551 - jenkins-plugin/pipeline-model-definition: Jenkins Pipeline Declarative Plugin Allows Restart of Bui…

Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a build from a specific stage is approved, allowing attackers with Item/Build permission to restart a previous build whose (Jenkinsfile) script is no longe…

πŸ“… Published: Nov. 13, 2024, 8:53 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 8:39 p.m.

4.3

CVSS3.1

CVE-2024-52549 - jenkins-plugin/script-security: Jenkins Script Security Plugin File Disclosure Vulnerability

Jenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ and 1362.1364.v4cf2dc5d8776, does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files on the co…

πŸ“… Published: Nov. 13, 2024, 8:53 p.m. πŸ”„ Last Modified: Oct. 10, 2025, 3:29 p.m.

8

CVSS3.1

CVE-2024-52550 - jenkins-plugin/workflow-cps: Lack of Approval Check for Rebuilt Jenkins Pipelines

Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main (Jenkinsfile) script for a rebuilt build is approved, allowing attackers with Item/Build permission to rebuild a previous build whose (Jenkinsfile) script is no longer app…

πŸ“… Published: Nov. 13, 2024, 8:53 p.m. πŸ”„ Last Modified: Oct. 10, 2025, 3:29 p.m.

6.8

CVSS4.0

CVE-2024-28049 -

Improper input validation in firmware for some Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi wireless products before version 23.40 may allow an unauthenticated user to enable denial of service via adjacent access.

πŸ“… Published: Nov. 13, 2024, 8:36 p.m. πŸ”„ Last Modified: Sept. 29, 2025, 2:45 p.m.

6.8

CVSS4.0

CVE-2024-24984 -

Improper input validation for some Intel(R) Wireless Bluetooth(R) products for Windows before version 23.40 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

πŸ“… Published: Nov. 13, 2024, 8:36 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS4.0

CVE-2024-23198 -

Improper input validation in firmware for some Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi products before version 23.40 may allow an unauthenticated user to enable denial of service via adjacent access.

πŸ“… Published: Nov. 13, 2024, 8:36 p.m. πŸ”„ Last Modified: Sept. 25, 2025, 6:25 p.m.

4.8

CVSS4.0

CVE-2024-25565 -

Insufficient control flow management in UEFI firmware for some Intel(R) Xeon(R) Processors may allow an authenticated user to enable denial of service via local access.

πŸ“… Published: Nov. 13, 2024, 8:36 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2024-21820 -

Incorrect default permissions in some Intel(R) Xeon(R) processor memory controller configurations when using Intel(R) SGX may allow a privileged user to potentially enable escalation of privilege via local access.

πŸ“… Published: Nov. 13, 2024, 8:34 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 348208
Page 7796 of 34,821
Β« previous page Β» next page
Filters