CVE security advisories and vulnerability history for Jenkins.
Jenkins has 1,885 published CVE records since 2011, of which 7 are in CISA's Known Exploited Vulnerabilities catalog and 28 have a known public exploit. The average CVSS base score across scored CVEs is 6.5.
This page aggregates every publicly disclosed vulnerability (CVE) affecting Jenkins products, with severity breakdowns, the most-affected products, the most common weakness types, and the latest disclosures.
A quick read on Jenkins's vulnerability posture, as a share of its 1,885 published CVEs.
across 1,885 scored CVEs
702 of 1,885 scored
7 of 1,885 CVEs
28 of 1,885 CVEs
1,758 of 1,885 CVEs
How the CVSS severity of Jenkins's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
In CISA’s Known Exploited Vulnerabilities catalog
7
7 of Jenkins's CVEs are confirmed exploited in the wild.
Public exploits
28
28 of Jenkins's CVEs have a known public exploit available.
The Jenkins products with the most published CVEs. Follow any product to browse its versions and vulnerabilities.
The CWE weakness categories most often found in Jenkins CVEs. Follow any weakness for its full explanation.
The CVE Numbering Authorities that publish Jenkins CVE records.
How many Jenkins CVEs were published each year.
The most recently disclosed vulnerabilities affecting Jenkins.
Browse vulnerabilities for other tracked vendors.
Common questions about Jenkins vulnerabilities.
Vulnerability data is sourced from the CVE Program; severity, KEV, and exploit signals are aggregated by RadicalNotion.AI.
Monitor new Jenkins vulnerabilities as they are disclosed, with AI-written analysis and remediation guidance.
Track new Jenkins CVEs as they are disclosed and get AI-written analysis and remediation guidance.
Monitor Jenkins CVEs