Products › Server applications and development
Server applications and development
Development and CI/CD
Code forges, continuous integration pipelines, package repositories and developer tools.
For example: Jenkins, GitLab, TeamCity, JFrog Artifactory.
-
16 vulnerabilities added in the last 12 months
-
34 exploited vulnerabilities in the catalog, in total
-
3 added in the last 30 days
Pace of additions
| Period | Vulnerabilities added |
|---|---|
| Sep 9, 2025 to Oct 8, 2025 | 1 |
| Oct 9, 2025 to Nov 7, 2025 | 0 |
| Nov 8, 2025 to Dec 7, 2025 | 0 |
| Dec 8, 2025 to Jan 6, 2026 | 0 |
| Jan 7, 2026 to Feb 5, 2026 | 5 |
| Feb 6, 2026 to Mar 7, 2026 | 1 |
| Mar 8, 2026 to Apr 6, 2026 | 1 |
| Apr 7, 2026 to May 6, 2026 | 1 |
| May 7, 2026 to Jun 5, 2026 | 1 |
| Jun 6, 2026 to Jul 5, 2026 | 0 |
| Jul 6, 2026 to Aug 4, 2026 | 0 |
| Aug 5, 2026 to Sep 3, 2026 | 4 |
| Sep 4, 2026 to Oct 3, 2026 (in progress) | 3 |
Affected brands
In alphabetical order, with their number of vulnerabilities in this category.
- Aqua Security 1 vulnerability · 1 in the last 12 months
- Atlassian 1 vulnerability
- Docker 1 vulnerability
- Git 1 vulnerability
- Gitea 1 vulnerability · 1 in the last 12 months
- GitLab 5 vulnerabilities · 3 in the last 12 months
- Gogs 1 vulnerability · 1 in the last 12 months
- Jenkins 6 vulnerabilities
- JetBrains 4 vulnerabilities · 2 in the last 12 months
- JFrog 4 vulnerabilities · 4 in the last 12 months
- Nx 1 vulnerability · 1 in the last 12 months
- PHPUnit 1 vulnerability
- Prettier 1 vulnerability · 1 in the last 12 months
- React Native Community 1 vulnerability · 1 in the last 12 months
- reviewdog 1 vulnerability
- Sonatype 2 vulnerabilities
- tj-actions 1 vulnerability
- Vite 1 vulnerability · 1 in the last 12 months
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
See also
- Frameworks and libraries 76 vulnerabilities
- AI and automation 16 vulnerabilities
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.
- Rank 1
GitLab Community / Enterprise Edition (CE/EE)CVE-2026-85706
GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
Recently addedHunt for compromise (CISA)
CVSS severity 10.0critical
Added Sep 11, 2026
- Rank 2
JFrog ArtifactoryCVE-2026-42016
JFrog Artifactory Incorrect Authorization Vulnerability
Recently added
CVSS severity 8.8high
Added Sep 11, 2026
- Rank 3
JFrog ArtifactoryCVE-2026-42018
JFrog Artifactory Improper Authentication Vulnerability
Recently added
CVSS severity 7.5high
Added Sep 11, 2026
- Rank 4
JFrog ArtifactoryCVE-2026-82329
JFrog Artifactory Improper Authentication Vulnerability
Hunt for compromise (CISA)
CVSS severity 9.8critical
Added Sep 2, 2026
- Rank 5
GiteaCVE-2026-60004
Gitea Code Injection Vulnerability
Hunt for compromise (CISA)
CVSS severity 9.8critical
Added Aug 25, 2026
- Rank 6
JetBrains TeamCityCVE-2026-63077
JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
Hunt for compromise (CISA)Ransomware
CVSS severity 9.8critical
Added Aug 5, 2026
- Rank 7
Nx ConsoleCVE-2026-48027
Nx Console Embedded Malicious Code Vulnerability
Ransomware
CVSS severity 9.8critical
Added May 27, 2026
- Rank 8
GitLab Community / Enterprise Edition (CE/EE)CVE-2021-22175
GitLab Server-Side Request Forgery (SSRF) Vulnerability
CVE from 2021, added in 2026
CVSS severity 9.8critical
Added Feb 18, 2026
- Rank 9
React Native Community React Native CLICVE-2025-11953
React Native Community CLI OS Command Injection Vulnerability
CVSS severity 9.8critical
Added Feb 5, 2026
- Rank 10
Aqua Security TrivyCVE-2026-33634
Aquasecurity Trivy Embedded Malicious Code Vulnerability
CVSS severity 8.8high
Added Mar 26, 2026
Show 24 more vulnerabilities
- Rank 11
GogsCVE-2025-8110
Gogs Path Traversal Vulnerability
CVSS severity 8.8high
Added Jan 12, 2026
- Rank 12
GitLab Community / Enterprise Edition (CE/EE)CVE-2021-39935
GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability
CVE from 2021, added in 2026
CVSS severity 7.5high
Added Feb 3, 2026
- Rank 13
ViteCVE-2025-31125
Vite Vitejs Improper Access Control Vulnerability
CVSS severity 7.5high
Added Jan 22, 2026
- Rank 14
Prettier eslint-config-prettierCVE-2025-54313
Prettier eslint-config-prettier Embedded Malicious Code Vulnerability
CVSS severity 7.5high
Added Jan 22, 2026
- Rank 15
JetBrains TeamCityCVE-2024-27199
JetBrains TeamCity Relative Path Traversal Vulnerability
RansomwareCVE from 2024, added in 2026
CVSS severity 7.3high
Added Apr 20, 2026
- Rank 16
JFrog ArtifactoryCVE-2026-66384
JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
CVSS severity 5.3medium
Added Aug 27, 2026
- Rank 17
GitLab Community / Enterprise Edition (CE/EE)CVE-2021-22205
GitLab Community and Enterprise Editions Remote Code Execution Vulnerability
Ransomware
CVSS severity 10.0critical
Added Nov 3, 2021
- Rank 18
Jenkins PluginsCVE-2019-1003029
Jenkins Script Security Plugin Sandbox Bypass Vulnerability
CVE from 2019, added in 2022
CVSS severity 9.9critical
Added Apr 25, 2022
- Rank 19
Jenkins PluginsCVE-2019-1003030
Jenkins Matrix Project Plugin Remote Code Execution Vulnerability
CVE from 2019, added in 2022
CVSS severity 9.9critical
Added Mar 25, 2022
- Rank 20
Jenkins CoreCVE-2017-1000353
Jenkins Remote Code Execution Vulnerability
CVE from 2017, added in 2025
CVSS severity 9.8critical
Added Oct 2, 2025
- Rank 21
Jenkins CoreCVE-2024-23897
Jenkins Command Line Interface (CLI) Path Traversal Vulnerability
Ransomware
CVSS severity 9.8critical
Added Aug 19, 2024
- Rank 22
GitLab Community / Enterprise Edition (CE/EE)CVE-2023-7028
GitLab Community and Enterprise Editions Improper Access Control Vulnerability
CVSS severity 9.8critical
Added May 1, 2024
- Rank 23
JetBrains TeamCityCVE-2024-27198
JetBrains TeamCity Authentication Bypass Vulnerability
Ransomware
CVSS severity 9.8critical
Added Mar 7, 2024
- Rank 24
JetBrains TeamCityCVE-2023-42793
JetBrains TeamCity Authentication Bypass Vulnerability
Ransomware
CVSS severity 9.8critical
Added Oct 4, 2023
- Rank 25
PHPUnitCVE-2017-9841
PHPUnit Command Injection Vulnerability
CVE from 2017, added in 2022
CVSS severity 9.8critical
Added Feb 15, 2022
- Rank 26
Jenkins CoreCVE-2018-1000861
Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability
CVE from 2018, added in 2022
CVSS severity 9.8critical
Added Feb 10, 2022
- Rank 27
Sonatype Nexus RepositoryCVE-2019-7238
Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability
CVE from 2019, added in 2021
CVSS severity 9.8critical
Added Dec 10, 2021
- Rank 28
Atlassian Bitbucket Server / Data CenterCVE-2022-36804
Atlassian Bitbucket Server and Data Center Command Injection Vulnerability
CVSS severity 8.8high
Added Sep 30, 2022
- Rank 29
Sonatype Nexus RepositoryCVE-2020-10199
Sonatype Nexus Repository Remote Code Execution Vulnerability
CVSS severity 8.8high
Added Nov 3, 2021
- Rank 30
reviewdog action-setup GitHub ActionCVE-2025-30154
reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability
CVSS severity 8.6high
Added Mar 24, 2025
- Rank 31
tj-actions changed-files GitHub ActionCVE-2025-30066
tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability
CVSS severity 8.6high
Added Mar 18, 2025
- Rank 32
Git Link Following Vulnerability
CVSS severity 8.0high
Added Aug 25, 2025
- Rank 33
Docker DesktopCVE-2019-15752
Docker Desktop Community Edition Privilege Escalation Vulnerability
CVE from 2019, added in 2021
CVSS severity 7.8high
Added Nov 3, 2021
- Rank 34
Jenkins CoreCVE-2015-5317
Jenkins User Interface (UI) Information Disclosure Vulnerability
CVE from 2015, added in 2023
CVSS severity 7.5high
Added May 12, 2023
Follow and verify
Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.