jumpserver Summary
Latest vulnerabilities published by jumpserver
Vulnerability Published:
- ποΈ Published - - Anytime 
Sort By:
- ποΈ Published Date - - Descending 
- Unauthorized Access in JumpServer Bastion Host by Low-Privileged UsersCVE-2025-62795JumpserverJumpserver7.1HIGH
- Unauthorized Access Vulnerability in JumpServer by JumpServerCVE-2025-62712JumpserverJumpserver9.6CRITICAL
- Vulnerability in JumpServer's Kubernetes Session Feature Allows Unauthorized AccessCVE-2025-27095JumpserverJumpserver4.3MEDIUM
- Secrets Disclosure Vulnerability in JumpServer PAM ToolCVE-2024-40628JumpserverJumpserver9.1CRITICAL
- Ansible Playbook Exploit Allows Remote Code Execution in Celery ContainerCVE-2024-40629JumpserverJumpserver9.8CRITICAL
- Jinja2 Template Injection Vulnerability Affects JumpServer's AnsibleCVE-2024-29202JumpserverJumpserverEPSS 81%π°9.9CRITICAL
- Arbitrary Code Execution Vulnerability in JumpServer's Ansible Could Lead to Sensitive Information Theft or Database ManipulationCVE-2024-29201JumpserverJumpserverπΎπ‘EPSS 68%π°9.9CRITICAL
- Sensitive Information Disclosure Vulnerability in JumpServerCVE-2024-29020JumpserverJumpserver5.3MEDIUM
- JumpServer Bastion Host Vulnerable to IDOR AttacksCVE-2024-29024JumpserverJumpserver5.3MEDIUM
- JumpServer vulnerability affects phishing and cross-site scripting attacksCVE-2024-24763jumpserverjumpserverEPSS 26%6.1MEDIUM
- JumpServer default admin user email leak password resetCVE-2023-46138JumpserverJumpserver3.7LOW
- jumpserver is vulnerable to password brute-force protection bypass via arbitrary IP valuesCVE-2023-46123JumpserverJumpserver5.3MEDIUM
- SSH public key login without private key challenge if mfa is enabled in jumpserverCVE-2023-42818JumpserverJumpserver9.8CRITICAL
- Remote code execution on the host system via MongoDB shell in jumpserverCVE-2023-43651JumpserverJumpserverEPSS 13%9.9CRITICAL
- Non-MFA account takeover via brute-force attack on weak password reset code in jumpserverCVE-2023-43650JumpserverJumpserver7.4HIGH
- Non-MFA account takeover via using only SSH public key to login in jumpserverCVE-2023-43652JumpserverJumpserver9.1CRITICAL
- Path traversal in JumpserverCVE-2023-42819JumpserverJumpserverπΎπ‘EPSS 36%8.9HIGH
- Random seed leakage in JumpserverCVE-2023-42820JumpserverJumpserverπΎπ‘EPSS 59%7HIGH
- JumpServer session replays download without authenticationCVE-2023-42442jumpserverjumpserverπΎπ‘EPSS 88%5.3MEDIUM
- JumpServer Koko vulnerable to Command Injection for Kubernetes ConnectionCVE-2023-28110JumpserverJumpserver5.7MEDIUM
- Access Control Issue in Jumpserver by JumpserverCVE-2021-3169JumpserverJumpserver9.8CRITICAL
