cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2021-21620,https://securityvulnerability.io/vulnerability/CVE-2021-21620,,A cross-site request forgery (CSRF) vulnerability in Jenkins Claim Plugin 2.18.1 and earlier allows attackers to change claims.,Jenkins,Jenkins Claim Plugin,4.3,MEDIUM,0.0005300000193528831,false,,false,false,false,,,false,false,,2021-02-24T15:05:30.000Z,0 CVE-2021-21619,https://securityvulnerability.io/vulnerability/CVE-2021-21619,,"Jenkins Claim Plugin 2.18.1 and earlier does not escape the user display name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers who are able to control the display names of Jenkins users, either via the security realm, or directly inside Jenkins.",Jenkins,Jenkins Claim Plugin,5.4,MEDIUM,0.0005000000237487257,false,,false,false,false,,,false,false,,2021-02-24T15:05:29.000Z,0