Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

44 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8)0.41%—Jenkins Sonarqube ScannerAISonarsource SonarqubeAI2/9/20263/9/2026
Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard links it creates based on SonarQube scanner results, allowing the `javascript:` scheme, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Pendiente de análisisMedia (4.3)0.27%—Jenkins Codesonar PluginAI5/8/202631/8/2026
Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
AplazadaAlta (8)0.19%—CleanuparrAISonarrAIRadarrAIQbittorrentAI12/5/202617/6/2026
Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, Cleanuparr's global CORS policy reflects every request Origin and combines it with AllowCredentials(). When DisableAuthForLocalAddresses is enabled, the API…
AplazadaCrítica (9.8)0.33%—CleanuparrAISonarrAIRadarrAIQbittorrentAI12/5/202617/6/2026
Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, TrustedNetworkAuthenticationHandler.ResolveClientIp parses the leftmost entry of the X-Forwarded-For header as the client IP. That entry is…
AnalizadaAlta (8.7)0.66%—Teamt5 Threatsonar Anti-ransomware20/4/202617/6/2026
ThreatSonar Anti-Ransomware developed by TeamT5 has an Privilege Escalation vulnerability. Authenticated remote attackers with shell access can inject OS commands and execute them with root privileges.
AnalizadaAlta (7.2)0.64%—Teamt5 Threatsonar Anti-ransomware20/4/202617/6/2026
ThreatSonar Anti-Ransomware developed by TeamT5 has an Arbitrary File Deletion vulnerability. Authenticated remote attackers with web access can exploit Path Traversal to delete arbitrary files on the system.
AnalizadaAlta (7.5)0.71%—Sonarr25/3/202617/6/2026
Sonarr is a PVR for Usenet and BitTorrent users. In versions on the 4.x branch prior to 4.0.17.2950, an unauthenticated remote attacker can potentially read any file readable by the Sonarr process. These include application configuration files (containing API keys and database credentials), Windows system files, and…
AnalizadaCrítica (9.8)0.60%—Sonarr25/3/202617/6/2026
Sonarr is a PVR for Usenet and BitTorrent users. Versions prior to 4.0.16.2942 have an authentication bypass that affected users that had disabled authentication for local addresses (Authentication Required set to: `Disabled for Local Addresses`) without a reverse proxy running in front of Sonarr that didn't not pass…
AplazadaAlta (8.5)0.14%—Sonarsource SonarqubeAI29/1/20267/10/2026
SonarQube 8.3.1 contains an unquoted service path vulnerability that allows local attackers to gain SYSTEM privileges by exploiting the service executable path. Attackers can replace the wrapper.exe in the service path with a malicious executable to execute code with highest system privileges during service restart.
AplazadaMedia (5.3)0.25%—Sonarsource Jenkins PluginAI3/12/202517/6/2026
A fix was made in BlazeMeter Jenkins Plugin version 4.27 to allow users only with certain permissions to see the list of available resources like credential IDs, bzm workspaces and bzm project Ids. Prior to this fix, anyone could see this list as a dropdown on the Jenkins UI.
AplazadaAlta (8.5)0.13%—SonarrAI13/11/202517/6/2026
A vulnerability was found in Sonarr 4.0.15.2940. The impacted element is an unknown function of the file C:\ProgramData\Sonarr\bin\Sonarr.Console.exe of the component Service. Performing manipulation results in incorrect default permissions. The attack is only possible with local access. The vendor confirms this…
AplazadaMedia (4.3)0.22%—Sonarsource SonarqubeAI10/10/202517/6/2026
In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/users-management/users endpoint and obtain user fields intended for administrators only, including the email addresses of other accounts.
AplazadaAlta (7.7)1.5%—Sonarqube Github ActionAI26/9/202517/6/2026
SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. A command injection vulnerability exists in SonarQube GitHub Action in version 4.0.0 to before version 6.0.0 when workflows pass user-controlled input to the args parameter on Windows runners without proper…
AplazadaAlta (7.8)1.1%—Sonarqube ServerAISonarqube CloudAISonarqube Scan Github ActionAI2/9/202517/6/2026
SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. In versions 4 to 5.3.0, a command injection vulnerability was discovered in the SonarQube Scan GitHub Action that allows untrusted input arguments to be processed without proper sanitization. Arguments sent to…
AplazadaAlta (8.6)1.0%—Teamt5 Threatsonar Anti-ransomwareAI7/7/202517/6/2026
ThreatSonar Anti-Ransomware developed by TeamT5 has an OS Command Injection vulnerability, allowing remote attackers with product platform intermediate privileges to inject arbitrary OS commands and execute them on the server, thereby gaining administrative access to the remote host.
AplazadaAlta (8.6)0.47%—Teamt5 Threatsonar Anti-ransomwareAI19/5/202517/6/2026
The ThreatSonar Anti-Ransomware from TeamT5 has a Privilege Escalation vulnerability, allowing remote attackers with intermediate privileges to escalate their privileges to highest administrator level through a specific API.
AplazadaMedia (6.1)0.24%—SonarrAI6/10/202417/6/2026
Sonarr – CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
AnalizadaAlta (7.2)0.45%—Sonarsource Sonarqube4/10/202417/6/2026
In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-memberships API endpoint that allows SonarQube users with the administrator role to inject blind SQL commands.
AplazadaAlta (7.2)0.48%—Sonarsource SonarqubeAI4/10/202417/6/2026
An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5. A SonarQube user with the Administrator role can modify an existing configuration of a GitHub integration to exfiltrate a pre-signed JWT.
AnalizadaAlta (7.2)1.8%⚠ Explotación activaTeamt5 Threatsonar Anti-ransomware12/8/202417/6/2026
ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system command on the server.
ModificadaMedia (6.5)0.33%—Sonarsource Sonarqube16/6/202417/6/2026
In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part of the URL parameters in the logs (such as SonarQube Access Logs, Proxy Logs, etc).
AplazadaMedia (4.3)0.21%—Sonarsource Jenkins PluginAI17/4/202417/6/2026
Versions of the BlazeMeter Jenkins plugin prior to 4.22 contain a flaw which results in credential enumeration
ModificadaMedia (5.4)0.66%—Jenkins Sonargraph Integration14/6/202317/6/2026
Jenkins Sonargraph Integration Plugin 5.0.1 and earlier does not escape the file path and the project name for the Log file field form validation, resulting in a stored cross-site scripting vulnerability exploitable by attackers with Item/Configure permission.
ModificadaMedia (5.3)0.63%—Perfsonar1/1/202317/6/2026
perfSONAR before 4.4.6 inadvertently supports the parse option for a file:// URL.
ModificadaMedia (5.3)0.60%—Perfsonar1/1/202317/6/2026
perfSONAR before 4.4.6, when performing participant discovery, incorrectly uses an HTTP request header value to determine a local address.
Orbitaley — Vulnerabilidades