Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8) | 0.41% | — | Jenkins Sonarqube ScannerAISonarsource SonarqubeAI | 2/9/2026 | 3/9/2026 | Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard links it creates based on SonarQube scanner results, allowing the `javascript:` scheme, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Pendiente de análisis | Media (4.3) | 0.27% | — | Jenkins Codesonar PluginAI | 5/8/2026 | 31/8/2026 | Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Aplazada | Alta (8) | 0.19% | — | CleanuparrAISonarrAIRadarrAIQbittorrentAI | 12/5/2026 | 17/6/2026 | Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, Cleanuparr's global CORS policy reflects every request Origin and combines it with AllowCredentials(). When DisableAuthForLocalAddresses is enabled, the API… | |
| Aplazada | Crítica (9.8) | 0.33% | — | CleanuparrAISonarrAIRadarrAIQbittorrentAI | 12/5/2026 | 17/6/2026 | Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, TrustedNetworkAuthenticationHandler.ResolveClientIp parses the leftmost entry of the X-Forwarded-For header as the client IP. That entry is… | |
| Analizada | Alta (8.7) | 0.66% | — | Teamt5 Threatsonar Anti-ransomware | 20/4/2026 | 17/6/2026 | ThreatSonar Anti-Ransomware developed by TeamT5 has an Privilege Escalation vulnerability. Authenticated remote attackers with shell access can inject OS commands and execute them with root privileges. | |
| Analizada | Alta (7.2) | 0.64% | — | Teamt5 Threatsonar Anti-ransomware | 20/4/2026 | 17/6/2026 | ThreatSonar Anti-Ransomware developed by TeamT5 has an Arbitrary File Deletion vulnerability. Authenticated remote attackers with web access can exploit Path Traversal to delete arbitrary files on the system. | |
| Analizada | Alta (7.5) | 0.71% | — | Sonarr | 25/3/2026 | 17/6/2026 | Sonarr is a PVR for Usenet and BitTorrent users. In versions on the 4.x branch prior to 4.0.17.2950, an unauthenticated remote attacker can potentially read any file readable by the Sonarr process. These include application configuration files (containing API keys and database credentials), Windows system files, and… | |
| Analizada | Crítica (9.8) | 0.60% | — | Sonarr | 25/3/2026 | 17/6/2026 | Sonarr is a PVR for Usenet and BitTorrent users. Versions prior to 4.0.16.2942 have an authentication bypass that affected users that had disabled authentication for local addresses (Authentication Required set to: `Disabled for Local Addresses`) without a reverse proxy running in front of Sonarr that didn't not pass… | |
| Aplazada | Alta (8.5) | 0.14% | — | Sonarsource SonarqubeAI | 29/1/2026 | 7/10/2026 | SonarQube 8.3.1 contains an unquoted service path vulnerability that allows local attackers to gain SYSTEM privileges by exploiting the service executable path. Attackers can replace the wrapper.exe in the service path with a malicious executable to execute code with highest system privileges during service restart. | |
| Aplazada | Media (5.3) | 0.25% | — | Sonarsource Jenkins PluginAI | 3/12/2025 | 17/6/2026 | A fix was made in BlazeMeter Jenkins Plugin version 4.27 to allow users only with certain permissions to see the list of available resources like credential IDs, bzm workspaces and bzm project Ids. Prior to this fix, anyone could see this list as a dropdown on the Jenkins UI. | |
| Aplazada | Alta (8.5) | 0.13% | — | SonarrAI | 13/11/2025 | 17/6/2026 | A vulnerability was found in Sonarr 4.0.15.2940. The impacted element is an unknown function of the file C:\ProgramData\Sonarr\bin\Sonarr.Console.exe of the component Service. Performing manipulation results in incorrect default permissions. The attack is only possible with local access. The vendor confirms this… | |
| Aplazada | Media (4.3) | 0.22% | — | Sonarsource SonarqubeAI | 10/10/2025 | 17/6/2026 | In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/users-management/users endpoint and obtain user fields intended for administrators only, including the email addresses of other accounts. | |
| Aplazada | Alta (7.7) | 1.5% | — | Sonarqube Github ActionAI | 26/9/2025 | 17/6/2026 | SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. A command injection vulnerability exists in SonarQube GitHub Action in version 4.0.0 to before version 6.0.0 when workflows pass user-controlled input to the args parameter on Windows runners without proper… | |
| Aplazada | Alta (7.8) | 1.1% | — | Sonarqube ServerAISonarqube CloudAISonarqube Scan Github ActionAI | 2/9/2025 | 17/6/2026 | SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. In versions 4 to 5.3.0, a command injection vulnerability was discovered in the SonarQube Scan GitHub Action that allows untrusted input arguments to be processed without proper sanitization. Arguments sent to… | |
| Aplazada | Alta (8.6) | 1.0% | — | Teamt5 Threatsonar Anti-ransomwareAI | 7/7/2025 | 17/6/2026 | ThreatSonar Anti-Ransomware developed by TeamT5 has an OS Command Injection vulnerability, allowing remote attackers with product platform intermediate privileges to inject arbitrary OS commands and execute them on the server, thereby gaining administrative access to the remote host. | |
| Aplazada | Alta (8.6) | 0.47% | — | Teamt5 Threatsonar Anti-ransomwareAI | 19/5/2025 | 17/6/2026 | The ThreatSonar Anti-Ransomware from TeamT5 has a Privilege Escalation vulnerability, allowing remote attackers with intermediate privileges to escalate their privileges to highest administrator level through a specific API. | |
| Aplazada | Media (6.1) | 0.24% | — | SonarrAI | 6/10/2024 | 17/6/2026 | Sonarr – CWE-601: URL Redirection to Untrusted Site ('Open Redirect') | |
| Analizada | Alta (7.2) | 0.45% | — | Sonarsource Sonarqube | 4/10/2024 | 17/6/2026 | In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-memberships API endpoint that allows SonarQube users with the administrator role to inject blind SQL commands. | |
| Aplazada | Alta (7.2) | 0.48% | — | Sonarsource SonarqubeAI | 4/10/2024 | 17/6/2026 | An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5. A SonarQube user with the Administrator role can modify an existing configuration of a GitHub integration to exfiltrate a pre-signed JWT. | |
| Analizada | Alta (7.2) | 1.8% | ⚠ Explotación activa | Teamt5 Threatsonar Anti-ransomware | 12/8/2024 | 17/6/2026 | ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system command on the server. | |
| Modificada | Media (6.5) | 0.33% | — | Sonarsource Sonarqube | 16/6/2024 | 17/6/2026 | In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part of the URL parameters in the logs (such as SonarQube Access Logs, Proxy Logs, etc). | |
| Aplazada | Media (4.3) | 0.21% | — | Sonarsource Jenkins PluginAI | 17/4/2024 | 17/6/2026 | Versions of the BlazeMeter Jenkins plugin prior to 4.22 contain a flaw which results in credential enumeration | |
| Modificada | Media (5.4) | 0.66% | — | Jenkins Sonargraph Integration | 14/6/2023 | 17/6/2026 | Jenkins Sonargraph Integration Plugin 5.0.1 and earlier does not escape the file path and the project name for the Log file field form validation, resulting in a stored cross-site scripting vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Media (5.3) | 0.63% | — | Perfsonar | 1/1/2023 | 17/6/2026 | perfSONAR before 4.4.6 inadvertently supports the parse option for a file:// URL. | |
| Modificada | Media (5.3) | 0.60% | — | Perfsonar | 1/1/2023 | 17/6/2026 | perfSONAR before 4.4.6, when performing participant discovery, incorrectly uses an HTTP request header value to determine a local address. |