Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1897 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.38% | — | Jenkins | 2/4/2025 | 17/6/2026 | A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Configure permission to copy an agent, gaining access to encrypted secrets in its configuration. | |
| Analizada | Media (4.3) | 0.40% | — | Jenkins | 2/4/2025 | 17/6/2026 | A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Extended Read permission to copy an agent, gaining access to its configuration. | |
| Analizada | Baja (3.1) | 0.28% | — | Jenkins Zoho Qengine | 19/3/2025 | 17/6/2026 | Jenkins Zoho QEngine Plugin 1.0.29.vfa_cc23396502 and earlier does not mask the QEngine API Key form field, increasing the potential for attackers to observe and capture it. | |
| Analizada | Media (6.5) | 0.31% | — | Jenkins Anchorchain | 19/3/2025 | 17/6/2026 | Jenkins AnchorChain Plugin 1.0 does not limit URL schemes for links it creates based on workspace content, allowing the `javascript:` scheme, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control the input file for the Anchor Chain post-build step. | |
| Analizada | Media (4.3) | 0.62% | — | Jenkins | 5/3/2025 | 17/6/2026 | In Jenkins 2.499 and earlier, LTS 2.492.1 and earlier, redirects starting with backslash (`\`) characters are considered safe, allowing attackers to perform phishing attacks by having users go to a Jenkins URL that will forward them to a different site, because browsers interpret these characters as part of… | |
| Analizada | Media (5.4) | 0.44% | — | Jenkins | 5/3/2025 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins 2.499 and earlier, LTS 2.492.1 and earlier allows attackers to have users toggle their collapsed/expanded status of sidepanel widgets (e.g., Build Queue and Build Executor Status widgets). | |
| Analizada | Media (4.3) | 0.34% | — | Jenkins | 5/3/2025 | 17/6/2026 | Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of views via REST API or CLI, allowing attackers with View/Read permission to view encrypted values of secrets. | |
| Analizada | Media (4.3) | 0.78% | — | Jenkins | 5/3/2025 | 17/6/2026 | Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of agents via REST API or CLI, allowing attackers with Agent/Extended Read permission to view encrypted values of secrets. | |
| Aplazada | Baja (2.6) | 0.17% | — | Zoom Jenkins Marketplace PluginAIJenkinsAI | 3/2/2025 | 17/6/2026 | Missing password field masking in the Zoom Jenkins Marketplace plugin before version 1.6 may allow an unauthenticated user to conduct a disclosure of information via adjacent network access. | |
| Aplazada | Media (4.3) | 0.27% | — | Zoom Jenkins Marketplace PluginAI | 30/1/2025 | 17/6/2026 | Cleartext storage of sensitive information in the Zoom Jenkins Marketplace plugin before version 1.4 may allow an authenticated user to conduct a disclosure of information via network access. | |
| Analizada | Media (4.3) | 0.30% | — | Jenkins Azure Service Fabric | 22/1/2025 | 17/6/2026 | A missing permission check in Jenkins Azure Service Fabric Plugin 1.6 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of Azure credentials stored in Jenkins. | |
| Analizada | Media (4.3) | 0.22% | — | Jenkins Azure Service Fabric | 22/1/2025 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Service Fabric Plugin 1.6 and earlier allows attackers to connect to a Service Fabric URL using attacker-specified credentials IDs obtained through another method. | |
| Analizada | Media (6.8) | 0.31% | — | Jenkins Folder-based Authorization Strategy | 22/1/2025 | 17/6/2026 | Jenkins Folder-based Authorization Strategy Plugin 217.vd5b_18537403e and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitled to. | |
| Analizada | Media (4.3) | 0.30% | — | Jenkins Eiffel Broadcaster | 22/1/2025 | 17/6/2026 | Jenkins Eiffel Broadcaster Plugin 2.8.0 through 2.10.2 (both inclusive) uses the credential ID as the cache key during signing operations, allowing attackers able to create a credential with the same ID as a legitimate one in a different credentials store to sign an event published to RabbitMQ with the legitimate… | |
| Analizada | Alta (8.8) | 0.55% | — | Jenkins Openid Connect Authentication | 22/1/2025 | 17/6/2026 | Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats usernames as case-insensitive, allowing attackers on Jenkins instances configured with a case-sensitive OpenID Connect provider to log in as any user by providing a username that differs only in… | |
| Analizada | Alta (8.8) | 0.30% | — | Jenkins Bitbucket Server Integration | 22/1/2025 | 17/6/2026 | Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins. | |
| Analizada | Media (4.3) | 0.30% | — | Jenkins Gitlab | 22/1/2025 | 17/6/2026 | An incorrect permission check in Jenkins GitLab Plugin 1.9.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credential IDs of GitLab API token and Secret text credentials stored in Jenkins. | |
| Analizada | Media (4.3) | 0.80% | — | Jenkins Filesystem List Parameter | 27/11/2024 | 17/6/2026 | Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects list Parameter, allowing attackers with Item/Configure permission to enumerate file names on the Jenkins controller file system. | |
| Analizada | Alta (8) | 80% | — | Jenkins Simple Queue | 27/11/2024 | 17/6/2026 | Jenkins Simple Queue Plugin 1.4.4 and earlier does not escape the view name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Create permission. | |
| Analizada | Alta (8.8) | 0.52% | — | Jenkins Shared Library Version Override | 13/11/2024 | 17/6/2026 | Jenkins Shared Library Version Override Plugin 17.v786074c9fce7 and earlier declares folder-scoped library overrides as trusted, so that they're not executed in the Script Security sandbox, allowing attackers with Item/Configure permission on a folder to configure a folder-scoped library override that runs without… | |
| Analizada | Alta (8.8) | 0.64% | — | Jenkins Openid Connect Authentication | 13/11/2024 | 17/6/2026 | Jenkins OpenId Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier does not invalidate the previous session on login. | |
| Analizada | Alta (8) | 0.69% | — | Jenkins Authorize Project | 13/11/2024 | 17/6/2026 | Jenkins Authorize Project Plugin 1.7.2 and earlier evaluates a string containing the job name with JavaScript on the Authorization view, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Analizada | Alta (8) | 0.56% | — | Jenkins Pipeline\ | 13/11/2024 | 17/6/2026 | Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a build from a specific stage is approved, allowing attackers with Item/Build permission to restart a previous build whose (Jenkinsfile) script is no longer approved. | |
| Analizada | Alta (8) | 0.44% | 💥 PoC | Jenkins Pipeline\ | 13/11/2024 | 17/6/2026 | Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main (Jenkinsfile) script for a rebuilt build is approved, allowing attackers with Item/Build permission to rebuild a previous build whose (Jenkinsfile) script is no longer approved. | |
| Analizada | Media (4.3) | 0.35% | — | Jenkins Script Security | 13/11/2024 | 17/6/2026 | Jenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ and 1362.1364.v4cf2dc5d8776, does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files on the controller file system. |