Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2538▼ 400 respecto a la semana anterior
Críticas / altas1320▲ 39 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
259 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.61% | — | Jenkins Github | 5/6/2018 | 17/6/2026 | A server-side request forgery vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubPluginConfig.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL. | |
| Modificada | Media (6.5) | 1.0% | — | Jenkins Github | 5/6/2018 | 17/6/2026 | A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubServerConfig.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in… | |
| Modificada | Media (6.7) | 0.36% | — | Jenkins Github Pull Request Builder | 5/4/2018 | 17/6/2026 | An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 and older in GhprbCause.java that allows an attacker with local file system access to obtain GitHub credentials. | |
| Modificada | Alta (7.8) | 0.37% | — | Jenkins Github Pull Request Builder | 5/4/2018 | 17/6/2026 | An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 and older in GhprbCause.java that allows an attacker with local file system access to obtain GitHub credentials. | |
| Modificada | Media (6.3) | 0.64% | — | Jenkins Github Branch Source | 5/10/2017 | 17/6/2026 | GitHub Branch Source Plugin connects to a user-specified GitHub API URL (e.g. GitHub Enterprise) as part of form validation and completion (e.g. to verify Scan Credentials are correct). This functionality improperly checked permissions, allowing any user with Overall/Read access to Jenkins to connect to any web server… | |
| Modificada | Media (4.3) | 0.79% | — | Jenkins Github Branch Source | 5/10/2017 | 17/6/2026 | GitHub Branch Source provides a list of applicable credential IDs to allow users configuring a job to select the one they'd like to use. This functionality did not check permissions, allowing any user with Overall/Read permission to get a list of valid credentials IDs. Those could be used as part of an attack to… | |
| Modificada | Baja (3.6) | 0.39% | — | Github HUB | 27/5/2014 | 17/6/2026 | The am function in lib/hub/commands.rb in hub before 1.12.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary patch file. | |
| Modificada | Media (5.8) | 0.57% | — | Github Gaug.esRoderick Baier Weberknecht | 4/11/2012 | 16/6/2026 | Weberknecht, as used in GitHub Gaug.es and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Alta (7.5) | 1.8% | — | Github | 5/4/2012 | 16/6/2026 | GitHub Enterprise before 20120304 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the public_key[user_id] value via a modified URL for the public-key update form, related to a "mass assignment" vulnerability. |