Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1897 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 79% | — | Jenkins Build Monitor View | 6/3/2024 | 17/6/2026 | Jenkins Build Monitor View Plugin 1.14-860.vd06ef2568b_3f and earlier does not escape Build Monitor View names, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure Build Monitor Views. | |
| Modificada | Media (4.3) | 0.45% | — | Jenkins Appspider | 6/3/2024 | 17/6/2026 | Jenkins AppSpider Plugin 1.0.16 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to obtain information about available scan config names, engine group names, and client names. | |
| Modificada | Media (6.5) | 0.68% | — | Jenkins MQ Notifier | 6/3/2024 | 17/6/2026 | Jenkins MQ Notifier Plugin 1.4.0 and earlier logs potentially sensitive build parameters as part of debug information in build logs by default. | |
| Modificada | Media (5.4) | 0.69% | — | Jenkins Owasp Dependency-check | 6/3/2024 | 17/6/2026 | Jenkins OWASP Dependency-Check Plugin 5.4.5 and earlier does not escape vulnerability metadata from Dependency-Check reports, resulting in a stored cross-site scripting (XSS) vulnerability. | |
| Analizada | Media (6.3) | 0.56% | — | Jenkins Bitbucket Branch Source | 6/3/2024 | 17/6/2026 | In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks, the trust policy "Forks in the same account" allows changes to Jenkinsfiles from users without write access to the project when using Bitbucket Server. | |
| Analizada | Media (4.3) | 0.94% | — | Jenkins Html Publisher | 6/3/2024 | 17/6/2026 | Jenkins HTML Publisher Plugin 1.32 and earlier archives invalid symbolic links in report directories on agents and recreates them on the controller, allowing attackers with Item/Configure permission to determine whether a path on the Jenkins controller file system exists, without being able to access it. | |
| Analizada | Media (4.7) | 0.68% | — | Jenkins Html Publisher | 6/3/2024 | 17/6/2026 | Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names, report names, and index page titles shown as part of the report frame, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Analizada | Media (6.5) | 0.70% | — | Jenkins Html Publisher | 6/3/2024 | 17/6/2026 | Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers with Item/Configure permission to implement cross-site scripting (XSS) attacks and to determine whether a path on the Jenkins controller file system exists. | |
| Modificada | Media (5.4) | 0.56% | — | Jenkins RED HAT Dependency Analytics | 24/1/2024 | 17/6/2026 | Jenkins Red Hat Dependency Analytics Plugin 0.7.1 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download. | |
| Modificada | Alta (7.5) | 0.88% | — | Jenkins LOG Command | 24/1/2024 | 17/6/2026 | Jenkins Log Command Plugin 1.0.2 and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read content from arbitrary files on the Jenkins controller file system. | |
| Modificada | Media (5.3) | 0.50% | — | Jenkins Github Branch Source | 24/1/2024 | 17/6/2026 | Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token. | |
| Modificada | Media (4.3) | 0.32% | — | Jenkins Github Branch Source | 24/1/2024 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier allows attackers to connect to an attacker-specified URL. | |
| Modificada | Media (6.5) | 0.46% | — | Jenkins Github Branch Source | 24/1/2024 | 17/6/2026 | Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier unconditionally discovers projects that are shared with the configured owner group, allowing attackers to configure and share a project, resulting in a crafted Pipeline being built by Jenkins during the next scan of the group. | |
| Modificada | Media (4.3) | 0.69% | — | Jenkins Matrix Project | 24/1/2024 | 17/6/2026 | Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects, allowing attackers with Item/Configure permission to create or replace any config.xml files on the Jenkins controller file system with content not controllable by the attackers. | |
| Modificada | Media (6.5) | 1.3% | — | Jenkins GIT Server | 24/1/2024 | 17/6/2026 | Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing attackers with Overall/Read permission to read content from arbitrary files on the Jenkins controller file… | |
| Modificada | Alta (8.8) | 67% | 💥 PoC | Jenkins | 24/1/2024 | 17/6/2026 | Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability, allowing attackers to execute CLI commands on the Jenkins controller. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Jenkins | 24/1/2024 | 17/6/2026 | Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system. | |
| Modificada | Media (4.3) | 0.48% | — | Jenkins Paaslane Estimate | 13/12/2023 | 17/6/2026 | Missing permission checks in Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified token. | |
| Modificada | Alta (8.8) | 0.41% | — | Jenkins Paaslane Estimate | 13/12/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier allows attackers to connect to an attacker-specified URL using an attacker-specified token. | |
| Modificada | Media (4.3) | 0.32% | — | Jenkins Paaslane Estimate | 13/12/2023 | 17/6/2026 | Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier does not mask PaaSLane authentication tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them. | |
| Modificada | Media (4.3) | 0.34% | — | Jenkins Paaslane Estimate | 13/12/2023 | 17/6/2026 | Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier stores PaaSLane authentication tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system. | |
| Modificada | Media (4.3) | 0.35% | — | Jenkins Deployment Dashboard | 13/12/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers to copy jobs. | |
| Modificada | Alta (8.1) | 0.49% | — | Jenkins Html Resource | 13/12/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins HTMLResource Plugin 1.02 and earlier allows attackers to delete arbitrary files on the Jenkins controller file system. | |
| Modificada | Media (4.3) | 0.35% | — | Jenkins Dingding Json Pusher | 13/12/2023 | 17/6/2026 | Jenkins Dingding JSON Pusher Plugin 2.0 and earlier does not mask access tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them. | |
| Modificada | Media (4.3) | 0.35% | — | Jenkins Dingding Json Pusher | 13/12/2023 | 17/6/2026 | Jenkins Dingding JSON Pusher Plugin 2.0 and earlier stores access tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system. |