Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1897 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.60% | — | Jenkins Openid Connect Authentication | 13/12/2023 | 17/6/2026 | Jenkins OpenId Connect Authentication Plugin 2.6 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks. | |
| Modificada | Media (6.7) | 0.29% | — | Jenkins Openid | 13/12/2023 | 17/6/2026 | Jenkins OpenId Connect Authentication Plugin 2.6 and earlier stores a password of a local user account used as an anti-lockout feature in a recoverable format, allowing attackers with access to the Jenkins controller file system to recover the plain text password of that account, likely gaining administrator access to… | |
| Modificada | Media (4.3) | 0.48% | — | Jenkins Nexus Platform | 13/12/2023 | 17/6/2026 | Missing permission checks in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Alta (8.8) | 0.45% | — | Jenkins Nexus Platform | 13/12/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Media (5.4) | 0.44% | — | Jenkins Nexus Platform | 13/12/2023 | 17/6/2026 | Missing permission checks in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML. | |
| Modificada | Alta (8.8) | 0.45% | — | Jenkins Nexus Platform | 13/12/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allows attackers to send an HTTP request to an attacker-specified URL and parse the response as XML. | |
| Modificada | Media (4.3) | 0.45% | — | Jenkins Scriptler | 13/12/2023 | 17/6/2026 | A missing permission check in Jenkins Scriptler Plugin 342.v6a_89fd40f466 and earlier allows attackers with Overall/Read permission to read the contents of a Groovy script by knowing its ID. | |
| Modificada | Alta (8.1) | 0.84% | — | Jenkins Scriptler | 13/12/2023 | 17/6/2026 | Jenkins Scriptler Plugin 342.v6a_89fd40f466 and earlier does not restrict a file name query parameter in an HTTP endpoint, allowing attackers with Scriptler/Configure permission to delete arbitrary files on the Jenkins controller file system. | |
| Modificada | Media (4.3) | 0.48% | — | Jenkins Neuvector Vulnerability Scanner | 29/11/2023 | 17/6/2026 | A missing permission check in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified hostname and port using attacker-specified username and password. | |
| Modificada | Alta (8.8) | 0.45% | — | Jenkins Neuvector Vulnerability ScannerJenkins JiraJenkins Google Compute EngineJenkins Matlab | 29/11/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers to connect to an attacker-specified hostname and port using attacker-specified username and password. | |
| Modificada | Crítica (9.8) | 0.84% | — | Jenkins Matlab | 29/11/2023 | 17/6/2026 | Jenkins MATLAB Plugin 2.11.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Modificada | Alta (8.8) | 0.40% | — | Jenkins Matlab | 29/11/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins MATLAB Plugin 2.11.0 and earlier allows attackers to have Jenkins parse an XML file from the Jenkins controller file system. | |
| Modificada | Crítica (9.8) | 0.79% | — | Jenkins Matlab | 29/11/2023 | 17/6/2026 | Missing permission checks in Jenkins MATLAB Plugin 2.11.0 and earlier allow attackers to have Jenkins parse an XML file from the Jenkins controller file system. | |
| Modificada | Media (6.5) | 0.61% | — | Jenkins Jira | 29/11/2023 | 17/6/2026 | Jenkins Jira Plugin 3.11 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to. | |
| Modificada | Baja (2.7) | 0.53% | — | Jenkins Google Compute Engine | 29/11/2023 | 17/6/2026 | Incorrect permission checks in Jenkins Google Compute Engine Plugin 4.550.vb_327fca_3db_11 and earlier allow attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate system-scoped credentials IDs of credentials stored in Jenkins and to connect to… | |
| Modificada | Media (5.3) | 0.46% | — | Jenkins Zanata | 25/10/2023 | 17/6/2026 | Jenkins Zanata Plugin 0.6 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token hashes are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token. | |
| Modificada | Media (5.4) | 0.46% | — | Jenkins Edgewall Trac | 25/10/2023 | 17/6/2026 | Jenkins Edgewall Trac Plugin 1.13 and earlier does not escape the Trac website URL on the build page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Media (5.3) | 0.57% | — | Jenkins Msteams Webhook Trigger | 25/10/2023 | 17/6/2026 | Jenkins MSTeams Webhook Trigger Plugin 0.1.1 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token. | |
| Modificada | Media (5.3) | 0.57% | — | Jenkins Gogs | 25/10/2023 | 17/6/2026 | Jenkins Gogs Plugin 1.0.15 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token. | |
| Modificada | Media (5.3) | 0.56% | — | Jenkins Multibranch Scan Webhook Trigger | 25/10/2023 | 17/6/2026 | Jenkins Multibranch Scan Webhook Trigger Plugin 1.0.9 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token. | |
| Modificada | Media (6.5) | 1.2% | — | Jenkins Cloudbees CD | 25/10/2023 | 17/6/2026 | Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the directory from which artifacts are published during the 'CloudBees CD - Publish Artifact' post-build step, allowing attackers able to configure jobs to publish arbitrary files from the Jenkins controller file system to… | |
| Modificada | Alta (8.1) | 1.4% | — | Jenkins Cloudbees CD | 25/10/2023 | 17/6/2026 | Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the expected directory during the cleanup process of the 'CloudBees CD - Publish Artifact' post-build step, allowing attackers able to configure jobs to delete arbitrary files on the Jenkins controller file system. | |
| Modificada | Media (6.5) | 0.36% | — | Jenkins Lambdatest-automation | 25/10/2023 | 17/6/2026 | Jenkins lambdatest-automation Plugin 1.20.10 and earlier logs LAMBDATEST Credentials access token at the INFO level, potentially resulting in its exposure. | |
| Modificada | Media (4.3) | 0.39% | — | Jenkins Lambdatest-automation | 25/10/2023 | 17/6/2026 | A missing permission check in Jenkins lambdatest-automation Plugin 1.20.9 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of LAMBDATEST credentials stored in Jenkins. | |
| Modificada | Media (6.5) | 0.61% | — | Jenkins Warnings | 25/10/2023 | 17/6/2026 | Jenkins Warnings Plugin 10.5.0 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to. This fix has been backported to 10.4.1. |