Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

583 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.82%—Jenkins Awseb Deployment7/4/202017/6/2026
Jenkins AWSEB Deployment Plugin 0.3.19 and earlier does not escape various values printed as part of form validation output, resulting in a reflected cross-site scripting vulnerability.
ModificadaAlta (8.8)1.1%—Jenkins Rapiddeploy25/3/202017/6/2026
Jenkins RapidDeploy Plugin 4.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
ModificadaMedia (5.4)0.73%—Jenkins Rapiddeploy25/3/202017/6/2026
Jenkins RapidDeploy Plugin 4.2 and earlier does not escape package names in the table of packages obtained from a remote server, resulting in a stored XSS vulnerability.
ModificadaAlta (8.8)1.0%—Octopus Deploy19/3/202017/6/2026
In Octopus Deploy before 2020.1.5, for customers running on-premises Active Directory linked to their Octopus server, an authenticated user can leverage a bug to escalate privileges.
ModificadaMedia (4.3)0.64%—Jenkins Deployhub9/3/202017/6/2026
Jenkins DeployHub Plugin 8.0.14 and earlier transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure.
ModificadaMedia (5.3)0.61%—Jenkins Openshift Deployer9/3/202017/6/2026
Jenkins OpenShift Deployer Plugin 1.2.0 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
ModificadaAlta (8.8)0.49%—Cloudfoundry Cf-deploymentCloudfoundry User Account AND Authentication27/2/202017/6/2026
In Cloud Foundry UAA, versions prior to 74.14.0, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function when authenticating with external identity providers.
ModificadaMedia (6.5)0.75%—Cloudfoundry Capi-releaseCloudfoundry Cf-deployment27/2/202017/6/2026
Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which may include sensitive information such as credentials if provided to the job. A malicious user with access to those logs may gain unauthorized access to resources protected by such credentials.
ModificadaBaja (2.3)0.32%—IBM Urbancode BuildIBM Urbancode Deploy13/2/202017/6/2026
IBM UrbanCode Deploy (UCD) 7.0.3 and IBM UrbanCode Build 6.1.5 could allow a local user to obtain sensitive information by unmasking certain secure values in documents. IBM X-Force ID: 171248.
ModificadaAlta (7.4)0.53%—Cloudfoundry CredhubPivotal Software Cloud Foundry Cf-deployment12/2/202017/6/2026
Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TLS. A malicious user with access to the network between CredHub and its MySQL database may eavesdrop on database connections and thereby gain unauthorized access to CredHub and other components.
ModificadaMedia (4.3)0.69%—Jenkins BMC Release Package AND Deployment12/2/202017/6/2026
Jenkins BMC Release Package and Deployment Plugin 1.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
ModificadaAlta (7.6)0.90%—Jenkins Websphere Deployer29/1/202017/6/2026
Jenkins WebSphere Deployer Plugin 1.6.1 and earlier does not configure the XML parser to prevent XXE attacks which can be exploited by a user with Job/Configure permissions.
ModificadaAlta (7.5)3.1%—Xmlsoft Libxml2Debian LinuxNetapp Cloud BackupNetapp Clustered Data Ontap+2021/1/202017/6/2026
xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak.
ModificadaAlta (7.5)89%💥 PoCVmware Spring FrameworkOracle Application Testing SuiteOracle Communications Billing AND Revenue Management Elastic Charging EngineOracle Communications Cloud Native Core Policy+2917/1/202017/6/2026
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.
ModificadaCrítica (9.8)8.6%—Fasterxml Jackson-databindOracle Banking PlatformOracle Communications Billing AND Revenue ManagementOracle Communications Cloud Native Core Network Slice Selection Function+263/1/202017/6/2026
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
ModificadaAlta (7.5)5.6%—Xmlsoft Libxml2Debian LinuxOracle Real User Experience InsightFedoraproject Fedora+824/12/201917/6/2026
xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.
ModificadaMedia (4.3)0.78%—Cloudfoundry Capi-releaseCloudfoundry Cf-deployment19/12/201917/6/2026
Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all global service brokers, including service broker URLs and GUIDs, which should only be accessible to admins.
ModificadaAlta (8)0.96%—Tibco Spotfire AnalystTibco Spotfire Analytics Platform FOR AWSTibco Spotfire Deployment KITTibco Spotfire Desktop+117/12/201917/6/2026
The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Deployment Kit, TIBCO Spotfire Desktop, and TIBCO Spotfire Desktop Language Packs contains a vulnerability that theoretically allows an attacker with permission to write…
ModificadaMedia (4.3)0.71%—Jenkins Rapiddeploy17/12/201917/6/2026
A missing permission check in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified web server.
ModificadaAlta (8.8)0.69%—Jenkins Rapiddeploy17/12/201917/6/2026
A cross-site request forgery vulnerability in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers to connect to an attacker-specified web server.
ModificadaAlta (7.1)0.51%—Jenkins Websphere Deployer17/12/201917/6/2026
Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows users with Overall/Read access to disable SSL/TLS certificate and hostname validation for the entire Jenkins master JVM.
ModificadaAlta (8.8)0.69%—Jenkins Websphere Deployer17/12/201917/6/2026
A cross-site request forgery vulnerability in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers to perform connection tests and determine whether files with an attacker-specified path exist on the Jenkins master file system.
ModificadaMedia (5.4)0.68%—Jenkins Websphere Deployer17/12/201917/6/2026
A missing permission check in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers with Overall/Read permission to perform connection tests and determine whether files with an attacker-specified path exist on the Jenkins master file system.
ModificadaAlta (8.1)1.5%—Redhat EdeployRedhat Jboss Enterprise WEB Server15/12/201917/6/2026
eDeploy has tmp file race condition flaws
ModificadaCrítica (9.8)2.4%—Redhat EdeployRedhat Jboss Enterprise WEB Server15/12/201917/6/2026
eDeploy has RCE via cPickle deserialization of untrusted data