Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
583 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.82% | — | Jenkins Awseb Deployment | 7/4/2020 | 17/6/2026 | Jenkins AWSEB Deployment Plugin 0.3.19 and earlier does not escape various values printed as part of form validation output, resulting in a reflected cross-site scripting vulnerability. | |
| Modificada | Alta (8.8) | 1.1% | — | Jenkins Rapiddeploy | 25/3/2020 | 17/6/2026 | Jenkins RapidDeploy Plugin 4.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Modificada | Media (5.4) | 0.73% | — | Jenkins Rapiddeploy | 25/3/2020 | 17/6/2026 | Jenkins RapidDeploy Plugin 4.2 and earlier does not escape package names in the table of packages obtained from a remote server, resulting in a stored XSS vulnerability. | |
| Modificada | Alta (8.8) | 1.0% | — | Octopus Deploy | 19/3/2020 | 17/6/2026 | In Octopus Deploy before 2020.1.5, for customers running on-premises Active Directory linked to their Octopus server, an authenticated user can leverage a bug to escalate privileges. | |
| Modificada | Media (4.3) | 0.64% | — | Jenkins Deployhub | 9/3/2020 | 17/6/2026 | Jenkins DeployHub Plugin 8.0.14 and earlier transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure. | |
| Modificada | Media (5.3) | 0.61% | — | Jenkins Openshift Deployer | 9/3/2020 | 17/6/2026 | Jenkins OpenShift Deployer Plugin 1.2.0 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure. | |
| Modificada | Alta (8.8) | 0.49% | — | Cloudfoundry Cf-deploymentCloudfoundry User Account AND Authentication | 27/2/2020 | 17/6/2026 | In Cloud Foundry UAA, versions prior to 74.14.0, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function when authenticating with external identity providers. | |
| Modificada | Media (6.5) | 0.75% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deployment | 27/2/2020 | 17/6/2026 | Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which may include sensitive information such as credentials if provided to the job. A malicious user with access to those logs may gain unauthorized access to resources protected by such credentials. | |
| Modificada | Baja (2.3) | 0.32% | — | IBM Urbancode BuildIBM Urbancode Deploy | 13/2/2020 | 17/6/2026 | IBM UrbanCode Deploy (UCD) 7.0.3 and IBM UrbanCode Build 6.1.5 could allow a local user to obtain sensitive information by unmasking certain secure values in documents. IBM X-Force ID: 171248. | |
| Modificada | Alta (7.4) | 0.53% | — | Cloudfoundry CredhubPivotal Software Cloud Foundry Cf-deployment | 12/2/2020 | 17/6/2026 | Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TLS. A malicious user with access to the network between CredHub and its MySQL database may eavesdrop on database connections and thereby gain unauthorized access to CredHub and other components. | |
| Modificada | Media (4.3) | 0.69% | — | Jenkins BMC Release Package AND Deployment | 12/2/2020 | 17/6/2026 | Jenkins BMC Release Package and Deployment Plugin 1.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | |
| Modificada | Alta (7.6) | 0.90% | — | Jenkins Websphere Deployer | 29/1/2020 | 17/6/2026 | Jenkins WebSphere Deployer Plugin 1.6.1 and earlier does not configure the XML parser to prevent XXE attacks which can be exploited by a user with Job/Configure permissions. | |
| Modificada | Alta (7.5) | 3.1% | — | Xmlsoft Libxml2Debian LinuxNetapp Cloud BackupNetapp Clustered Data Ontap+20 | 21/1/2020 | 17/6/2026 | xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak. | |
| Modificada | Alta (7.5) | 89% | 💥 PoC | Vmware Spring FrameworkOracle Application Testing SuiteOracle Communications Billing AND Revenue Management Elastic Charging EngineOracle Communications Cloud Native Core Policy+29 | 17/1/2020 | 17/6/2026 | In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input. | |
| Modificada | Crítica (9.8) | 8.6% | — | Fasterxml Jackson-databindOracle Banking PlatformOracle Communications Billing AND Revenue ManagementOracle Communications Cloud Native Core Network Slice Selection Function+26 | 3/1/2020 | 17/6/2026 | FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking. | |
| Modificada | Alta (7.5) | 5.6% | — | Xmlsoft Libxml2Debian LinuxOracle Real User Experience InsightFedoraproject Fedora+8 | 24/12/2019 | 17/6/2026 | xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs. | |
| Modificada | Media (4.3) | 0.78% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deployment | 19/12/2019 | 17/6/2026 | Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all global service brokers, including service broker URLs and GUIDs, which should only be accessible to admins. | |
| Modificada | Alta (8) | 0.96% | — | Tibco Spotfire AnalystTibco Spotfire Analytics Platform FOR AWSTibco Spotfire Deployment KITTibco Spotfire Desktop+1 | 17/12/2019 | 17/6/2026 | The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Deployment Kit, TIBCO Spotfire Desktop, and TIBCO Spotfire Desktop Language Packs contains a vulnerability that theoretically allows an attacker with permission to write… | |
| Modificada | Media (4.3) | 0.71% | — | Jenkins Rapiddeploy | 17/12/2019 | 17/6/2026 | A missing permission check in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified web server. | |
| Modificada | Alta (8.8) | 0.69% | — | Jenkins Rapiddeploy | 17/12/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers to connect to an attacker-specified web server. | |
| Modificada | Alta (7.1) | 0.51% | — | Jenkins Websphere Deployer | 17/12/2019 | 17/6/2026 | Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows users with Overall/Read access to disable SSL/TLS certificate and hostname validation for the entire Jenkins master JVM. | |
| Modificada | Alta (8.8) | 0.69% | — | Jenkins Websphere Deployer | 17/12/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers to perform connection tests and determine whether files with an attacker-specified path exist on the Jenkins master file system. | |
| Modificada | Media (5.4) | 0.68% | — | Jenkins Websphere Deployer | 17/12/2019 | 17/6/2026 | A missing permission check in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers with Overall/Read permission to perform connection tests and determine whether files with an attacker-specified path exist on the Jenkins master file system. | |
| Modificada | Alta (8.1) | 1.5% | — | Redhat EdeployRedhat Jboss Enterprise WEB Server | 15/12/2019 | 17/6/2026 | eDeploy has tmp file race condition flaws | |
| Modificada | Crítica (9.8) | 2.4% | — | Redhat EdeployRedhat Jboss Enterprise WEB Server | 15/12/2019 | 17/6/2026 | eDeploy has RCE via cPickle deserialization of untrusted data |