Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

1897 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.56%—Jenkins Openshift Login12/7/202317/6/2026
Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.
ModificadaAlta (8.8)0.83%—Jenkins Openshift Login12/7/202317/6/2026
Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier does not invalidate the previous session on login.
ModificadaMedia (4.3)0.45%—Jenkins Saml Single Sign ON12/7/202317/6/2026
A missing permission check in Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 through 2.3.0 (both inclusive) allows attackers with Overall/Read permission to download a string representation of the current security realm.
ModificadaMedia (6.5)0.83%—Jenkins Datadog12/7/202317/6/2026
A missing permission check in Jenkins Datadog Plugin 5.4.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
ModificadaMedia (5.9)0.46%—Jenkins Active Directory12/7/202317/6/2026
Jenkins Active Directory Plugin 2.30 and earlier ignores the "Require TLS" and "StartTls" options and always performs the connection test to Active directory unencrypted, allowing attackers able to capture network traffic between the Jenkins controller and Active Directory servers to obtain Active Directory…
ModificadaMedia (6.5)0.61%—Jenkins External Monitor JOB Type12/7/202317/6/2026
Jenkins External Monitor Job Type Plugin 206.v9a_94ff0b_4a_10 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
ModificadaMedia (4.3)0.50%—Jenkins Team Concert19/6/202317/6/2026
Missing permission checks in Jenkins Team Concert Plugin 2.4.1 and earlier allow attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.
ModificadaMedia (6.5)0.66%—Jenkins Digital.ai APP Management Publisher14/6/202317/6/2026
A missing permission check in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL, capturing credentials stored in Jenkins.
ModificadaMedia (6.5)0.45%—Jenkins Digital.ai APP Management Publisher14/6/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers to connect to an attacker-specified URL, capturing credentials stored in Jenkins.
ModificadaMedia (6.5)0.63%—Jenkins AWS Codecommit Trigger14/6/202317/6/2026
Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not restrict the AWS SQS queue name path parameter in an HTTP endpoint, allowing attackers with Item/Read permission to obtain the contents of arbitrary files on the Jenkins controller file system.
ModificadaMedia (5.4)0.75%—Jenkins Template Workflows14/6/202317/6/2026
Jenkins Template Workflows Plugin 41.v32d86a_313b_4a and earlier does not escape names of jobs used as buildings blocks for Template Workflow Job, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create jobs.
ModificadaMedia (5.4)0.66%—Jenkins Sonargraph Integration14/6/202317/6/2026
Jenkins Sonargraph Integration Plugin 5.0.1 and earlier does not escape the file path and the project name for the Log file field form validation, resulting in a stored cross-site scripting vulnerability exploitable by attackers with Item/Configure permission.
ModificadaMedia (5.4)0.62%—Jenkins Maven Repository Server14/6/202317/6/2026
Jenkins Maven Repository Server Plugin 1.10 and earlier does not escape project and build display names on the Build Artifacts As Maven Repository page, resulting in a stored cross-site scripting (XSS) vulnerability.
ModificadaMedia (5.4)0.62%—Jenkins Maven Repository Server14/6/202317/6/2026
Jenkins Maven Repository Server Plugin 1.10 and earlier does not escape the versions of build artifacts on the Build Artifacts As Maven Repository page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control maven project versions in `pom.xml`.
ModificadaAlta (8.1)0.78%—Jenkins Checkmarx14/6/202317/6/2026
Jenkins Checkmarx Plugin 2022.4.3 and earlier disables SSL/TLS validation for connections to the Checkmarx server by default.
ModificadaAlta (8)0.86%—Jenkins14/6/202317/6/2026
In Jenkins 2.399 and earlier, LTS 2.387.3 and earlier, POST requests are sent in order to load the list of context actions. If part of the URL includes insufficiently escaped user-provided values, a victim may be tricked into sending a POST request to an unexpected endpoint by opening a context menu.
ModificadaMedia (4.3)0.39%—Jenkins Code DX16/5/202317/6/2026
A missing permission check in Jenkins Code Dx Plugin 3.1.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.
ModificadaBaja (3.5)0.41%—Jenkins Code DX16/5/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Code Dx Plugin 3.1.0 and earlier allows attackers to connect to an attacker-specified URL.
ModificadaMedia (4.3)0.41%—Jenkins Code DX16/5/202317/6/2026
Jenkins Code Dx Plugin 3.1.0 and earlier does not mask Code Dx server API keys displayed on the configuration form, increasing the potential for attackers to observe and capture them.
ModificadaMedia (4.3)0.63%—Jenkins Code DX16/5/202317/6/2026
Jenkins Code Dx Plugin 3.1.0 and earlier stores Code Dx server API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
ModificadaMedia (4.3)0.95%—Jenkins Code DX16/5/202317/6/2026
A missing permission check in Jenkins Code Dx Plugin 3.1.0 and earlier allows attackers with Item/Read permission to check for the existence of an attacker-specified file path on an agent file system.
ModificadaMedia (5.4)0.46%—Jenkins Loadcomplete Support16/5/202317/6/2026
Jenkins LoadComplete support Plugin 1.0 and earlier does not escape the LoadComplete test name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
ModificadaMedia (5.4)0.32%—Jenkins Wso2 Oauth16/5/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins WSO2 Oauth Plugin 1.0 and earlier allows attackers to trick users into logging in to the attacker's account.
ModificadaMedia (5.4)0.43%—Jenkins Wso2 Oauth16/5/202317/6/2026
Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the previous session on login.
ModificadaMedia (4.3)0.43%—Jenkins TAG Profiler16/5/202317/6/2026
A missing permission check in Jenkins Tag Profiler Plugin 0.2 and earlier allows attackers with Overall/Read permission to reset profiler statistics.
Orbitaley — Vulnerabilidades