Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
583 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.34% | — | Jenkins AWS Codedeploy | 9/7/2018 | 17/6/2026 | Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodeDeployPublisher.java that can result in Credentials Disclosure. This attack appear to be exploitable via local file access. This vulnerability appears to have been fixed in… | |
| Modificada | Media (4.3) | 0.97% | — | Jenkins AWS Codedeploy | 9/7/2018 | 17/6/2026 | Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a File and Directory Information Exposure vulnerability in AWSCodeDeployPublisher.java that can result in Disclosure of environment variables. This vulnerability appears to have been fixed in 1.20 and later. | |
| Modificada | Alta (7.5) | 1.1% | — | Tokitdeployer Project Tokitdeployer | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for Deploy, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (8.8) | 0.93% | — | Tibco Spotfire AnalystTibco Spotfire Analytics Platform FOR AWSTibco Spotfire Deployment KITTibco Spotfire Desktop+1 | 27/6/2018 | 17/6/2026 | The TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Deployment Kit, TIBCO Spotfire Desktop, and TIBCO Spotfire Desktop Language Packs contain multiple vulnerabilities that may… | |
| Modificada | Crítica (9.8) | 3.2% | — | Tibco Spotfire AnalystTibco Spotfire Analytics Platform FOR AWSTibco Spotfire Deployment KITTibco Spotfire Desktop+1 | 27/6/2018 | 17/6/2026 | The TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Deployment Kit, TIBCO Spotfire Desktop, and TIBCO Spotfire Desktop Language Packs contain multiple vulnerabilities that may… | |
| Modificada | Media (6.5) | 0.79% | — | Octopus Deploy | 26/6/2018 | 17/6/2026 | In Octopus Deploy 3.0 onwards (before 2018.6.7), an authenticated user with incorrect permissions may be able to create Accounts under the Infrastructure menu. | |
| Modificada | Alta (7.2) | 1.8% | — | Cloudfoundry Cf-deploymentPivotal Software Cloud Foundry Diego | 6/6/2018 | 17/6/2026 | Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers. A remote attacker with CF admin privileges can upload a malicious buildpack that will allow a complete takeover of a Diego Cell VM and access to all apps running on that Diego Cell. | |
| Modificada | Media (4.9) | 1.6% | — | IBM Urbancode Deploy | 25/5/2018 | 17/6/2026 | IBM UrbanCode Deploy 6.1 and 6.2 could allow an authenticated privileged user to obtain highly sensitive information. IBM X-Force ID: 135547. | |
| Modificada | Media (5.3) | 1.1% | — | Cloudfoundry Cf-deploymentCloudfoundry Routing-release | 23/5/2018 | 17/6/2026 | Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. A remote user can set the X-Forwarded-Proto header in a request to potentially bypass an application requirement to only respond over secure connections. | |
| Modificada | Alta (7.2) | 1.3% | — | Pivotal Software Cloud Foundry UAAPivotal Software Cloud Foundry Uaa-releaseCloudfoundry Cf-deployment | 15/5/2018 | 17/6/2026 | Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clients performing offline validation. A zone administrator could configure their zone to issue tokens which impersonate another zone, granting up to admin privileges in the… | |
| Modificada | Media (5.4) | 0.73% | — | Octopus Deploy | 1/5/2018 | 17/6/2026 | In Octopus Deploy 3.4.x before 2018.4.7, an authenticated user is able to view/update/save variable values within the Tenant Variables area for Environments that do not exist within their associated Team scoping. This occurs in situations where this authenticated user also belongs to multiple teams, where one of the… | |
| Modificada | Media (6.5) | 1.1% | — | Cloudfoundry Garden-runcCloudfoundry Cf-deployment | 30/4/2018 | 17/6/2026 | Cloud Foundry Garden-runC, versions prior to 1.13.0, does not correctly enforce disc quotas for Docker image layers. A remote authenticated user may push an app with a malicious Docker image that will consume more space on a Diego cell than allocated in their quota, potentially causing a DoS against the cell. | |
| Modificada | Alta (7.5) | 1.3% | — | Octopus Deploy | 30/4/2018 | 17/6/2026 | In Octopus Deploy before 2018.4.7, target and tenant tag variable scopes were not checked against the list of tenants the user has access to. | |
| Modificada | Alta (8.8) | 0.92% | — | Cloudfoundry Cf-deploymentCloudfoundry Garden-runc-release | 29/3/2018 | 17/6/2026 | Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access to Garden logs may be able to obtain leaked credentials and perform authenticated actions using those credentials. | |
| Modificada | Media (6.5) | 1.0% | — | Octopus Deploy | 27/3/2018 | 17/6/2026 | In Octopus Deploy 2.0 and later before 2018.3.7, an authenticated user, with variable edit permissions, can scope some variables to targets greater than their permissions should allow. In other words, they can see machines beyond their team's scoped environments. | |
| Modificada | Crítica (9.8) | 1.2% | — | Unify Openscape Deployment Service | 19/3/2018 | 17/6/2026 | SQL injection vulnerability in OpenScape Deployment Service (DLS) before 6.x and 7.x before R1.11.3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (8.1) | 1.2% | — | Cloudfoundry Cf-deploymentCloudfoundry Routing-release | 19/3/2018 | 17/6/2026 | In cf-deployment before 1.14.0 and routing-release before 0.172.0, the Cloud Foundry Gorouter mishandles WebSocket requests for AWS Application Load Balancers (ALBs) and some other HTTP-aware Load Balancers. A user with developer privileges could use this vulnerability to steal data or cause denial of service. | |
| Modificada | Alta (8.8) | 0.98% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deploymentCloudfoundry Cf-release | 19/3/2018 | 17/6/2026 | In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller accepts refresh tokens for authentication where access tokens are expected. This exposes a vulnerability where a refresh token that would otherwise be insufficient to obtain an… | |
| Modificada | Media (6.5) | 0.84% | — | Symantec Altiris Deployment Solution | 19/2/2018 | 16/6/2026 | DBManager in Symantec Altiris Deployment Solution 6.9.x before DS 6.9 SP4 allows remote attackers to cause a denial of service via a crafted request. | |
| Modificada | Alta (8.8) | 1.0% | — | Pivotal Software Cloud Foundry UAAPivotal Software Cloud Foundry Uaa-releasePivotal Software Cloud Foundry Cf-releasePivotal Software Cloud Foundry Cf-deployment | 1/2/2018 | 17/6/2026 | In Cloud Foundry Foundation cf-release versions prior to v285; cf-deployment versions prior to v1.7; UAA 4.5.x versions prior to 4.5.5, 4.8.x versions prior to 4.8.3, and 4.7.x versions prior to 4.7.4; and UAA-release 45.7.x versions prior to 45.7, 52.7.x versions prior to 52.7, and 53.3.x versions prior to 53.3, the… | |
| Modificada | Media (4.3) | 0.95% | — | Oracle Siebel Engineering-installer AND Deployment | 18/1/2018 | 17/6/2026 | Vulnerability in the Siebel Engineering - Installer and Deployment component of Oracle Siebel CRM (subcomponent: Siebel Approval Manager). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel… | |
| Modificada | Alta (8.8) | 1.0% | — | Octopus Deploy | 16/1/2018 | 17/6/2026 | An issue was discovered in Octopus Deploy before 4.1.9. Any user with user editing permissions can modify teams to give themselves Administer System permissions even if they didn't have them, as demonstrated by use of the RoleEdit or TeamEdit permission. | |
| Modificada | Media (5.4) | 0.70% | — | IBM Urbancode Deploy | 9/1/2018 | 17/6/2026 | IBM UrbanCode Deploy (UCD) 6.1 and 6.2 could allow an authenticated user to edit objects that they should not have access to due to improper access controls. IBM X-Force ID: 128691. | |
| Modificada | Alta (8.8) | 1.1% | — | Octopus Deploy | 3/1/2018 | 17/6/2026 | In Octopus Deploy versions 3.2.11 - 4.1.5 (fixed in 4.1.6), an authenticated user with ProcessEdit permission could reference an Azure account in such a way as to bypass the scoping restrictions, resulting in a potential escalation of privileges. | |
| Modificada | Alta (8.8) | 1.1% | — | Octopus Deploy | 13/12/2017 | 17/6/2026 | In Octopus Deploy before 4.1.3, the machine update process doesn't check that the user has access to all environments. This allows an access-control bypass because the set of environments to which a machine is scoped may include environments in which the user lacks access. |