Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

50 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)13%—Apache Commons CompressOracle Banking ApisOracle Banking Digital ExperienceOracle Banking Enterprise Default Management+3013/7/202117/6/2026
When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.
ModificadaAlta (7.5)12%—Apache Commons CompressNetapp Active IQ Unified ManagerNetapp Oncommand InsightOracle Banking Digital Experience+2013/7/202117/6/2026
When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
ModificadaAlta (7.5)12%—Apache Commons CompressNetapp Active IQ Unified ManagerNetapp Oncommand InsightOracle Banking Digital Experience+2213/7/202117/6/2026
When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
ModificadaCrítica (9.8)6.9%—PythonOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Slice Selection Function+26/5/202117/6/2026
In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.
ModificadaMedia (4.3)1.1%—ElasticsearchOracle Communications Cloud Native Core Automated Test Suite8/3/202117/6/2026
A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query against a recently updated document. This affects documents that have been updated and not yet…
ModificadaMedia (4.8)1.2%—ElasticsearchOracle Communications Cloud Native Core Automated Test Suite14/1/202117/6/2026
Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This…
ModificadaMedia (6.1)2.2%💥 PoCRedhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+1838/11/201925/8/2026
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
ModificadaAlta (8.8)1.6%—JenkinsOracle Communications Cloud Native Core Automated Test SuiteRedhat Openshift Container Platform28/8/201917/6/2026
Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session ID, resulting in CSRF tokens that did not expire and could be used to bypass CSRF protection for the anonymous user.
ModificadaMedia (4.8)1.4%—JenkinsOracle Communications Cloud Native Core Automated Test SuiteRedhat Openshift Container Platform28/8/201917/6/2026
A stored cross-site scripting vulnerability in Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed attackers with Overall/Administer permission to configure the update site URL to inject arbitrary HTML and JavaScript in update center web pages.
ModificadaMedia (5.4)1.3%—JenkinsOracle Communications Cloud Native Core Automated Test SuiteRedhat Openshift Container Platform10/4/201917/6/2026
The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, resulting in a cross-site scripting (XSS) vulnerability exploitable by users with the ability to control job names.
ModificadaAlta (8.1)2.1%—JenkinsRedhat Openshift Container PlatformOracle Communications Cloud Native Core Automated Test Suite10/4/201917/6/2026
Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-1003004 in these releases did not reject existing remoting-based CLI authentication…
ModificadaMedia (5.4)0.89%—JenkinsOracle Communications Cloud Native Core Automated Test Suite23/7/201817/6/2026
A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers with the ability to control the existence of some URLs in Jenkins to define JavaScript that would be executed in another user's browser…
ModificadaMedia (5.4)0.89%—JenkinsOracle Communications Cloud Native Core Automated Test Suite23/7/201817/6/2026
A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in BuildTimelineWidget.java, BuildTimelineWidget/control.jelly that allows attackers with Job/Configure permission to define JavaScript that would be executed in another user's browser when that other user performs some UI…
ModificadaMedia (4.3)0.94%—JenkinsOracle Communications Cloud Native Core Automated Test Suite23/7/201817/6/2026
A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in SlaveComputer.java that allows attackers with Overall/Read permission to initiate agent launches, and abort in-progress agent launches.
ModificadaMedia (4.3)0.76%—JenkinsOracle Communications Cloud Native Core Automated Test Suite23/7/201817/6/2026
A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Queue.java that allows attackers with Overall/Read permission to cancel queued builds.
ModificadaAlta (7.5)86%💥 ExploitJenkinsOracle Communications Cloud Native Core Automated Test Suite23/7/201817/6/2026
A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers to send crafted HTTP requests returning the contents of any file on the Jenkins master file system that the Jenkins master has access to.
ModificadaAlta (8.8)18%—JenkinsOracle Communications Cloud Native Core Automated Test Suite23/7/201817/6/2026
A unauthorized modification of configuration vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in User.java that allows attackers to provide crafted login credentials that cause Jenkins to move the config.xml file from the Jenkins home directory. If Jenkins is started without this file present, it…
ModificadaMedia (4.3)2.1%—JenkinsOracle Communications Cloud Native Core Automated Test Suite5/6/201817/6/2026
A server-side request forgery vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in ZipExtractionInstaller.java that allows users with Overall/Read permission to have Jenkins submit a HTTP GET request to an arbitrary URL and learn whether the response is successful (200) or not.
ModificadaAlta (8.1)2.6%—JenkinsOracle Communications Cloud Native Core Automated Test Suite5/6/201817/6/2026
A path traversal vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in FilePath.java, SoloFilePathFilter.java that allows malicious agents to read and write arbitrary files on the Jenkins master, bypassing the agent-to-master security subsystem protection.
ModificadaMedia (4.3)1.0%—JenkinsOracle Communications Cloud Native Core Automated Test Suite5/6/201817/6/2026
A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in HudsonPrivateSecurityRealm.java that allows users to sign up using user names containing control characters that can then appear to have the same name as other users, and cannot be deleted via the…
ModificadaMedia (4.3)1.1%—JenkinsOracle Communications Cloud Native Core Automated Test Suite5/6/201817/6/2026
A information exposure vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in AboutJenkins.java, ListPluginsCommand.java that allows users with Overall/Read access to enumerate all installed plugins.
ModificadaMedia (6.5)3.9%—JenkinsOracle Communications Cloud Native Core Automated Test Suite20/2/201817/6/2026
Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base directory for URLs accessing plugin resource files. This allowed users with Overall/Read permission to download files from the Jenkins master they should not have access to. On Windows, any file…
ModificadaMedia (5.3)2.0%—JenkinsOracle Communications Cloud Native Core Automated Test Suite16/2/201817/6/2026
An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to access plugin resource files in the META-INF and WEB-INF directories that should not be accessible, if the Jenkins home directory is on a case-insensitive file system.
ModificadaMedia (5.3)1.7%—JenkinsOracle Communications Cloud Native Core Automated Test Suite16/2/201817/6/2026
An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to have Jenkins submit HTTP GET requests and get limited information about the response.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitJenkinsOracle Communications Cloud Native Core Automated Test Suite29/1/201817/6/2026
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers to transfer a serialized Java `SignedObject` object to the Jenkins CLI, that would be deserialized using a new…
Orbitaley — Vulnerabilidades