Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
–

54 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.97%—Jenkins Rundeck21/9/202217/6/2026
Jenkins Rundeck Plugin 3.6.11 and earlier does not protect access to the /plugin/rundeck/webhook/ endpoint, allowing users with Overall/Read permission to trigger jobs that are configured to be triggerable via Rundeck.
ModificadaMedia (4.3)0.62%—Jenkins Rundeck21/9/202217/6/2026
Jenkins Rundeck Plugin 3.6.11 and earlier does not perform Run/Artifacts permission checks in multiple HTTP endpoints, allowing attackers with Item/Read permission to obtain information about build artifacts of a given job, if the optional Run/Artifacts permission is enabled.
ModificadaAlta (7.5)0.67%—Pagerduty Rundeck15/6/202217/6/2026
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. The Key Storage converter plugin mechanism was not enabled correctly in Rundeck 4.2.0 and 4.2.1, resulting in use of the encryption layer for Key Storage possibly not working. Any credentials created or overwritten using…
ModificadaCrítica (9.8)1.2%—Pagerduty Rundeck20/5/202217/6/2026
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Rundeck community and rundeck-enterprise docker images contained a pre-generated SSH keypair. If the id_rsa.pub public key of the keypair was copied to authorized_keys files on remote host, those hosts would allow access…
ModificadaMedia (4.3)0.97%—Nextcloud Deck20/5/202217/6/2026
Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud. In versions prior to 1.4.8, 1.5.6, and 1.6.1, an authenticated user can move stacks with cards from their own board to a board of another user. The Nextcloud Deck app contains a patch for this issue in versions 1.4.8, 1.5.6, and 1.6.1.…
ModificadaMedia (4.3)1.1%—Nextcloud Deck20/5/202217/6/2026
Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud, similar to Trello. The full path of the application is exposed to unauthorized users. It is recommended that the Nextcloud Deck app is upgraded to 1.2.11, 1.4.6, or 1.5.4. There is no workaround available.
ModificadaMedia (5.4)73%—Jenkins Rundeck17/5/202217/6/2026
Jenkins Rundeck Plugin 3.6.10 and earlier does not restrict URL schemes in Rundeck webhook submissions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to submit crafted Rundeck webhook payloads.
ModificadaAlta (8.1)0.75%—Pagerduty Rundeck28/2/202217/6/2026
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In versions prior to 3.4.5, authenticated users could craft a request to modify or delete System or Project level Calendars, without appropriate authorization. Modifying or removing calendars could cause Scheduled Jobs to…
ModificadaMedia (5.4)0.56%—Pagerduty Rundeck28/2/202217/6/2026
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to versions 3.4.5 and 3.3.15, an authenticated user with authorization to read webhooks in one project can craft a request to reveal Webhook definitions and tokens in another project. The user could use the revealed…
ModificadaAlta (8.1)1.3%—Nextcloud Deck25/10/202117/6/2026
Nextcloud is an open-source, self-hosted productivity platform. A missing permission check in Nextcloud Deck before 1.2.9, 1.4.5 and 1.5.3 allows another authenticated users to access Deck cards of another user. It is recommended that the Nextcloud Deck App is upgraded to 1.2.9, 1.4.5 or 1.5.3. There are no known…
ModificadaMedia (6.5)1.3%—Nextcloud Deck7/9/202117/6/2026
Deck is an open source kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In affected versions the Deck application didn't properly check membership of users in a Circle. This allowed other users in the instance to gain access to boards that have…
ModificadaMedia (6.8)0.45%—Pagerduty Rundeck30/8/202117/6/2026
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to version 3.3.14 and version 3.4.3, a user with `admin` access to the `system` resource type is potentially vulnerable to a CSRF attack that could cause the server to run untrusted code on all Rundeck editions.…
ModificadaAlta (8.8)1.7%—Pagerduty Rundeck30/8/202117/6/2026
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to version 3.3.14 and version 3.4.3, an authorized user can upload a zip-format plugin with a crafted plugin.yaml, or a crafted aclpolicy yaml file, or upload an untrusted project archive with a crafted aclpolicy…
ModificadaMedia (6.5)1.4%—Nextcloud Deck11/6/202117/6/2026
Nextcloud Deck before 1.2.7, 1.4.1 suffers from an information disclosure vulnerability when searches for sharees utilize the lookup server by default instead of only the local Nextcloud server unless a global search has been explicitly chosen by the user.
ModificadaMedia (4.3)1.3%—Nextcloud Deck23/2/202117/6/2026
Nextcloud Deck before 1.0.2 suffers from an insecure direct object reference (IDOR) vulnerability that permits users with a duplicate user identifier to access deck data of a previous deleted user.
ModificadaMedia (4.3)0.78%—Nextcloud Deck5/10/202017/6/2026
Missing access control in Nextcloud Deck 1.0.4 caused an insecure direct object reference allowing an attacker to view all attachments.
ModificadaAlta (8)1.0%—Nextcloud Deck5/10/202017/6/2026
Improper access control in Nextcloud Deck 0.8.0 allowed an attacker to reshare boards shared with them with more permissions than they had themselves.
ModificadaMedia (4.1)0.64%—Nextcloud Deck2/7/202017/6/2026
Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to inject tasks into other users decks.
ModificadaMedia (6.5)1.4%—Pagerduty Rundeck29/4/202017/6/2026
In Rundeck before version 3.2.6, authenticated users can craft a request that reveals Execution data and logs and Job details that they are not authorized to see. Depending on the configuration and the way that Rundeck is used, this could result in anything between a high severity risk, or a very low risk. If access…
ModificadaAlta (7.1)1.1%—Jenkins Rundeck9/3/202017/6/2026
Jenkins Rundeck Plugin 3.6.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
ModificadaMedia (4.8)0.84%—Nextcloud DeckNextcloud ServerNextcloud Talk4/2/202017/6/2026
Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project.
ModificadaMedia (6.5)0.85%—Jenkins Rundeck17/12/201917/6/2026
Jenkins Rundeck Plugin 3.6.5 and earlier stores credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
ModificadaMedia (4.3)0.64%—Jenkins Rundeck16/10/201917/6/2026
A missing permission check in Jenkins Rundeck Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
ModificadaMedia (4.3)0.66%—Jenkins Rundeck16/10/201917/6/2026
A cross-site request forgery vulnerability in Jenkins Rundeck Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials.
ModificadaCrítica (9.8)2.1%—Hbwsl Slidedeck 222/8/201917/6/2026
The slidedeck2 plugin before 2.3.5 for WordPress has file inclusion.