Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1897 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 0.42% | — | Jenkins Microsoft Entra ID PluginAI | 2/9/2026 | 3/9/2026 | Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique object ID and its display name, allowing attackers who can create an Entra group with a colliding display name to gain the permissions configured for a privileged group. | |
| Pendiente de análisis | Alta (8.8) | 0.83% | — | Jenkins File Parameter PluginAI | 2/9/2026 | 3/9/2026 | Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier allows writing files to arbitrary locations on the Jenkins controller file system through Stapler data binding, which can lead to remote code execution. | |
| Pendiente de análisis | Alta (8.8) | 0.64% | — | Jenkins PerformanceAI | 2/9/2026 | 3/9/2026 | Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performance reports stored in the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller. | |
| Pendiente de análisis | Alta (8.8) | 0.55% | — | Jenkins Allure PluginAI | 2/9/2026 | 3/9/2026 | A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier allows attackers with Item/Read permission on jobs that publish Allure report results to read arbitrary files on the Jenkins controller's file system. | |
| Pendiente de análisis | Alta (8.8) | 0.42% | — | Jenkins SamlAIStaplerAI | 2/9/2026 | 3/9/2026 | Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata file through Stapler data binding, allowing attackers to replace it with attacker-controlled content and authenticate as any user. | |
| Pendiente de análisis | Alta (7.1) | 0.38% | — | Jenkins ThinbackupAI | 2/9/2026 | 3/9/2026 | Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plugin's backup configuration through Stapler data binding, allowing attackers to redirect backup writes to an attacker-specified directory and to include arbitrary files from the Jenkins controller file system in backups. | |
| Pendiente de análisis | Media (5.4) | 0.14% | — | Jenkins JOB Configuration HistoryAI | 2/9/2026 | 4/9/2026 | Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier allows overwriting the plugin's history recording configuration through Stapler data binding, allowing attackers to redirect history storage to an attacker-specified directory and modify history recording settings. | |
| Pendiente de análisis | Alta (8) | 0.41% | — | Jenkins Sonarqube ScannerAISonarsource SonarqubeAI | 2/9/2026 | 3/9/2026 | Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard links it creates based on SonarQube scanner results, allowing the `javascript:` scheme, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Pendiente de análisis | Media (5.4) | 0.14% | — | Jenkins Gitlab PluginAI | 2/9/2026 | 3/9/2026 | Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global GitLab connection configuration through Stapler data binding, allowing attackers to connect to an attacker-specified URL using GitLab API tokens already configured by administrators. | |
| Pendiente de análisis | Media (5.4) | 0.14% | — | JenkinsAIJenkins Pipeline Groovy LibrariesAI | 2/9/2026 | 3/9/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 798.v5cc688825312 and earlier allows attackers to delete shared library caches. | |
| Pendiente de análisis | Media (4.3) | 0.25% | — | Jenkins Ldap PluginAI | 2/9/2026 | 3/9/2026 | Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allows connecting to a specified URL through Stapler data binding, allowing attackers to connect to an attacker-specified URL. | |
| Pendiente de análisis | Media (5.4) | 0.36% | — | Jenkins Pipeline Build StepAI | 2/9/2026 | 3/9/2026 | A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes downstream builds awaited by the `waitForBuild` step when the `propagateAbort` parameter is used to be canceled even when the build's authentication lacks Item/Cancel permission on the downstream job. | |
| Pendiente de análisis | Media (5.4) | 0.36% | — | Jenkins Pipeline Build StepAIJenkins PipelineAI | 2/9/2026 | 3/9/2026 | A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes downstream builds triggered by the `build` step to be canceled even when the build's authentication lacks Item/Cancel permission on the downstream job. | |
| Analizada | Media (4.2) | 0.25% | — | Jenkins | 2/9/2026 | 15/9/2026 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flag to cancel a build triggered to wait for completion, allowing attackers with Item/Build permission to cancel builds started by other users. | |
| Analizada | Media (4.3) | 0.30% | — | Jenkins | 2/9/2026 | 15/9/2026 | A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attackers with Item/Read permission on at least one job to read build parameter names and values of jobs they have no access to. | |
| Analizada | Media (4.3) | 0.31% | — | Jenkins | 2/9/2026 | 15/9/2026 | Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST API, allowing attackers able to control map property names to inject arbitrary fields into JSON and Python API responses. | |
| Pendiente de análisis | Media (5.4) | 0.25% | — | JenkinsAIStaplerAI | 2/9/2026 | 3/9/2026 | In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, form data binding allows setting public static fields of the bound configuration object, allowing attackers who can submit configuration forms to modify public static fields of… | |
| Analizada | Baja (3.5) | 0.34% | — | Jenkins | 2/9/2026 | 15/9/2026 | Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to. | |
| Analizada | Alta (7.3) | 0.44% | — | Jenkins | 2/9/2026 | 11/9/2026 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember me" cookie, allowing attackers able to serve content on the same site as Jenkins to set a known session cookie in the victim's browser, which after the victim authenticates via the… | |
| Analizada | Media (6.3) | 0.31% | — | Jenkins | 2/9/2026 | 11/9/2026 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for updating agent configuration do not prevent a submitted configuration from overwriting a different agent by specifying that agent's name in the submitted XML document, allowing attackers with Agent/Configure permission on one… | |
| Analizada | Alta (8.8) | 0.47% | — | Jenkins | 2/9/2026 | 11/9/2026 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, the impact depending on how those fields are used. | |
| Pendiente de análisis | Alta (8.8) | 0.20% | — | JenkinsAIStaplerAI | 2/9/2026 | 3/9/2026 | In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HTTP endpoint serving dynamically generated JavaScript resources embeds the user's cross-site… | |
| Analizada | Alta (8.8) | 0.58% | — | Jenkins | 2/9/2026 | 11/9/2026 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers in control of agent processes. | |
| Pendiente de análisis | Alta (8.8) | 0.52% | — | JenkinsAIStaplerAI | 2/9/2026 | 3/9/2026 | In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via form data binding to those compatible with the expected field type, allowing attackers with… | |
| Analizada | Media (4.3) | 0.34% | — | Jenkins | 2/9/2026 | 11/9/2026 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML. |