Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.74% | — | Jenkins Rocketchat Notifier | 29/3/2022 | 17/6/2026 | A missing permission check in Jenkins RocketChat Notifier Plugin 1.4.10 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials. | |
| Modificada | Media (4.3) | 0.61% | — | Jenkins Rocketchat Notifier | 29/3/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins RocketChat Notifier Plugin 1.4.10 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credential. | |
| Modificada | Media (6.5) | 0.81% | — | Jenkins Jabber (xmpp) Notifier AND Control | 30/3/2021 | 17/6/2026 | Jenkins Jabber (XMPP) notifier and control Plugin 1.41 and earlier stores passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Media (5.6) | 1.6% | — | Node-notifier Project Node-notifier | 11/12/2020 | 17/6/2026 | This affects the package node-notifier before 9.0.0. It allows an attacker to run arbitrary commands on Linux machines due to the options params not being sanitised when being passed an array. | |
| Modificada | Media (5.3) | 2.2% | — | Siemens Opcenter Execution DiscreteSiemens Opcenter Execution FoundationSiemens Opcenter Execution ProcessSiemens Opcenter Intelligence+9 | 14/7/2020 | 17/6/2026 | A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcenter Intelligence (All versions < V3.3), Opcenter Quality (All versions < V11.3), Opcenter RD&L (V8.0), SIMATIC IT LMS… | |
| Modificada | Alta (8.2) | 2.5% | — | Siemens Opcenter Execution DiscreteSiemens Opcenter Execution FoundationSiemens Opcenter Execution ProcessSiemens Opcenter Intelligence+9 | 14/7/2020 | 17/6/2026 | A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcenter Intelligence (All versions < V3.3), Opcenter Quality (All versions < V11.3), Opcenter RD&L (V8.0), SIMATIC IT LMS… | |
| Modificada | Media (6.7) | 0.38% | — | Siemens Opcenter Execution DiscreteSiemens Opcenter Execution FoundationSiemens Opcenter Execution ProcessSiemens Opcenter Intelligence+7 | 14/7/2020 | 17/6/2026 | A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcenter Intelligence (All versions < V3.3), Opcenter Quality (All versions < V11.3), Opcenter RD&L (V8.0), SIMATIC Notifier… | |
| Modificada | Crítica (9.8) | 1.9% | — | Honeywell Notifier Webserver | 7/4/2020 | 17/6/2026 | Honeywell Notifier Web Server (NWS) Version 3.50 is vulnerable to a path traversal attack, which allows an attacker to bypass access to restricted directories. Honeywell has released a firmware update to address the problem. | |
| Modificada | Crítica (9.1) | 1.3% | — | Honeywell Notifier Webserver | 24/3/2020 | 17/6/2026 | In Notifier Web Server (NWS) Version 3.50 and earlier, the Honeywell Fire Web Server’s authentication may be bypassed by a capture-replay attack from a web browser. | |
| Modificada | Media (4.3) | 0.81% | — | Jenkins Azure Event Grid Notifier | 25/9/2019 | 17/6/2026 | Jenkins Azure Event Grid Build Notifier Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system. | |
| Modificada | Media (6.1) | 0.91% | — | Event Notifier Project Event Notifier | 22/8/2019 | 17/6/2026 | The event-notifier plugin before 1.2.1 for WordPress has XSS via the loading animation. | |
| Modificada | Alta (8.8) | 1.3% | — | Jenkins Amazon SNS Build Notifier | 4/4/2019 | 17/6/2026 | Jenkins Amazon SNS Build Notifier Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. |