Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
128 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.23% | — | Octopus Server | 25/7/2024 | 17/6/2026 | In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the task log in clear-text. | |
| Analizada | Baja (2.2) | 0.24% | — | Octopus Server | 25/7/2024 | 17/6/2026 | In affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restricted project artifacts. | |
| Analizada | Media (5.4) | 0.26% | — | Octopus Server | 8/5/2024 | 17/6/2026 | In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting payload on the audit page. | |
| Analizada | Baja (3.5) | 0.30% | — | Octopus Server | 30/4/2024 | 17/6/2026 | It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all users, user roles and permissions. This functionality was removed in versions of Octopus Server after the fixed versions listed. | |
| Analizada | Media (4.3) | 0.23% | — | Octopus Server | 18/4/2024 | 17/6/2026 | It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt. | |
| Analizada | Alta (7.5) | 0.39% | — | Octopus Server | 9/4/2024 | 17/6/2026 | A race condition was identified through which privilege escalation was possible in certain configurations. | |
| Modificada | Media (5.4) | 0.56% | — | Hongmaple Octopus | 25/1/2024 | 17/6/2026 | A vulnerability was found in hongmaple octopus 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument description with the input <script>alert(document.cookie)</script> leads to cross site scripting. The attack can be launched remotely.… | |
| Modificada | Crítica (9.8) | 0.66% | — | Hongmaple Octopus | 25/1/2024 | 17/6/2026 | A vulnerability was found in hongmaple octopus 1.0. It has been classified as critical. Affected is an unknown function of the file /system/dept/edit. The manipulation of the argument ancestors leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Crítica (9.8) | 0.68% | — | Hongmaple Octopus | 22/1/2024 | 17/6/2026 | A vulnerability was found in hongmaple octopus 1.0. It has been classified as critical. Affected is an unknown function of the file /system/role/list. The manipulation of the argument dataScope leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Alta (7.5) | 0.39% | — | Octopus Server | 14/12/2023 | 17/6/2026 | In affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the configuration of Octopus Server. | |
| Modificada | Media (4.3) | 0.30% | — | Octopus Server | 2/8/2023 | 17/6/2026 | In affected versions of Octopus Deploy it is possible for a low privileged guest user to craft a request that allows enumeration/recon of an environment. | |
| Modificada | Media (4.3) | 0.34% | — | Octopus Server | 2/8/2023 | 17/6/2026 | In affected versions of Octopus Deploy it is possible for a low privileged guest user to interact with extension endpoints. | |
| Modificada | Media (5.3) | 0.45% | — | Octopus Server | 18/5/2023 | 17/6/2026 | In affected versions of Octopus Deploy it is possible to discover network details via error message | |
| Modificada | Media (5.5) | 0.18% | — | Octopus Server | 10/5/2023 | 17/6/2026 | In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service | |
| Modificada | Media (5.3) | 0.45% | — | Octopus Deploy | 2/5/2023 | 17/6/2026 | In affected versions of Octopus Deploy it is possible to unmask variable secrets using the variable preview function | |
| Modificada | Media (5.3) | 0.42% | — | Octopus Server | 19/4/2023 | 17/6/2026 | In affected versions of Octopus Deploy it is possible to render user supplied input into the webpage | |
| Modificada | Alta (8.8) | 0.72% | — | Octopus Server | 16/3/2023 | 17/6/2026 | In affected versions of Octopus Deploy it is possible for a user to introduce code via offline package creation | |
| Modificada | Media (4.3) | 0.44% | — | Octopus Server | 13/3/2023 | 17/6/2026 | In affected versions of Octopus Deploy it is possible for a user to view Workerpools without being explicitly assigned permissions to view these items | |
| Modificada | Media (4.3) | 0.50% | — | Octopus Server | 13/3/2023 | 17/6/2026 | In affected versions of Octopus Deploy it is possible for a user to view Tagsets without being explicitly assigned permissions to view these items | |
| Modificada | Alta (7.5) | 1.0% | — | Octopus Server | 22/2/2023 | 17/6/2026 | In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service | |
| Modificada | Media (5.4) | 0.39% | — | Octopus Server | 31/1/2023 | 17/6/2026 | In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link. This was initially resolved in advisory 2022-07 however it was identified that the fix could be bypassed in certain circumstances. A different approach was taken to prevent the… | |
| Modificada | Media (6.1) | 0.39% | — | Octopus Server | 3/1/2023 | 17/6/2026 | In affected versions of Octopus Deploy users of certain browsers using AD to sign-in to Octopus Server were able to bypass authentication checks and be redirected to the configured redirect url without any validation. | |
| Modificada | Alta (7.5) | 0.56% | — | Octopus Server | 3/1/2023 | 17/6/2026 | In affected versions of Octopus Deploy it is possible for certain types of sensitive variables to inadvertently become unmasked when viewed in variable preview. | |
| Modificada | Alta (7.5) | 0.60% | — | Octopus Server | 25/11/2022 | 17/6/2026 | In affected versions of Octopus Server it is possible for target discovery to print certain values marked as sensitive to log files in plaint-text in when verbose logging is enabled. | |
| Modificada | Crítica (9.8) | 0.89% | — | Octopus Server | 1/11/2022 | 17/6/2026 | In affected versions of Octopus Server where access is managed by an external authentication provider, it was possible that the API key/keys of a disabled/deleted user were still valid after the access was revoked. |