Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

143 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)0.38%—Goreleaser Nfpm30/5/202317/6/2026
nFPM is an alternative to fpm. The file permissions on the checked-in files were not maintained. Hence, when nfpm packaged the files (without extra config for enforcing it’s own permissions) files could go out with bad permissions (chmod 666 or 777). Anyone using nfpm for creating packages without checking/setting…
ModificadaMedia (5.9)0.58%—Cloudfoundry Cf-deploymentCloudfoundry Routing Release26/5/202317/6/2026
In Cloud foundry routing release versions from 0.262.0 and prior to 0.266.0,a bug in the gorouter process can lead to a denial of service of applications hosted on Cloud Foundry. Under the right circumstances, when client connections are closed prematurely, gorouter marks the currently selected backend as failed and…
ModificadaAlta (8.1)0.36%—Cloudfoundry Capi-releaseCloudfoundry Cf-deploymentCloudfoundry Loggregator-agent19/5/202317/6/2026
Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override other users syslog drain credentials if they're aware of the client certificate used for that syslog drain. This applies even if the drain has zero certs. This would allow the user to override the…
ModificadaMedia (6.5)0.69%—Jenkins Xebialabs XL Release30/6/202217/6/2026
Missing permission checks in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
ModificadaMedia (6.5)0.49%—Jenkins Xebialabs XL Release30/6/202217/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
ModificadaMedia (4.3)0.56%—Jenkins Xebialabs XL Release30/6/202217/6/2026
A missing permission check in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
ModificadaAlta (7.5)1.7%—Semantic-release Project Semantic-release9/6/202217/6/2026
semantic-release is an open source npm package for automated version management and package publishing. In affected versions secrets that would normally be masked by semantic-release can be accidentally disclosed if they contain characters that are excluded from uri encoding by `encodeURI`. Occurrence is further…
ModificadaMedia (5.3)0.92%—Cloudfoundry Capi-releaseCloudfoundry Cf-deployment25/3/202217/6/2026
In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker that (accidentally or maliciously) causes CC instances to timeout and fail is possible. An attacker can leverage this vulnerability to cause an inability for anyone to push or manage apps.
ModificadaMedia (4.3)0.74%—Jenkins Release Helper15/3/202217/6/2026
A missing permission check in Jenkins Release Helper Plugin 1.3.3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
ModificadaMedia (4.3)0.49%—Jenkins Release Helper15/3/202217/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Release Helper Plugin 1.3.3 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.
ModificadaAlta (7.5)1.0%—Cloudfoundry Capi-releaseCloudfoundry Cf-deployment27/10/202117/6/2026
Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerability allowing unauthenticated attackers to cause denial of service by using REST HTTP requests with label_selectors on multiple V3 endpoints by generating an enormous SQL query.
ModificadaAlta (8.6)1.3%—Emby.releases9/9/202117/6/2026
Emby Server is a personal media server with apps on many devices. In Emby Server on Windows there is a set of arbitrary file read vulnerabilities. This vulnerability is known to exist in version 4.6.4.0 and may not be patched in later versions. Known vulnerable routes are…
ModificadaMedia (6.5)0.84%—Cloudfoundry Capi-releaseCloudfoundry Cf-deployment8/4/202117/6/2026
Cloud Controller API versions prior to 1.106.0 logs service broker credentials if the default value of db logging config field is changed. CAPI database logs service broker password in plain text whenever a job to clean up orphaned items is run by Cloud Controller.
ModificadaAlta (7.5)1.1%—Cloudfoundry Capi-releaseCloudfoundry Cf-deployment2/12/202017/6/2026
CAPI (Cloud Controller) versions prior to 1.101.0 are vulnerable to a denial-of-service attack in which an unauthenticated malicious attacker can send specially-crafted YAML files to certain endpoints, causing the YAML parser to consume excessive CPU and RAM.
ModificadaAlta (8.1)1.4%—Semantic-release Project Semantic-release18/11/202017/6/2026
In the npm package semantic-release before version 17.2.3, secrets that would normally be masked by `semantic-release` can be accidentally disclosed if they contain characters that become encoded when included in a URL. Secrets that do not contain characters that become encoded when included in a URL are already…
ModificadaMedia (6.5)0.54%—Barchart Maven Cascade Release8/10/202017/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Maven Cascade Release Plugin 1.3.2 and earlier allows attackers to start cascade builds and layout builds, and reconfigure the plugin.
ModificadaMedia (6.5)0.81%—Barchart Maven Cascade Release8/10/202017/6/2026
Jenkins Maven Cascade Release Plugin 1.3.2 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to start cascade builds and layout builds, and reconfigure the plugin.
ModificadaMedia (5.4)0.73%—Jenkins Release8/10/202017/6/2026
Jenkins Release Plugin 2.10.2 and earlier does not escape the release version in badge tooltip, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Release/Release permission.
ModificadaMedia (5.4)0.72%—Jenkins Clearcase Release16/9/202017/6/2026
Jenkins ClearCase Release Plugin 0.3 and earlier does not escape the composite baseline in badge tooltip, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
ModificadaMedia (4.3)0.57%—Cloudfoundry Capi-releaseCloudfoundry Cf-deployment3/9/202017/6/2026
Cloud Foundry CAPI (Cloud Controller) versions prior to 1.98.0 allow authenticated users having only the "cloud_controller.read" scope, but no roles in any spaces, to list all droplets in all spaces (whereas they should see none).
ModificadaAlta (8.8)0.99%—Cloudfoundry Capi-releaseCloudfoundry Cf-deployment21/8/202017/6/2026
Cloud Foundry CAPI (Cloud Controller), versions prior to 1.97.0, when used in a deployment where an app domain is also the system domain (which is true in the default CF Deployment manifest), were vulnerable to developers maliciously or accidentally claiming certain sensitive routes, potentially resulting in the…
ModificadaMedia (6.5)1.2%—Cloudfoundry Cf-deploymentCloudfoundry Routing-release21/8/202017/6/2026
Cloud Foundry Routing (Gorouter), versions prior to 0.204.0, when used in a deployment with NGINX reverse proxies in front of the Gorouters, is potentially vulnerable to denial-of-service attacks in which an unauthenticated malicious attacker can send specially-crafted HTTP requests that may cause the Gorouters to be…
ModificadaMedia (5.9)2.9%—Golang GOCloudfoundry Cf-deploymentCloudfoundry Routing-releaseDebian Linux+217/7/202017/6/2026
Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net/http servers, as demonstrated by the httputil.ReverseProxy Handler, because it reads a request body and writes a response at the same time.
ModificadaMedia (6.1)6.2%—Jenkins Subversion Partial Release Manager3/6/202017/6/2026
Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier does not escape the error message for the repository URL field form validation, resulting in a reflected cross-site scripting vulnerability.
ModificadaMedia (6.1)1.3%—Jenkins Subversion Release Manager9/3/202017/6/2026
Jenkins Subversion Release Manager Plugin 1.2 and earlier does not escape the error message for the Repository URL field form validation, resulting in a reflected cross-site scripting vulnerability.