Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
143 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.1) | 0.38% | — | Goreleaser Nfpm | 30/5/2023 | 17/6/2026 | nFPM is an alternative to fpm. The file permissions on the checked-in files were not maintained. Hence, when nfpm packaged the files (without extra config for enforcing it’s own permissions) files could go out with bad permissions (chmod 666 or 777). Anyone using nfpm for creating packages without checking/setting… | |
| Modificada | Media (5.9) | 0.58% | — | Cloudfoundry Cf-deploymentCloudfoundry Routing Release | 26/5/2023 | 17/6/2026 | In Cloud foundry routing release versions from 0.262.0 and prior to 0.266.0,a bug in the gorouter process can lead to a denial of service of applications hosted on Cloud Foundry. Under the right circumstances, when client connections are closed prematurely, gorouter marks the currently selected backend as failed and… | |
| Modificada | Alta (8.1) | 0.36% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deploymentCloudfoundry Loggregator-agent | 19/5/2023 | 17/6/2026 | Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override other users syslog drain credentials if they're aware of the client certificate used for that syslog drain. This applies even if the drain has zero certs. This would allow the user to override the… | |
| Modificada | Media (6.5) | 0.69% | — | Jenkins Xebialabs XL Release | 30/6/2022 | 17/6/2026 | Missing permission checks in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Media (6.5) | 0.49% | — | Jenkins Xebialabs XL Release | 30/6/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Media (4.3) | 0.56% | — | Jenkins Xebialabs XL Release | 30/6/2022 | 17/6/2026 | A missing permission check in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Modificada | Alta (7.5) | 1.7% | — | Semantic-release Project Semantic-release | 9/6/2022 | 17/6/2026 | semantic-release is an open source npm package for automated version management and package publishing. In affected versions secrets that would normally be masked by semantic-release can be accidentally disclosed if they contain characters that are excluded from uri encoding by `encodeURI`. Occurrence is further… | |
| Modificada | Media (5.3) | 0.92% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deployment | 25/3/2022 | 17/6/2026 | In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker that (accidentally or maliciously) causes CC instances to timeout and fail is possible. An attacker can leverage this vulnerability to cause an inability for anyone to push or manage apps. | |
| Modificada | Media (4.3) | 0.74% | — | Jenkins Release Helper | 15/3/2022 | 17/6/2026 | A missing permission check in Jenkins Release Helper Plugin 1.3.3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials. | |
| Modificada | Media (4.3) | 0.49% | — | Jenkins Release Helper | 15/3/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Release Helper Plugin 1.3.3 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials. | |
| Modificada | Alta (7.5) | 1.0% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deployment | 27/10/2021 | 17/6/2026 | Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerability allowing unauthenticated attackers to cause denial of service by using REST HTTP requests with label_selectors on multiple V3 endpoints by generating an enormous SQL query. | |
| Modificada | Alta (8.6) | 1.3% | — | Emby.releases | 9/9/2021 | 17/6/2026 | Emby Server is a personal media server with apps on many devices. In Emby Server on Windows there is a set of arbitrary file read vulnerabilities. This vulnerability is known to exist in version 4.6.4.0 and may not be patched in later versions. Known vulnerable routes are… | |
| Modificada | Media (6.5) | 0.84% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deployment | 8/4/2021 | 17/6/2026 | Cloud Controller API versions prior to 1.106.0 logs service broker credentials if the default value of db logging config field is changed. CAPI database logs service broker password in plain text whenever a job to clean up orphaned items is run by Cloud Controller. | |
| Modificada | Alta (7.5) | 1.1% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deployment | 2/12/2020 | 17/6/2026 | CAPI (Cloud Controller) versions prior to 1.101.0 are vulnerable to a denial-of-service attack in which an unauthenticated malicious attacker can send specially-crafted YAML files to certain endpoints, causing the YAML parser to consume excessive CPU and RAM. | |
| Modificada | Alta (8.1) | 1.4% | — | Semantic-release Project Semantic-release | 18/11/2020 | 17/6/2026 | In the npm package semantic-release before version 17.2.3, secrets that would normally be masked by `semantic-release` can be accidentally disclosed if they contain characters that become encoded when included in a URL. Secrets that do not contain characters that become encoded when included in a URL are already… | |
| Modificada | Media (6.5) | 0.54% | — | Barchart Maven Cascade Release | 8/10/2020 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Maven Cascade Release Plugin 1.3.2 and earlier allows attackers to start cascade builds and layout builds, and reconfigure the plugin. | |
| Modificada | Media (6.5) | 0.81% | — | Barchart Maven Cascade Release | 8/10/2020 | 17/6/2026 | Jenkins Maven Cascade Release Plugin 1.3.2 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to start cascade builds and layout builds, and reconfigure the plugin. | |
| Modificada | Media (5.4) | 0.73% | — | Jenkins Release | 8/10/2020 | 17/6/2026 | Jenkins Release Plugin 2.10.2 and earlier does not escape the release version in badge tooltip, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Release/Release permission. | |
| Modificada | Media (5.4) | 0.72% | — | Jenkins Clearcase Release | 16/9/2020 | 17/6/2026 | Jenkins ClearCase Release Plugin 0.3 and earlier does not escape the composite baseline in badge tooltip, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission. | |
| Modificada | Media (4.3) | 0.57% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deployment | 3/9/2020 | 17/6/2026 | Cloud Foundry CAPI (Cloud Controller) versions prior to 1.98.0 allow authenticated users having only the "cloud_controller.read" scope, but no roles in any spaces, to list all droplets in all spaces (whereas they should see none). | |
| Modificada | Alta (8.8) | 0.99% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deployment | 21/8/2020 | 17/6/2026 | Cloud Foundry CAPI (Cloud Controller), versions prior to 1.97.0, when used in a deployment where an app domain is also the system domain (which is true in the default CF Deployment manifest), were vulnerable to developers maliciously or accidentally claiming certain sensitive routes, potentially resulting in the… | |
| Modificada | Media (6.5) | 1.2% | — | Cloudfoundry Cf-deploymentCloudfoundry Routing-release | 21/8/2020 | 17/6/2026 | Cloud Foundry Routing (Gorouter), versions prior to 0.204.0, when used in a deployment with NGINX reverse proxies in front of the Gorouters, is potentially vulnerable to denial-of-service attacks in which an unauthenticated malicious attacker can send specially-crafted HTTP requests that may cause the Gorouters to be… | |
| Modificada | Media (5.9) | 2.9% | — | Golang GOCloudfoundry Cf-deploymentCloudfoundry Routing-releaseDebian Linux+2 | 17/7/2020 | 17/6/2026 | Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net/http servers, as demonstrated by the httputil.ReverseProxy Handler, because it reads a request body and writes a response at the same time. | |
| Modificada | Media (6.1) | 6.2% | — | Jenkins Subversion Partial Release Manager | 3/6/2020 | 17/6/2026 | Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier does not escape the error message for the repository URL field form validation, resulting in a reflected cross-site scripting vulnerability. | |
| Modificada | Media (6.1) | 1.3% | — | Jenkins Subversion Release Manager | 9/3/2020 | 17/6/2026 | Jenkins Subversion Release Manager Plugin 1.2 and earlier does not escape the error message for the Repository URL field form validation, resulting in a reflected cross-site scripting vulnerability. |