Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
47 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.33% | — | Jenkins AWS Codecommit Trigger | 6/9/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier allows attackers to clear the SQS queue. | |
| Modificada | Media (4.3) | 0.45% | — | Jenkins AWS Codecommit Trigger | 6/9/2023 | 17/6/2026 | A missing permission check in Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of AWS credentials stored in Jenkins. | |
| Modificada | Media (6.5) | 0.63% | — | Jenkins AWS Codecommit Trigger | 14/6/2023 | 17/6/2026 | Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not restrict the AWS SQS queue name path parameter in an HTTP endpoint, allowing attackers with Item/Read permission to obtain the contents of arbitrary files on the Jenkins controller file system. | |
| Modificada | Media (5.4) | 0.48% | — | Jenkins Quay.io Trigger | 12/4/2023 | 17/6/2026 | Jenkins Quay.io trigger Plugin 0.1 and earlier does not limit URL schemes for repository homepage URLs submitted via Quay.io trigger webhooks, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to submit crafted Quay.io trigger webhook payloads. | |
| Modificada | Media (5.3) | 0.46% | — | Jenkins Quay.io Trigger | 12/4/2023 | 17/6/2026 | A missing permission check in Jenkins Quay.io trigger Plugin 0.1 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository. | |
| Modificada | Media (6.5) | 0.49% | — | Jenkins Gerrit Trigger | 26/1/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Gerrit Trigger Plugin 2.38.0 and earlier allows attackers to rebuild previous builds triggered by Gerrit. | |
| Modificada | Media (5.3) | 0.55% | — | Jenkins Generic Webhook Trigger | 19/10/2022 | 17/6/2026 | Jenkins Generic Webhook Trigger Plugin 1.84.1 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token. | |
| Modificada | Media (4.3) | 0.68% | — | Jenkins Files Found Trigger | 27/7/2022 | 17/6/2026 | Jenkins Files Found Trigger Plugin 1.5 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system. | |
| Modificada | Media (5.4) | 0.83% | — | Jenkins Gerrit Trigger | 12/4/2022 | 17/6/2026 | Jenkins Gerrit Trigger Plugin 2.35.2 and earlier does not escape the name and description of Base64 Encoded String parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Media (5.5) | 0.38% | — | Jenkins Parameterized Trigger | 15/3/2022 | 17/6/2026 | Jenkins Parameterized Trigger Plugin 2.43 and earlier captures environment variables passed to builds triggered using Jenkins Parameterized Trigger Plugin, including password parameter values, in their `build.xml` files. These values are stored unencrypted and can be viewed by users with access to the Jenkins… | |
| Modificada | Media (5.4) | 0.66% | — | Jenkins Generic Webhook Trigger | 15/2/2022 | 17/6/2026 | Jenkins Generic Webhook Trigger Plugin 1.81 and earlier does not escape the build cause when using the webhook, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Crítica (9.8) | 26% | — | Jenkins Generic Webhook Trigger | 18/6/2021 | 17/6/2026 | Jenkins Generic Webhook Trigger Plugin 1.72 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Modificada | Alta (8.1) | 67% | — | Jenkins Urltrigger | 25/5/2021 | 17/6/2026 | Jenkins URLTrigger Plugin 0.48 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Modificada | Alta (8.8) | 1.6% | — | Jenkins Filesystem Trigger | 25/5/2021 | 17/6/2026 | Jenkins Filesystem Trigger Plugin 0.40 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Modificada | Media (4.3) | 0.52% | — | Jenkins Parameterized Remote Trigger | 1/9/2020 | 17/6/2026 | Jenkins Parameterized Remote Trigger Plugin 3.1.3 and earlier stores a secret unencrypted in its global configuration file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system. | |
| Modificada | Media (5.4) | 0.62% | — | Jenkins Gerrit Trigger | 17/12/2019 | 17/6/2026 | A missing permission check in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP URL or SSH server using attacker-specified credentials, or determine the existence of a file with a given path on the Jenkins master. | |
| Modificada | Alta (8.8) | 0.69% | — | Jenkins Gerrit Trigger | 17/12/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers to connect to an attacker-specified HTTP URL or SSH server using attacker-specified credentials. | |
| Modificada | Media (6.5) | 0.70% | — | Jenkins Urltrigger | 26/6/2018 | 17/6/2026 | A server-side request forgery vulnerability exists in Jenkins URLTrigger Plugin 0.41 and earlier in URLTrigger.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL. | |
| Modificada | Media (5.4) | 0.89% | — | Jenkins Gerrit Trigger | 13/3/2018 | 17/6/2026 | An improper authorization vulnerability exists in Jenkins Gerrit Trigger Plugin 2.27.4 and earlier in GerritManagement.java, GerritServer.java, and PluginImpl.java that allows an attacker with Overall/Read access to modify the Gerrit configuration in Jenkins. | |
| Modificada | Media (4.3) | 0.66% | — | Jenkins Gerrit Trigger | 13/3/2018 | 17/6/2026 | An improper authorization vulnerability exists in Jenkins Gerrit Trigger Plugin 2.27.4 and earlier in GerritManagement.java, GerritServer.java, and PluginImpl.java that allows an attacker with Overall/Read access to retrieve some configuration information about Gerrit in Jenkins. | |
| Modificada | Media (6.5) | 0.78% | — | Jenkins Parameterized Trigger | 5/10/2017 | 17/6/2026 | Parameterized Trigger Plugin fails to check Item/Build permission: The Parameterized Trigger Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins. | |
| Modificada | Media (5) | 1.2% | — | Triggertg Tclanportal | 31/12/2005 | 16/6/2026 | SQL injection vulnerability in index.php in TClanPortal 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands, and retrieve all usernames and passwords, via the id parameter. |