Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
1897 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.2) | 0.57% | — | Jenkins Visual Studio Code Metrics | 2/4/2023 | 17/6/2026 | Jenkins Visual Studio Code Metrics Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Modificada | Alta (7.5) | 0.77% | — | Jenkins Crap4j | 2/4/2023 | 17/6/2026 | Jenkins Crap4J Plugin 0.9 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Modificada | Media (5.4) | 0.57% | — | Jenkins Mashup Portlets | 2/4/2023 | 17/6/2026 | Jenkins Mashup Portlets Plugin 1.1.2 and earlier provides the "Generic JS Portlet" feature that lets a user populate a portlet using a custom JavaScript expression, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by authenticated attackers with Overall/Read permission. | |
| Modificada | Media (5.4) | 0.46% | — | Jenkins Cppcheck | 2/4/2023 | 17/6/2026 | Jenkins Cppcheck Plugin 1.26 and earlier does not escape file names from Cppcheck report files before showing them on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control report file contents. | |
| Modificada | Crítica (9.8) | 0.78% | — | Jenkins Convert TO Pipeline | 2/4/2023 | 17/6/2026 | Jenkins Convert To Pipeline Plugin 1.0 and earlier uses basic string concatenation to convert Freestyle projects' Build Environment, Build Steps, and Post-build Actions to the equivalent Pipeline step invocations, allowing attackers able to configure Freestyle projects to prepare a crafted configuration that injects… | |
| Modificada | Alta (8.8) | 0.64% | — | Jenkins Convert TO Pipeline | 2/4/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Convert To Pipeline Plugin 1.0 and earlier allows attackers to create a Pipeline based on a Freestyle project, potentially leading to remote code execution (RCE). | |
| Modificada | Media (4.3) | 0.43% | — | Jenkins Octoperf Load Testing | 2/4/2023 | 17/6/2026 | A missing permission check in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.2 and earlier allows attackers to connect to a previously configured Octoperf server using attacker-specified credentials. | |
| Modificada | Alta (8.8) | 0.36% | — | Jenkins Octoperf Load Testing | 2/4/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.2 and earlier allows attackers to connect to a previously configured Octoperf server using attacker-specified credentials. | |
| Modificada | Media (4.3) | 0.41% | — | Jenkins Octoperf Load Testing | 2/4/2023 | 17/6/2026 | A missing permission check in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Modificada | Media (6.5) | 0.51% | — | Jenkins Octoperf Load Testing | 2/4/2023 | 17/6/2026 | Jenkins OctoPerf Load Testing Plugin Plugin 4.5.1 and earlier does not perform a permission check in a connection test HTTP endpoint, allowing attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials… | |
| Modificada | Media (4.3) | 0.36% | — | Jenkins Octoperf Load Testing | 2/4/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Media (5.4) | 0.46% | — | Jenkins Pipeline Aggregator View | 2/4/2023 | 17/6/2026 | Jenkins Pipeline Aggregator View Plugin 1.13 and earlier does not escape a variable representing the current view's URL in inline JavaScript, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by authenticated attackers with Overall/Read permission. | |
| Modificada | Media (5.4) | 0.56% | — | Jenkins Jacoco | 2/4/2023 | 17/6/2026 | Jenkins JaCoCo Plugin 3.3.2 and earlier does not escape class and method names shown on the UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control input files for the 'Record JaCoCo coverage report' post-build action. | |
| Modificada | Crítica (9.8) | 0.83% | — | Jenkins Role-based Authorization Strategy | 2/4/2023 | 17/6/2026 | Jenkins Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they've been disabled. | |
| Modificada | Alta (7.1) | 0.60% | — | Jenkins Absint A3 | 22/3/2023 | 17/6/2026 | Jenkins AbsInt a³ Plugin 1.1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Modificada | Crítica (9.6) | 1.5% | — | Jenkins Update-center2 | 10/3/2023 | 17/6/2026 | Jenkins update-center2 3.13 and 3.14 renders the required Jenkins core version on plugin download index pages without sanitization, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting. | |
| Modificada | Media (5.3) | 0.72% | — | Jenkins | 10/3/2023 | 17/6/2026 | Jenkins 2.393 and earlier, LTS 2.375.3 and earlier prints an error stack trace on agent-related pages when agent connections are broken, potentially revealing information about Jenkins configuration that is otherwise inaccessible to attackers. | |
| Modificada | Media (4.4) | 0.24% | — | Jenkins | 10/3/2023 | 17/6/2026 | Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly created files when uploading a file parameter through the CLI, potentially allowing attackers with access to the Jenkins controller file system to read and write the… | |
| Modificada | Media (4.3) | 0.74% | — | Jenkins | 10/3/2023 | 17/6/2026 | Jenkins 2.393 and earlier, LTS 2.375.3 and earlier shows temporary directories related to job workspaces, which allows attackers with Item/Workspace permission to access their contents. | |
| Modificada | Alta (7.5) | 0.98% | — | Jenkins | 10/3/2023 | 17/6/2026 | Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request parts introduced in version 1.5 for CVE-2023-24998 in org.kohsuke.stapler.RequestImpl, allowing attackers to trigger a denial of service. | |
| Modificada | Alta (7.5) | 0.98% | — | Jenkins | 10/3/2023 | 17/6/2026 | Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request parts introduced in version 1.5 for CVE-2023-24998 in hudson.util.MultipartFormDataParser, allowing attackers to trigger a denial of service. | |
| Modificada | Alta (7) | 0.23% | — | Jenkins | 10/3/2023 | 17/6/2026 | Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly created files when uploading a plugin for installation, potentially allowing attackers with access to the Jenkins controller file system to read and write the file… | |
| Modificada | Crítica (9.6) | 1.8% | — | Jenkins | 10/3/2023 | 17/6/2026 | Jenkins 2.270 through 2.393 (both inclusive), LTS 2.277.1 through 2.375.3 (both inclusive) does not escape the Jenkins version a plugin depends on when rendering the error message stating its incompatibility with the current version of Jenkins, resulting in a stored cross-site scripting (XSS) vulnerability exploitable… | |
| Modificada | Media (4.3) | 0.51% | — | Jenkins Synopsys Coverity | 15/2/2023 | 17/6/2026 | A missing permission check in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Modificada | Media (4.3) | 0.52% | — | Jenkins Synopsys Coverity | 15/2/2023 | 17/6/2026 | Missing permission checks in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. |