Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
1897 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.79% | 💥 PoC | Jenkins | 2/9/2026 | 11/9/2026 | In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such as the global configuration and jobs) can appear as nested field values in user-submitted `config.xml` documents and subsequently handle HTTP… | |
| Analizada | Media (4.3) | 0.28% | — | Jenkins Script Security | 2/9/2026 | 22/9/2026 | Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enforce a permission check in the method that controls the "Force the use of the sandbox globally in the system" setting, allowing attackers to disable it through Stapler data binding. | |
| Analizada | Media (4.3) | 0.31% | — | Jenkins Script Security | 2/9/2026 | 22/9/2026 | Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@DataBoundConstructor` annotation on a constructor that loads script approval configuration, allowing attackers able to submit certain forms to read that configuration. | |
| Pendiente de análisis | Alta (7.1) | 0.32% | — | Jenkins IVY ReportAI | 5/8/2026 | 31/8/2026 | Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when processing Ivy report files. | |
| Pendiente de análisis | Media (4.3) | 0.27% | — | Jenkins AWS Codebuild PluginAI | 5/8/2026 | 31/8/2026 | Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Pendiente de análisis | Media (4.3) | 0.27% | — | Jenkins Codesonar PluginAI | 5/8/2026 | 31/8/2026 | Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Pendiente de análisis | Media (4.3) | 0.27% | — | Jenkins Sauce OndemandAIJenkinsAI | 5/8/2026 | 31/8/2026 | Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Pendiente de análisis | Media (4.3) | 0.29% | — | Jenkins Violation Comments TO Gitlab PluginAI | 5/8/2026 | 31/8/2026 | A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Pendiente de análisis | Media (4.3) | 0.27% | — | Jenkins HorreumAI | 5/8/2026 | 31/8/2026 | Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to have Jenkins send credentials they are not entitled to use to the administrator-configured Horreum URL. | |
| Pendiente de análisis | Media (4.3) | 0.27% | — | Jenkins Google Chat NotificationAI | 5/8/2026 | 31/8/2026 | Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to use. | |
| Pendiente de análisis | Media (5.4) | 0.23% | — | Jenkins Summary Display PluginAI | 5/8/2026 | 31/8/2026 | Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Create or Item/Configure permission. | |
| Pendiente de análisis | Media (5.4) | 0.23% | — | Jenkins Qualys Container Scanning ConnectorAI | 5/8/2026 | 31/8/2026 | Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-controlled field values in a JavaScript context, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Pendiente de análisis | Media (6.5) | 0.27% | — | Jenkins XML JOB TO JOB DSLAIJenkinsAI | 5/8/2026 | 31/8/2026 | Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers lacking appropriate permissions to invoke the conversion functionality. | |
| Pendiente de análisis | Media (4.3) | 0.27% | — | Jenkins Parameterized Remote TriggerAI | 5/8/2026 | 31/8/2026 | A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Pendiente de análisis | Baja (3.7) | 0.27% | — | Jenkins Webhook Secret Credentials Provider PluginAI | 5/8/2026 | 31/8/2026 | Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison function when checking whether the provided and expected webhook bearer token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook bearer token. | |
| Pendiente de análisis | Media (4.3) | 0.29% | — | Jenkins External Workspace Manager PluginAI | 5/8/2026 | 31/8/2026 | Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or performs an improper permission check (1.4.1) when providing access to externally-managed workspaces through the workspace browser, allowing attackers with Overall/Read permission to read files in… | |
| Pendiente de análisis | Media (4.2) | 0.19% | — | Jenkins Scm-manager PluginAI | 5/8/2026 | 31/8/2026 | A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Pendiente de análisis | Media (4.2) | 0.11% | — | Jenkins Scm-manager PluginAI | 5/8/2026 | 31/8/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Pendiente de análisis | Media (4.3) | 0.27% | — | Jenkins HCL Appscan PluginAI | 5/8/2026 | 31/8/2026 | Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Pendiente de análisis | Alta (8.8) | 0.30% | — | Jenkins Multijob PluginAI | 5/8/2026 | 31/8/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute arbitrary code in the context of the Jenkins controller JVM. | |
| Pendiente de análisis | Alta (8.8) | 0.64% | — | Jenkins Multijob PluginAIJenkins Script Security PluginAI | 5/8/2026 | 31/8/2026 | Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugin, allowing attackers with Item/Create or Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM. | |
| Analizada | Baja (2.7) | 0.31% | — | Jenkins | 5/8/2026 | 8/9/2026 | Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration… | |
| Analizada | Media (6.5) | 0.42% | — | Jenkins | 5/8/2026 | 8/9/2026 | Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters to impersonate other users or be granted their permissions in some circumstances. | |
| Analizada | Media (4.3) | 0.43% | — | Jenkins | 5/8/2026 | 8/9/2026 | Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file parameter names, allowing attackers with Item/Configure and Item/Build permission to write files to arbitrary locations on the controller file system. | |
| Analizada | Media (4.3) | 0.43% | — | Jenkins | 5/8/2026 | 8/9/2026 | Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write files to arbitrary locations on the… |