Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

216 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.72%—Request Project Request16/3/202317/6/2026
The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
ModificadaMedia (5.5)0.23%—Jenkins Github Pull Request Coverage Status26/1/202317/6/2026
Jenkins GitHub Pull Request Coverage Status Plugin 2.2.0 and earlier stores the GitHub Personal Access Token, Sonar access token and Sonar password unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
ModificadaMedia (4.3)0.66%—Jenkins Github Pull Request Builder26/1/202317/6/2026
A missing permission check in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
ModificadaMedia (6.5)0.82%—Jenkins Github Pull Request Builder26/1/202317/6/2026
A missing permission check in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
ModificadaAlta (8.8)0.56%—Jenkins Github Pull Request Builder26/1/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
ModificadaMedia (6.1)0.70%—Facetwp LOG Http Requests28/10/202217/6/2026
The Log HTTP Requests plugin for WordPress is vulnerable to Stored Cross-Site Scripting via logged HTTP requests in versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers who can trick a site's administrator into performing…
ModificadaMedia (6.5)0.84%—Jenkins Http Request27/7/202217/6/2026
Jenkins HTTP Request Plugin 1.15 and earlier stores HTTP Request passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
ModificadaAlta (8.8)1.4%—Emarketdesign Request A Quote25/7/202217/6/2026
The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead to a CSV injection once an admin download and open it
ModificadaMedia (4.8)0.64%—Emarketdesign Request A Quote25/7/202217/6/2026
The Request a Quote WordPress plugin before 2.3.9 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaMedia (6.1)0.57%—Bestpractical Request Tracker14/7/202217/6/2026
Best Practical Request Tracker (RT) before 5.0.3 has an Open Redirect via a ticket search.
ModificadaMedia (6.1)0.83%—Bestpractical Request Tracker14/7/202217/6/2026
Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 allows XSS via a crafted content type for an attachment.
ModificadaCrítica (9.1)0.91%—Bestpractical Request Tracker FOR Incident Response14/7/202217/6/2026
Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools.
ModificadaCrítica (9.1)0.91%—Bestpractical Request Tracker FOR Incident Response14/7/202217/6/2026
Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool.
ModificadaMedia (4.3)0.48%—Jenkins Request Rename OR Delete30/6/202217/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Request Rename Or Delete Plugin 1.1.0 and earlier allows attackers to accept pending requests, thereby renaming or deleting jobs.
ModificadaMedia (4.3)0.59%—Jenkins Request Rename OR Delete30/6/202217/6/2026
Jenkins Request Rename Or Delete Plugin 1.1.0 and earlier does not correctly perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to view an administrative configuration page listing pending requests.
ModificadaMedia (4.3)0.56%—Jenkins Requests30/6/202217/6/2026
An incorrect permission check in Jenkins requests-plugin Plugin 2.2.16 and earlier allows attackers with Overall/Read permission to view the list of pending requests.
ModificadaAlta (7.5)1.4%—Node-request-retry Project Node-request-retry23/2/202217/6/2026
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository fgribreau/node-request-retry prior to 7.0.0.
ModificadaMedia (4.8)0.64%—Emarketdesign Request A Quote25/10/202117/6/2026
The Request a Quote WordPress plugin before 2.3.9 does not sanitise, validate or escape some of its settings in the admin dashboard, leading to authenticated Stored Cross-Site Scripting issues even when the unfiltered_html capability is disallowed.
ModificadaCrítica (9.8)7.1%—Gridprosoftware Request Management25/10/202117/6/2026
Gridpro Request Management for Windows Azure Pack before 2.0.7912 allows Directory Traversal for remote code execution, as demonstrated by ..\\ in a scriptName JSON value to ServiceManagerTenant/GetVisibilityMap.
ModificadaAlta (7.5)1.8%—Bestpractical Request TrackerFedoraproject FedoraDebian Linux18/10/202117/6/2026
Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a timing attack against lib/RT/REST2/Middleware/Auth.pm.
ModificadaMedia (5.4)0.62%—Emarketdesign Request A Quote12/7/202117/6/2026
The Request a Quote WordPress plugin before 2.3.4 did not sanitise and escape some of its quote fields when adding/editing a quote as admin, leading to Stored Cross-Site scripting issues when the quote is output in the 'All Quotes" table.
ModificadaMedia (4.3)1.4%—Jenkins Requests30/6/202117/6/2026
Jenkins requests-plugin Plugin 2.2.7 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to send test emails to an attacker-specified email address.
ModificadaMedia (6.5)1.3%—Jenkins Requests30/6/202117/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins requests-plugin Plugin 2.2.12 and earlier allows attackers to create requests and/or have administrators apply pending requests.
ModificadaMedia (4.3)0.97%—Jenkins Requests30/6/202117/6/2026
A missing permission check in Jenkins requests-plugin Plugin 2.2.6 and earlier allows attackers with Overall/Read permission to view the list of pending requests.
ModificadaCrítica (9.8)2.1%—Wordpress Requests27/4/202117/6/2026
Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been patched and users of `Requests` 1.6.0, 1.6.1 and 1.7.0 should update to version 1.8.0.