Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
216 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.72% | — | Request Project Request | 16/3/2023 | 17/6/2026 | The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | |
| Modificada | Media (5.5) | 0.23% | — | Jenkins Github Pull Request Coverage Status | 26/1/2023 | 17/6/2026 | Jenkins GitHub Pull Request Coverage Status Plugin 2.2.0 and earlier stores the GitHub Personal Access Token, Sonar access token and Sonar password unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Media (4.3) | 0.66% | — | Jenkins Github Pull Request Builder | 26/1/2023 | 17/6/2026 | A missing permission check in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Modificada | Media (6.5) | 0.82% | — | Jenkins Github Pull Request Builder | 26/1/2023 | 17/6/2026 | A missing permission check in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Alta (8.8) | 0.56% | — | Jenkins Github Pull Request Builder | 26/1/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Media (6.1) | 0.70% | — | Facetwp LOG Http Requests | 28/10/2022 | 17/6/2026 | The Log HTTP Requests plugin for WordPress is vulnerable to Stored Cross-Site Scripting via logged HTTP requests in versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers who can trick a site's administrator into performing… | |
| Modificada | Media (6.5) | 0.84% | — | Jenkins Http Request | 27/7/2022 | 17/6/2026 | Jenkins HTTP Request Plugin 1.15 and earlier stores HTTP Request passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Alta (8.8) | 1.4% | — | Emarketdesign Request A Quote | 25/7/2022 | 17/6/2026 | The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users to attach a malicious CSV file to a quote, which could lead to a CSV injection once an admin download and open it | |
| Modificada | Media (4.8) | 0.64% | — | Emarketdesign Request A Quote | 25/7/2022 | 17/6/2026 | The Request a Quote WordPress plugin before 2.3.9 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (6.1) | 0.57% | — | Bestpractical Request Tracker | 14/7/2022 | 17/6/2026 | Best Practical Request Tracker (RT) before 5.0.3 has an Open Redirect via a ticket search. | |
| Modificada | Media (6.1) | 0.83% | — | Bestpractical Request Tracker | 14/7/2022 | 17/6/2026 | Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 allows XSS via a crafted content type for an attachment. | |
| Modificada | Crítica (9.1) | 0.91% | — | Bestpractical Request Tracker FOR Incident Response | 14/7/2022 | 17/6/2026 | Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools. | |
| Modificada | Crítica (9.1) | 0.91% | — | Bestpractical Request Tracker FOR Incident Response | 14/7/2022 | 17/6/2026 | Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool. | |
| Modificada | Media (4.3) | 0.48% | — | Jenkins Request Rename OR Delete | 30/6/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Request Rename Or Delete Plugin 1.1.0 and earlier allows attackers to accept pending requests, thereby renaming or deleting jobs. | |
| Modificada | Media (4.3) | 0.59% | — | Jenkins Request Rename OR Delete | 30/6/2022 | 17/6/2026 | Jenkins Request Rename Or Delete Plugin 1.1.0 and earlier does not correctly perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to view an administrative configuration page listing pending requests. | |
| Modificada | Media (4.3) | 0.56% | — | Jenkins Requests | 30/6/2022 | 17/6/2026 | An incorrect permission check in Jenkins requests-plugin Plugin 2.2.16 and earlier allows attackers with Overall/Read permission to view the list of pending requests. | |
| Modificada | Alta (7.5) | 1.4% | — | Node-request-retry Project Node-request-retry | 23/2/2022 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository fgribreau/node-request-retry prior to 7.0.0. | |
| Modificada | Media (4.8) | 0.64% | — | Emarketdesign Request A Quote | 25/10/2021 | 17/6/2026 | The Request a Quote WordPress plugin before 2.3.9 does not sanitise, validate or escape some of its settings in the admin dashboard, leading to authenticated Stored Cross-Site Scripting issues even when the unfiltered_html capability is disallowed. | |
| Modificada | Crítica (9.8) | 7.1% | — | Gridprosoftware Request Management | 25/10/2021 | 17/6/2026 | Gridpro Request Management for Windows Azure Pack before 2.0.7912 allows Directory Traversal for remote code execution, as demonstrated by ..\\ in a scriptName JSON value to ServiceManagerTenant/GetVisibilityMap. | |
| Modificada | Alta (7.5) | 1.8% | — | Bestpractical Request TrackerFedoraproject FedoraDebian Linux | 18/10/2021 | 17/6/2026 | Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a timing attack against lib/RT/REST2/Middleware/Auth.pm. | |
| Modificada | Media (5.4) | 0.62% | — | Emarketdesign Request A Quote | 12/7/2021 | 17/6/2026 | The Request a Quote WordPress plugin before 2.3.4 did not sanitise and escape some of its quote fields when adding/editing a quote as admin, leading to Stored Cross-Site scripting issues when the quote is output in the 'All Quotes" table. | |
| Modificada | Media (4.3) | 1.4% | — | Jenkins Requests | 30/6/2021 | 17/6/2026 | Jenkins requests-plugin Plugin 2.2.7 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to send test emails to an attacker-specified email address. | |
| Modificada | Media (6.5) | 1.3% | — | Jenkins Requests | 30/6/2021 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins requests-plugin Plugin 2.2.12 and earlier allows attackers to create requests and/or have administrators apply pending requests. | |
| Modificada | Media (4.3) | 0.97% | — | Jenkins Requests | 30/6/2021 | 17/6/2026 | A missing permission check in Jenkins requests-plugin Plugin 2.2.6 and earlier allows attackers with Overall/Read permission to view the list of pending requests. | |
| Modificada | Crítica (9.8) | 2.1% | — | Wordpress Requests | 27/4/2021 | 17/6/2026 | Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been patched and users of `Requests` 1.6.0, 1.6.1 and 1.7.0 should update to version 1.8.0. |