Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
120 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.4% | — | Jenkins Pipeline\Redhat Openshift Container Platform | 28/3/2019 | 17/6/2026 | A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary constructors in sandboxed scripts. | |
| Analizada | Crítica (9.9) | 97% | ⚠ Explotación activa💥 Exploit | Jenkins Pipeline\Redhat Openshift Container Platform | 8/3/2019 | 17/6/2026 | A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allows attackers able to control pipeline scripts to execute arbitrary code on the Jenkins master JVM. | |
| Modificada | Alta (8.8) | 81% | 💥 Exploit | Jenkins Pipeline\Redhat Openshift Container Platform | 22/1/2019 | 17/6/2026 | A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src/main/groovy/org/jenkinsci/plugins/pipeline/modeldefinition/parser/Converter.groovy that allows attackers with Overall/Read permission to provide a pipeline script to an HTTP endpoint that can result… | |
| Modificada | Alta (8.8) | 86% | 💥 Exploit | Jenkins Pipeline\Redhat Openshift Container Platform | 22/1/2019 | 17/6/2026 | A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins/workflow/cps/CpsFlowDefinition.java, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShellFactory.java that allows attackers with Overall/Read permission to provide a pipeline script to an… | |
| Modificada | Alta (7.5) | 2.5% | — | Asset Pipeline Project Asset-pipeline | 20/12/2018 | 17/6/2026 | Asset Pipeline Grails Plugin Asset-pipeline plugin version Prior to 2.14.1.1, 2.15.1 and 3.0.6 contains a Incorrect Access Control vulnerability in Applications deployed in Jetty that can result in Download .class files and any arbitrary file. This attack appear to be exploitable via Specially crafted GET request… | |
| Modificada | Alta (8.8) | 1.6% | — | Jenkins Pipeline\Redhat Openshift Container Platform | 10/12/2018 | 17/6/2026 | A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.59 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxTransformer.java, groovy-cps/lib/src/main/java/com/cloudbees/groovy/cps/SandboxCpsTransformer.java that allows attackers with Job/Configure permission, or unauthorized… | |
| Modificada | Alta (7.5) | 2.2% | — | Asset Pipeline Project Asset-pipeline | 28/9/2018 | 17/6/2026 | An issue was discovered in the Asset Pipeline plugin before 3.0.4 for Grails. An attacker can perform directory traversal via a crafted request when a servlet-based application is executed in Jetty, because there is a classloader vulnerability that can allow a reverse file traversal route in AssetPipelineFilter.groovy… | |
| Modificada | Alta (7.5) | 6.6% | — | Microsoft .net CoreMicrosoft Asp.net CoreMicrosoft System.io.pipelines | 13/9/2018 | 17/6/2026 | A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1. | |
| Modificada | Alta (8.5) | 1.1% | — | Jenkins Pipeline Classpath Step | 27/7/2018 | 17/6/2026 | It was found that the use of Pipeline: Classpath Step Jenkins plugin enables a bypass of the Script Security sandbox for users with SCM commit access, as well as users with e.g. Job/Configure permission in Jenkins. | |
| Modificada | Alta (7.8) | 0.34% | — | Jenkins AWS Codepipeline | 9/7/2018 | 17/6/2026 | Jenkins project Jenkins AWS CodePipeline Plugin version 0.36 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodePipelineSCM.java that can result in Credentials Disclosure. This attack appear to be exploitable via local file access. This vulnerability appears to have been fixed in 0.37… | |
| Modificada | Alta (8.8) | 2.6% | — | Jenkins Pipeline Supporting Apis | 9/2/2018 | 17/6/2026 | Jenkins Pipeline: Supporting APIs Plugin 2.17 and earlier have an arbitrary code execution due to incomplete sandbox protection: Methods related to Java deserialization like readResolve implemented in Pipeline scripts were not subject to sandbox protection, and could therefore execute arbitrary code. This could be… | |
| Modificada | Media (6.1) | 0.95% | — | Jenkins Delivery Pipeline | 26/1/2018 | 17/6/2026 | The Jenkins Delivery Pipeline Plugin version 1.0.7 and earlier used the unescaped content of the query parameter 'fullscreen' in its JavaScript, resulting in a cross-site scripting vulnerability through specially crafted URLs. | |
| Modificada | Media (4.8) | 1.0% | — | Jenkins Pipeline Nodes AND Processes | 23/1/2018 | 17/6/2026 | On Jenkins instances with Authorize Project plugin, the authentication associated with a build may lack the Computer/Build permission on some agents. This did not prevent the execution of Pipeline `node` blocks on those agents due to incorrect permissions checks in Pipeline: Nodes and Processes plugin 2.17 and earlier. | |
| Modificada | Alta (7.5) | 1.1% | — | Jenkins Pipeline-input-step | 5/10/2017 | 17/6/2026 | The Pipeline: Input Step Plugin by default allowed users with Item/Read access to a pipeline to interact with the step to provide input. This has been changed, and now requires users to have the Item/Build permission instead. | |
| Modificada | Alta (8.8) | 1.6% | — | Jenkins Pipeline\ | 5/10/2017 | 17/6/2026 | Arbitrary code execution due to incomplete sandbox protection: Constructors, instance variable initializers, and instance initializers in Pipeline scripts were not subject to sandbox protection, and could therefore execute arbitrary code. This could be exploited e.g. by regular Jenkins users with the permission to… | |
| Modificada | Media (5.3) | 0.96% | — | Jenkins Pipeline\ | 5/10/2017 | 17/6/2026 | Builds in Jenkins are associated with an authentication that controls the permissions that the build has to interact with other elements in Jenkins. The Pipeline: Build Step Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins. | |
| Modificada | Media (4.3) | 1.3% | — | SCT Corporation Campus Pipeline | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in render.UserLayoutRootNode.uP in SCT Campus Pipeline allows remote attackers to inject arbitrary web script or HTML via the utf parameter. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | SCT Corporation Campus Pipeline | 15/4/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SCT Campus Pipeline allows remote attackers to inject arbitrary web script or HTML via onload, onmouseover, and other Javascript events in an e-mail attachment. | |
| Modificada | Media (5) | 1.4% | — | Lucent Ascend MAX RouterLucent Ascend Pipeline RouterLucent Dslterminator | 31/12/2002 | 16/6/2026 | Lucent Ascend MAX Router 5.0 and earlier, Lucent Ascend Pipeline Router 6.0.2 and earlier and Lucent DSLTerminator allows remote attackers to obtain sensitive information such as hostname, MAC, and IP address of the Ethernet interface via a discard (UDP port 9) packet, which causes the device to leak the information… | |
| Modificada | Media (5) | 8.6% | 💥 Exploit | Lucent Ascend MAX RouterLucent Ascend Pipeline RouterLucent Ascend TNT Router | 16/3/1998 | 16/6/2026 | Attackers can cause a denial of service in Ascend MAX and Pipeline routers with a malformed packet to the discard port, which is used by the Java Configurator tool. |