Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

323 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.55%—Jenkins Sumologic Publisher12/7/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Sumologic Publisher Plugin 2.2.1 and earlier allows attackers to connect to an attacker-specified URL.
ModificadaAlta (7.8)0.74%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Publisher17/6/202317/6/2026
Microsoft Publisher Remote Code Execution Vulnerability
ModificadaAlta (7.8)0.74%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Publisher17/6/202317/6/2026
Microsoft Publisher Remote Code Execution Vulnerability
ModificadaMedia (6.5)0.66%—Jenkins Digital.ai APP Management Publisher14/6/202317/6/2026
A missing permission check in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL, capturing credentials stored in Jenkins.
ModificadaMedia (6.5)0.45%—Jenkins Digital.ai APP Management Publisher14/6/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers to connect to an attacker-specified URL, capturing credentials stored in Jenkins.
ModificadaAlta (8.8)0.27%—Podlove Podcast Publisher23/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher plugin <= 3.8.3 versions.
ModificadaAlta (7.5)0.57%—Jenkins Ns-nd Integration Performance Publisher16/5/202317/6/2026
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier does not mask credentials displayed on the configuration form, increasing the potential for attackers to observe and capture them.
ModificadaMedia (5.7)0.57%—Oracle BI Publisher18/4/202317/6/2026
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Security). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks require human interaction…
ModificadaMedia (4.3)0.48%—Oracle BI Publisher18/4/202317/6/2026
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 6.4.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this…
ModificadaMedia (4.8)0.39%—Podlove Podcast Publisher7/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Podlove Podlove Podcast Publisher plugin <= 3.8.2 versions.
ModificadaAlta (8.2)0.57%—Jenkins Performance Publisher2/4/202317/6/2026
Jenkins Performance Publisher Plugin 8.09 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
ModificadaAlta (7.5)0.65%—Flexera Flexnet Publisher29/3/202317/6/2026
A Denial of Service (DoS) vulnerability was discovered in FlexNet Publisher's lmadmin 11.16.5, when doing a crafted POST request on lmadmin using the web-based tool.
ModificadaMedia (6.1)1.3%💥 ExploitGnpublisher GN Publisher28/2/202317/6/2026
The GN Publisher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if…
ModificadaAlta (8.1)1.2%—Hapifhir HL7 Fhir CoreHL7 Fhir IG Publisher26/1/202317/6/2026
HL7 (Health Level 7) FHIR Core Libraries before 5.6.92 allow attackers to extract files into arbitrary directories via directory traversal from a crafted ZIP or TGZ archive (for a prepackaged terminology cache, NPM package, or comparison archive).
ModificadaAlta (8.8)0.63%—Oracle BI Publisher18/1/202317/6/2026
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 5.9.0.0.0, 6.4.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle BI Publisher.…
ModificadaAlta (8.8)0.63%—Oracle BI Publisher18/1/202317/6/2026
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 5.9.0.0.0, 6.4.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle BI Publisher.…
ModificadaAlta (7.2)1.1%—WP RSS BY Publishers Project WP RSS BY Publishers2/1/202317/6/2026
The WP RSS By Publishers WordPress plugin through 0.1 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
ModificadaAlta (7.2)0.98%—WP RSS BY Publishers Project WP RSS BY Publishers2/1/202317/6/2026
The WP RSS By Publishers WordPress plugin through 0.1 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
ModificadaAlta (7.2)0.98%—WP RSS BY Publishers Project WP RSS BY Publishers2/1/202317/6/2026
The WP RSS By Publishers WordPress plugin through 0.1 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
ModificadaMedia (6.5)0.68%—Jenkins Ns-nd Integration Performance Publisher15/11/202217/6/2026
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by attackers with Extended Read permission, or access to the Jenkins controller file system.
ModificadaAlta (7.5)0.42%—Jenkins Ns-nd Integration Performance Publisher15/11/202217/6/2026
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier globally and unconditionally disables SSL/TLS certificate and hostname validation for the entire Jenkins controller JVM.
ModificadaAlta (7.5)0.42%—Jenkins Ns-nd Integration Performance Publisher15/11/202217/6/2026
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.146 and earlier unconditionally disables SSL/TLS certificate and hostname validation for several features.
ModificadaAlta (7.6)0.71%—Oracle BI Publisher18/10/202217/6/2026
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Core Formatting API). Supported versions that are affected are 5.9.0.0, 6.4.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI…
ModificadaAlta (8)0.54%—Jenkins Build-publisher21/9/202217/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers to replace any config.xml file on the Jenkins controller file system with an empty file by providing a crafted file name to an API endpoint.
ModificadaMedia (5.7)1.4%—Jenkins Build-publisher21/9/202217/6/2026
Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers with Item/Configure permission to create or replace any config.xml file on the Jenkins controller file system by providing a crafted file name to an API endpoint.