Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
323 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.62% | — | Jenkins Build-publisher | 21/9/2022 | 17/6/2026 | Jenkins Build-Publisher Plugin 1.22 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to obtain names and URLs of Jenkins servers that the plugin is configured to publish builds to, as well as builds pending for publication to those Jenkins servers. | |
| Modificada | Media (5.4) | 0.62% | — | Jenkins Ns-nd Integration Performance Publisher | 21/9/2022 | 17/6/2026 | Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.134 and earlier does not escape configuration options of the Execute NetStorm/NetCloud Test build step, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Alta (8.8) | 0.97% | — | Jenkins Ns-nd Integration Performance Publisher | 21/9/2022 | 17/6/2026 | A missing permission check in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers with Overall/Read permissions to connect to an attacker-specified webserver using attacker-specified credentials. | |
| Modificada | Alta (8.8) | 0.54% | — | Jenkins Ns-nd Integration Performance Publisher | 21/9/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers to connect to an attacker-specified webserver using attacker-specified credentials. | |
| Modificada | Media (4.3) | 0.64% | — | Oracle BI Publisher | 19/7/2022 | 17/6/2026 | Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful… | |
| Modificada | Alta (7.8) | 0.25% | — | SAP Businessobjects BW Publisher Service | 12/7/2022 | 17/6/2026 | SAP BusinessObjects BW Publisher Service - versions 420, 430, uses a search path that contains an unquoted element. A local attacker can gain elevated privileges by inserting an executable file in the path of the affected service | |
| Modificada | Media (5.4) | 0.60% | — | Jenkins Rich Text Publisher | 30/6/2022 | 17/6/2026 | Jenkins Rich Text Publisher Plugin 1.4 and earlier does not escape the HTML message set by its post-build step, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs. | |
| Modificada | Media (6.5) | 0.73% | — | Jenkins Squash TM Publisher | 23/6/2022 | 17/6/2026 | Jenkins Squash TM Publisher (Squash4Jenkins) Plugin 1.0.0 and earlier stores passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Media (5.4) | 0.64% | — | Jenkins Ns-nd Integration Performance Publisher | 23/6/2022 | 17/6/2026 | Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.77 and earlier does not escape the name of NetStorm Test parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Media (5.5) | 3.1% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Publisher+1 | 10/5/2022 | 17/6/2026 | Microsoft Office Security Feature Bypass Vulnerability | |
| Modificada | Alta (8.8) | 0.79% | — | Jenkins SCP Publisher | 15/2/2022 | 17/6/2026 | A missing permission check in Jenkins SCP publisher Plugin 1.8 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials. | |
| Modificada | Alta (8.8) | 0.53% | — | Jenkins SCP Publisher | 15/2/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins SCP publisher Plugin 1.8 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials. | |
| Modificada | Media (5.9) | 3.8% | — | OpensslDebian LinuxOracle Health Sciences Inform PublisherOracle JD Edwards Enterpriseone Tools+4 | 28/1/2022 | 17/6/2026 | There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are affected, including some of the TLS 1.3 default curves. Impact was not analyzed in detail, because the pre-requisites for attack are considered unlikely and include reusing private keys. Analysis suggests that attacks… | |
| Modificada | Alta (7.5) | 2.2% | — | Oracle BI Publisher | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI… | |
| Modificada | Alta (8.1) | 1.1% | — | Jenkins Squash TM Publisher | 12/11/2021 | 17/6/2026 | Jenkins Squash TM Publisher (Squash4Jenkins) Plugin 1.0.0 and earlier implements an agent-to-controller message that does not implement any validation of its input, allowing attackers able to control agent processes to replace arbitrary files on the Jenkins controller file system with an attacker-controlled JSON… | |
| Modificada | Media (4.8) | 1.0% | — | Mpl-publisher | 19/10/2021 | 17/6/2026 | The MPL-Publisher WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/libs/PublisherController.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and… | |
| Modificada | Crítica (9.8) | 8.9% | 💥 Exploit | Podlove Podcast Publisher | 27/9/2021 | 17/6/2026 | The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by default), which adds the rest route '/services/contributor/(?P<id>[\d]+), takes an 'id' and 'category' parameters as arguments. Both parameters can be used for the SQLi. | |
| Modificada | Alta (7.5) | 2.1% | — | Flexera Flexnet Publisher | 17/9/2021 | 17/6/2026 | A Denial of Service vulnerability has been identified in FlexNet Publisher's lmadmin.exe version 11.16.6. A certain message protocol can be exploited to cause lmadmin to crash. | |
| Modificada | Alta (7.4) | 50% | 💥 PoC | OpensslDebian LinuxNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+28 | 24/8/2021 | 17/6/2026 | ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a… | |
| Modificada | Crítica (9.8) | 88% | — | OpensslDebian LinuxNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+27 | 24/8/2021 | 17/6/2026 | In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the… | |
| Modificada | Media (5.3) | 85% | — | Oracle BI Publisher | 21/7/2021 | 17/6/2026 | Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Alta (7.5) | 83% | — | Oracle BI Publisher | 21/7/2021 | 17/6/2026 | Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Alta (8.8) | 36% | — | Oracle BI Publisher | 21/7/2021 | 17/6/2026 | Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Alta (8.8) | 3.1% | — | Oracle BI Publisher | 21/7/2021 | 17/6/2026 | Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Alta (8.8) | 35% | — | Oracle BI Publisher | 21/7/2021 | 17/6/2026 | Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Scheduler). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher.… |