Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
197 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 1.4% | — | JenkinsOracle Communications Cloud Native Core Automated Test SuiteRedhat Openshift Container Platform | 28/8/2019 | 17/6/2026 | A stored cross-site scripting vulnerability in Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed attackers with Overall/Administer permission to configure the update site URL to inject arbitrary HTML and JavaScript in update center web pages. | |
| Modificada | Media (5.4) | 1.3% | — | JenkinsOracle Communications Cloud Native Core Automated Test SuiteRedhat Openshift Container Platform | 10/4/2019 | 17/6/2026 | The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, resulting in a cross-site scripting (XSS) vulnerability exploitable by users with the ability to control job names. | |
| Modificada | Alta (8.1) | 2.1% | — | JenkinsRedhat Openshift Container PlatformOracle Communications Cloud Native Core Automated Test Suite | 10/4/2019 | 17/6/2026 | Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-1003004 in these releases did not reject existing remoting-based CLI authentication… | |
| Modificada | Media (5.4) | 0.89% | — | JenkinsOracle Communications Cloud Native Core Automated Test Suite | 23/7/2018 | 17/6/2026 | A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers with the ability to control the existence of some URLs in Jenkins to define JavaScript that would be executed in another user's browser… | |
| Modificada | Media (5.4) | 0.89% | — | JenkinsOracle Communications Cloud Native Core Automated Test Suite | 23/7/2018 | 17/6/2026 | A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in BuildTimelineWidget.java, BuildTimelineWidget/control.jelly that allows attackers with Job/Configure permission to define JavaScript that would be executed in another user's browser when that other user performs some UI… | |
| Modificada | Media (4.3) | 0.94% | — | JenkinsOracle Communications Cloud Native Core Automated Test Suite | 23/7/2018 | 17/6/2026 | A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in SlaveComputer.java that allows attackers with Overall/Read permission to initiate agent launches, and abort in-progress agent launches. | |
| Modificada | Media (4.3) | 0.76% | — | JenkinsOracle Communications Cloud Native Core Automated Test Suite | 23/7/2018 | 17/6/2026 | A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Queue.java that allows attackers with Overall/Read permission to cancel queued builds. | |
| Modificada | Alta (7.5) | 86% | 💥 Exploit | JenkinsOracle Communications Cloud Native Core Automated Test Suite | 23/7/2018 | 17/6/2026 | A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers to send crafted HTTP requests returning the contents of any file on the Jenkins master file system that the Jenkins master has access to. | |
| Modificada | Alta (8.8) | 18% | — | JenkinsOracle Communications Cloud Native Core Automated Test Suite | 23/7/2018 | 17/6/2026 | A unauthorized modification of configuration vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in User.java that allows attackers to provide crafted login credentials that cause Jenkins to move the config.xml file from the Jenkins home directory. If Jenkins is started without this file present, it… | |
| Modificada | Alta (7.5) | 3.0% | — | Carrier Automatedlogic Webctrl | 14/6/2018 | 17/6/2026 | An XXE issue was discovered in Automated Logic Corporation (ALC) WebCTRL Versions 6.0, 6.1 and 6.5. An unauthenticated attacker could enter malicious input to WebCTRL and a weakly configured XML parser will allow the application to disclose full file contents from the underlying web server OS via the "X-Wap-Profile"… | |
| Modificada | Media (4.3) | 2.1% | — | JenkinsOracle Communications Cloud Native Core Automated Test Suite | 5/6/2018 | 17/6/2026 | A server-side request forgery vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in ZipExtractionInstaller.java that allows users with Overall/Read permission to have Jenkins submit a HTTP GET request to an arbitrary URL and learn whether the response is successful (200) or not. | |
| Modificada | Alta (8.1) | 2.6% | — | JenkinsOracle Communications Cloud Native Core Automated Test Suite | 5/6/2018 | 17/6/2026 | A path traversal vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in FilePath.java, SoloFilePathFilter.java that allows malicious agents to read and write arbitrary files on the Jenkins master, bypassing the agent-to-master security subsystem protection. | |
| Modificada | Media (4.3) | 1.0% | — | JenkinsOracle Communications Cloud Native Core Automated Test Suite | 5/6/2018 | 17/6/2026 | A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in HudsonPrivateSecurityRealm.java that allows users to sign up using user names containing control characters that can then appear to have the same name as other users, and cannot be deleted via the… | |
| Modificada | Media (4.3) | 1.1% | — | JenkinsOracle Communications Cloud Native Core Automated Test Suite | 5/6/2018 | 17/6/2026 | A information exposure vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in AboutJenkins.java, ListPluginsCommand.java that allows users with Overall/Read access to enumerate all installed plugins. | |
| Modificada | Media (6.5) | 3.9% | — | JenkinsOracle Communications Cloud Native Core Automated Test Suite | 20/2/2018 | 17/6/2026 | Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base directory for URLs accessing plugin resource files. This allowed users with Overall/Read permission to download files from the Jenkins master they should not have access to. On Windows, any file… | |
| Modificada | Media (5.3) | 2.0% | — | JenkinsOracle Communications Cloud Native Core Automated Test Suite | 16/2/2018 | 17/6/2026 | An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to access plugin resource files in the META-INF and WEB-INF directories that should not be accessible, if the Jenkins home directory is on a case-insensitive file system. | |
| Modificada | Media (5.3) | 1.7% | — | JenkinsOracle Communications Cloud Native Core Automated Test Suite | 16/2/2018 | 17/6/2026 | An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to have Jenkins submit HTTP GET requests and get limited information about the response. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | JenkinsOracle Communications Cloud Native Core Automated Test Suite | 29/1/2018 | 17/6/2026 | Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers to transfer a serialized Java `SignedObject` object to the Jenkins CLI, that would be deserialized using a new… | |
| Modificada | Alta (7.3) | 2.2% | — | Automatedlogic I-vuAutomatedlogic Sitescan WEBCarrier Automatedlogic Webctrl | 31/8/2017 | 17/6/2026 | An XXE issue was discovered in Automated Logic Corporation (ALC) Liebert SiteScan Web Version 6.5 and prior, ALC WebCTRL Version 6.5 and prior, and Carrier i-Vu Version 6.5 and prior. An attacker could enter malicious input to WebCTRL, i-Vu, or SiteScan Web through a weakly configured XML parser causing the… | |
| Modificada | Alta (7.8) | 2.4% | 💥 Exploit | Automatedlogic I-vuAutomatedlogic Sitescan WEBCarrier Automatedlogic Webctrl | 25/8/2017 | 17/6/2026 | An Unrestricted Upload of File with Dangerous Type issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2… | |
| Modificada | Alta (7) | 1.4% | 💥 Exploit | Automatedlogic I-vuAutomatedlogic Sitescan WEBCarrier Automatedlogic Webctrl | 25/8/2017 | 17/6/2026 | An Unquoted Search Path or Element issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An… | |
| Modificada | Media (6.3) | 8.5% | 💥 Exploit | Automatedlogic I-vuAutomatedlogic Sitescan WEBCarrier Automatedlogic Webctrl | 25/8/2017 | 17/6/2026 | A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An authenticated attacker… | |
| Modificada | Alta (7.8) | 0.31% | — | Vertiv Liebert Multilink Automated Shutdown | 10/4/2017 | 17/6/2026 | Liebert MultiLink Automated Shutdown v4.2.4 allows local users to gain privileges by replacing the LiebertM executable file. | |
| Modificada | Media (4.3) | 1.3% | — | Alcatel-lucent Omnitouch 8400 Instant Communications SuiteAlcatel-lucent Omnitouch 8460 Advanced Communication ServerAlcatel-lucent Omnitouch 8660 MY TeamworkAlcatel-lucent Omnitouch 8670 Automated Delivery Message Delivery System | 20/8/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the signin functionality of ics in MyTeamwork services in Alcatel-Lucent Omnitouch 8660 My Teamwork before 6.7, Omnitouch 8670 Automated Message Delivery System (AMDS) before 6.7, Omnitouch 8460 Advanced Communication Server before 9.1, and OmniTouch 8400 Instant… | |
| Modificada | Alta (7.8) | 2.6% | — | HP Intelligent Management Center FOR Automated Network ManagerHP Intelligent Management Center | 9/3/2013 | 16/6/2026 | Unspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 E0401 allows remote attackers to obtain sensitive information via unknown vectors, aka ZDI-CAN-1662. |