Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
323 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.3% | — | Jenkins FTP Publisher | 4/4/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins FTP publisher Plugin in the FTPPublisher.DescriptorImpl#doLoginCheck method allows attackers to initiate a connection to an attacker-specified server. | |
| Modificada | Alta (8.8) | 1.3% | — | Jenkins FTP Publisher | 4/4/2019 | 17/6/2026 | Jenkins FTP publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | |
| Modificada | Alta (8.8) | 1.3% | — | Jenkins AWS Elastic Beanstalk Publisher | 4/4/2019 | 17/6/2026 | Jenkins AWS Elastic Beanstalk Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | |
| Modificada | Media (6.5) | 1.6% | — | Trustsource ECS Publisher | 28/3/2019 | 17/6/2026 | A vulnerability in Jenkins ECS Publisher Plugin 1.0.0 and earlier allows attackers with Item/Extended Read permission, or local file system access to the Jenkins home directory to obtain the API token configured in this plugin's configuration. | |
| Modificada | Alta (7.5) | 2.8% | — | Flexera Flexnet PublisherOracle Communications Lsms | 21/3/2019 | 17/6/2026 | A Denial of Service vulnerability related to adding an item to a list in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and… | |
| Modificada | Alta (7.5) | 2.2% | — | Flexera Flexnet PublisherOracle Communications Lsms | 21/3/2019 | 17/6/2026 | A Denial of Service vulnerability related to message decoding in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and the… | |
| Modificada | Alta (7.5) | 2.2% | — | Flexera Flexnet PublisherOracle Communications Lsms | 21/3/2019 | 17/6/2026 | A Denial of Service vulnerability related to preemptive item deletion in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and… | |
| Modificada | Crítica (9.8) | 3.7% | — | Flexera Flexnet PublisherOracle Communications Lsms | 25/2/2019 | 17/6/2026 | A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow a remote attacker to corrupt the memory by allocating / deallocating memory, loading lmgrd or the vendor daemon and causing the heartbeat between lmgrd and the vendor daemon to… | |
| Modificada | Media (4.3) | 0.64% | — | Jenkins Confluence Publisher | 1/8/2018 | 17/6/2026 | A server-side request forgery vulnerability exists in Jenkins Confluence Publisher Plugin 2.0.1 and earlier in ConfluenceSite.java that allows attackers to have Jenkins submit login requests to an attacker-specified Confluence server URL with attacker specified credentials. | |
| Modificada | Alta (8.2) | 2.1% | — | Oracle Business Intelligence Publisher | 18/7/2018 | 17/6/2026 | Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0, 12.2.1.2.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI… | |
| Modificada | Media (6.5) | 2.0% | — | Oracle Business Intelligence Publisher | 18/7/2018 | 17/6/2026 | Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: Web Server). Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0, 12.2.1.2.0 and 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise BI Publisher.… | |
| Modificada | Alta (8.2) | 2.0% | — | Oracle Business Intelligence Publisher | 18/7/2018 | 17/6/2026 | Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: Layout Tools). The supported version that is affected is 11.1.1.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher. Successful attacks of this vulnerability… | |
| Modificada | Alta (7.8) | 17% | — | Microsoft Publisher | 14/6/2018 | 17/6/2026 | A remote code execution vulnerability exists when Microsoft Publisher fails to utilize features that lock down the Local Machine zone when instantiating OLE objects, aka "Microsoft Publisher Remote Code Execution Vulnerability." This affects Microsoft Publisher. | |
| Modificada | Media (5.4) | 0.67% | — | Jenkins S3 Publisher | 8/5/2018 | 17/6/2026 | A cross-site scripting vulnerability exists in Jenkins S3 Plugin 0.10.12 and older in src/main/resources/hudson/plugins/s3/S3ArtifactsProjectAction/jobMain.jelly that allows attackers able to control file names of uploaded files to define file names containing JavaScript that would be executed in another user's… | |
| Modificada | Media (6.5) | 2.7% | — | Jenkins Html Publisher | 8/5/2018 | 17/6/2026 | A path traversal vulnerability exists in Jenkins HTML Publisher Plugin 1.15 and older in HtmlPublisherTarget.java that allows attackers able to configure the HTML Publisher build step to override arbitrary files on the Jenkins master. | |
| Modificada | Media (4.3) | 0.66% | — | Jenkins Google-play-android-publisher | 13/3/2018 | 17/6/2026 | An improper authorization vulnerability exists in Jenkins Google Play Android Publisher Plugin version 1.6 and earlier in GooglePlayBuildStepDescriptor.java that allow an attacker to obtain credential IDs. | |
| Modificada | Alta (7.8) | 0.38% | — | Jenkins Build-publisher | 26/1/2018 | 17/6/2026 | Jenkins Build-Publisher plugin version 1.21 and earlier stores credentials to other Jenkins instances in the file hudson.plugins.build_publisher.BuildPublisher.xml in the Jenkins master home directory. These credentials were stored unencrypted, allowing anyone with local file system access to access them.… | |
| Modificada | Alta (7.5) | 2.6% | — | Oracle Business Intelligence Publisher | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle BI Publisher component of Oracle Fusion Middleware (subcomponent: Web Service API). Supported versions that are affected are 11.1.1.7.0 and 11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful… | |
| Modificada | Alta (8.2) | 2.0% | — | Oracle Business Intelligence Publisher | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle BI Publisher component of Oracle Fusion Middleware (subcomponent: Core Formatting API). Supported versions that are affected are 11.1.1.7.0 and 11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher.… | |
| Modificada | Alta (7.8) | 20% | — | Microsoft Publisher | 13/9/2017 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Publisher 2007 Service Pack 3 and Microsoft Publisher 2010 Service Pack 2 when they fail to properly handle objects in memory, aka "Microsoft Office Publisher Remote Code Execution". | |
| Modificada | Alta (8.8) | 1.1% | — | Podlove Podcast Publisher | 18/8/2017 | 17/6/2026 | lib\modules\contributors\contributor_list_table.php in the Podlove Podcast Publisher plugin 2.5.3 and earlier for WordPress has SQL injection in the orderby parameter to wp-admin/admin.php, exploitable through CSRF. | |
| Modificada | Media (6.5) | 1.6% | — | Oracle Business Intelligence Publisher | 8/8/2017 | 17/6/2026 | Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI… | |
| Modificada | Alta (8.2) | 1.9% | — | Oracle Business Intelligence Publisher | 8/8/2017 | 17/6/2026 | Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI… | |
| Modificada | Alta (7.6) | 1.4% | — | Oracle Business Intelligence Publisher | 8/8/2017 | 17/6/2026 | Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: Mobile Service). The supported version that is affected is 11.1.1.7.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise BI Publisher. Successful attacks require human… | |
| Modificada | Alta (8.2) | 1.9% | — | Oracle Business Intelligence Publisher | 8/8/2017 | 17/6/2026 | Vulnerability in the BI Publisher component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.7.0 and 11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher. Successful attacks… |