Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2585▼ 303 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
46 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.25% | — | Jenkins Bitbucket Push AND Pull RequestAI | 16/9/2026 | 18/9/2026 | Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URLs, allowing attackers to capture Bitbucket credentials stored in Jenkins by sending a crafted webhook payload. | |
| Pendiente de análisis | Media (4.2) | 0.11% | — | Jenkins Bitbucket Server Integration PluginAI | 16/9/2026 | 18/9/2026 | The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `oauth_callback` URL from the submitted form rather than from the server-side stored request token, allowing attackers to hijack the OAuth flow and obtain an access token on behalf of the victim. | |
| Aplazada | Crítica (9.2) | 0.72% | — | GitlabAIGiteaAIForgejoAIGithubAI+2 | 30/6/2026 | 14/7/2026 | Woodpecker before 3.15.0 matches the ApprovalAllowedUsers bypass list against pipeline.Author. For the GitLab forge driver, pipeline.Author is populated from the git commit author name (commit.author.name) carried in the webhook payload, which is attacker-controlled and not verified by GitLab. A user who can open a… | |
| Analizada | Media (4.8) | 0.16% | — | Jenkins Bitbucket Push AND Pull Request | 24/6/2026 | 26/6/2026 | Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections sending Bearer token authenticated requests to the configured Bitbucket Server endpoint, allowing attackers able to intercept network traffic to capture the token. | |
| Aplazada | Alta (8.7) | 0.48% | — | Syracom AG Secure Login 2FAAIAtlassian JiraAIAtlassian ConfluenceAIAtlassian BitbucketAI | 16/6/2026 | 21/6/2026 | syracom AG Secure Login (2FA) for Atlassian Jira, Confluence, and Bitbucket 3.4.0.x contains an authentication bypass vulnerability. An attacker with valid credentials for a user account can bypass the two-factor authentication flow by sending HTTP requests with a crafted User-Agent header containing specific strings… | |
| Analizada | Media (4.3) | 0.33% | — | Jenkins Bitbucket Oauth | 27/5/2026 | 17/6/2026 | Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks. | |
| Modificada | Media (5.4) | 0.24% | — | Jenkins Publish TO Bitbucket | 29/10/2025 | 17/6/2026 | A missing permission check in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Media (5.4) | 0.21% | — | Jenkins Publish TO Bitbucket | 29/10/2025 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Media (4.3) | 0.27% | — | Jenkins Publish TO Bitbucket | 29/10/2025 | 17/6/2026 | A missing permission check in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Analizada | Alta (8.8) | 0.30% | — | Jenkins Bitbucket Server Integration | 22/1/2025 | 17/6/2026 | Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins. | |
| Analizada | Media (4.3) | 0.25% | — | Atlassian Bitbucket Data Center | 24/7/2024 | 17/6/2026 | There is a low severity open redirect vulnerability within affected versions of Bitbucket Data Center. Versions of Bitbucket DC from 8.0.0 to 8.9.12 and 8.19.0 to 8.19.1 are affected by this vulnerability. It is patched in 8.9.13 and 8.19.2. This open redirect vulnerability, with a CVSS Score of 3.1 and a CVSS Vector… | |
| Analizada | Media (4.3) | 0.49% | — | Jenkins Bitbucket Branch Source | 26/6/2024 | 17/6/2026 | Jenkins Bitbucket Branch Source Plugin 886.v44cf5e4ecec5 and earlier prints the Bitbucket OAuth access token as part of the Bitbucket URL in the build log in some cases. | |
| Analizada | Media (6.3) | 0.56% | — | Jenkins Bitbucket Branch Source | 6/3/2024 | 17/6/2026 | In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks, the trust policy "Forks in the same account" allows changes to Jenkinsfiles from users without write access to the project when using Bitbucket Server. | |
| Modificada | Alta (8.8) | 16% | — | Atlassian Bitbucket Data CenterAtlassian Bitbucket Server | 19/9/2023 | 17/6/2026 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 8.0.0 of Bitbucket Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to… | |
| Modificada | Alta (7.5) | 0.68% | — | Jenkins Bitbucket Push AND Pull Request | 6/9/2023 | 17/6/2026 | Jenkins Bitbucket Push and Pull Request Plugin 2.4.0 through 2.8.3 (both inclusive) trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URLs, allowing attackers to capture Bitbucket credentials stored in Jenkins by sending a crafted… | |
| Modificada | Media (5.7) | 0.48% | — | Jenkins Bitbucket Oauth | 26/1/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket OAuth Plugin 0.12 and earlier allows attackers to trick users into logging in to the attacker's account. | |
| Modificada | Crítica (9.8) | 1.1% | — | Jenkins Bitbucket Oauth | 26/1/2023 | 17/6/2026 | Jenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous session on login. | |
| Modificada | Crítica (9.8) | 98% | — | Atlassian Bitbucket | 17/11/2022 | 17/6/2026 | There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance… | |
| Analizada | Alta (8.8) | 99% | ⚠ Explotación activa | Atlassian Bitbucket | 25/8/2022 | 17/6/2026 | Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from… | |
| Modificada | Alta (8.8) | 2.3% | — | Atlassian BambooAtlassian BitbucketAtlassian Confluence Data CenterAtlassian Confluence Server+7 | 20/7/2022 | 17/6/2026 | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource… | |
| Modificada | Crítica (9.8) | 5.4% | — | Atlassian BambooAtlassian BitbucketAtlassian Confluence Data CenterAtlassian Confluence Server+7 | 20/7/2022 | 17/6/2026 | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting.… | |
| Modificada | Crítica (9.8) | 70% | — | Atlassian Bitbucket Data Center | 20/4/2022 | 17/6/2026 | SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute arbitrary code via Java deserialization. | |
| Modificada | Media (5.4) | 0.67% | — | Jenkins Bitbucket Server Integration | 29/3/2022 | 17/6/2026 | Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to create, view, and delete BitBucket Server consumers. | |
| Modificada | Media (5.4) | 0.82% | — | Jenkins Bitbucket Server Integration | 29/3/2022 | 17/6/2026 | Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not limit URL schemes for callback URLs on OAuth consumers, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create BitBucket Server consumers. | |
| Modificada | Alta (7.1) | 0.66% | — | Jenkins Bitbucket Branch Source | 12/1/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. |