Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▲ 460 respecto a la semana anterior
Críticas / altas1445▲ 228 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 156 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.56% | — | Jenkins Health Advisor BY Cloudbees | 14/5/2025 | 17/6/2026 | Jenkins Health Advisor by CloudBees Plugin 374.v194b_d4f0c8c8 and earlier does not escape responses from the Jenkins Health Advisor server, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control Jenkins Health Advisor server responses. | |
| Modificada | Media (6.5) | 1.2% | — | Jenkins Cloudbees CD | 25/10/2023 | 17/6/2026 | Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the directory from which artifacts are published during the 'CloudBees CD - Publish Artifact' post-build step, allowing attackers able to configure jobs to publish arbitrary files from the Jenkins controller file system to… | |
| Modificada | Alta (8.1) | 1.4% | — | Jenkins Cloudbees CD | 25/10/2023 | 17/6/2026 | Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the expected directory during the cleanup process of the 'CloudBees CD - Publish Artifact' post-build step, allowing attackers able to configure jobs to delete arbitrary files on the Jenkins controller file system. | |
| Modificada | Alta (7.5) | 0.60% | — | Jenkins Cloudbees Docker Hub/registry Notification | 15/11/2022 | 17/6/2026 | A missing permission check in Jenkins CloudBees Docker Hub/Registry Notification Plugin 2.6.2 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository. | |
| Modificada | Media (4.3) | 0.74% | — | Jenkins Cloudbees AWS Credentials | 15/3/2022 | 17/6/2026 | A missing permission check in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Overall/Read permission to connect to an AWS service using an attacker-specified token. | |
| Modificada | Alta (8) | 0.51% | — | Jenkins Cloudbees AWS Credentials | 15/3/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Overall/Read permission to connect to an AWS service using an attacker-specified token. | |
| Modificada | Media (4.3) | 1.5% | — | Jenkins Cloudbees CD | 21/4/2021 | 17/6/2026 | Jenkins CloudBees CD Plugin 1.1.21 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Item/Read permission to schedule builds of projects without having Item/Build permission. | |
| Modificada | Media (4.3) | 0.72% | — | Jenkins Cloudbees AWS Credentials | 18/3/2021 | 17/6/2026 | Jenkins CloudBees AWS Credentials Plugin 1.28 and earlier does not perform a permission check in a helper method for HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of AWS credentials stored in Jenkins in some circumstances. | |
| Modificada | Media (4.3) | 0.69% | — | Jenkins Health Advisor BY Cloudbees | 16/9/2020 | 17/6/2026 | Jenkins Health Advisor by CloudBees Plugin 3.2.0 and earlier does not correctly perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to view that HTTP endpoint. | |
| Modificada | Alta (7.5) | 3.4% | — | Cloudbees JenkinsJenkins | 24/2/2020 | 16/6/2026 | Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before 1.424.2.1 and 1.400.x before 1.400.0.11 could allow remote attackers to cause a considerable CPU load, aka "the Hash DoS attack." | |
| Modificada | Alta (7.5) | 1.4% | — | Jenkins Cloudbees | 15/1/2020 | 17/6/2026 | XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via a crafted XML document. | |
| Modificada | Alta (7.5) | 1.4% | — | Jenkins Cloudbees | 15/1/2020 | 17/6/2026 | XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via an XPath query. | |
| Modificada | Media (4.3) | 0.82% | — | Jenkins Health Advisor BY Cloudbees | 15/1/2020 | 17/6/2026 | A missing permission check in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers with Overall/Read permission to send a fixed email to an attacker-specific recipient. | |
| Modificada | Alta (8.8) | 0.84% | — | Jenkins Health Advisor BY Cloudbees | 15/1/2020 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers to send an email with fixed content to an attacker-specified recipient. | |
| Modificada | Crítica (9.8) | 1.8% | — | Cloudbees Jenkins Operations Center | 19/4/2019 | 17/6/2026 | CloudBees Jenkins Operations Center 2.150.2.3, when an expired trial license exists, allows Cleartext Password Storage and Retrieval via the proxy configuration page. | |
| Modificada | Media (6.8) | 1.6% | — | Cloudbees Jenkins | 14/5/2014 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1.466.x before 1.466.14.1 and 1.480.x before 1.480.4.1 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary code or (2) initiate deployment of… | |
| Modificada | Baja (2.1) | 1.9% | — | JenkinsCloudbees Jenkins | 10/4/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1.466.x before 1.466.14.1 and 1.480.x before 1.480.4.1 allows remote authenticated users with write permission to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (2.6) | 2.5% | — | Cloudbees JenkinsJenkins | 24/2/2013 | 16/6/2026 | Unspecified vulnerability in Jenkins before 1.498, Jenkins LTS before 1.480.2, and Jenkins Enterprise 1.447.x before 1.447.6.1 and 1.466.x before 1.466.12.1, when a slave is attached and anonymous read access is enabled, allows remote attackers to obtain the master cryptographic key via unknown vectors. | |
| Modificada | Baja (3.5) | 1.4% | — | Cloudbees JenkinsJenkins | 24/2/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x before 1.447.4.1, and 1.466.x before 1.466.10.1 allows remote authenticated users with write access to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.8) | 1.8% | — | Cloudbees JenkinsJenkins | 24/2/2013 | 16/6/2026 | Open redirect vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x before 1.447.4.1, and 1.466.x before 1.466.10.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Media (4.3) | 1.8% | — | Cloudbees JenkinsJenkins | 24/2/2013 | 16/6/2026 | CRLF injection vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x before 1.447.4.1, and 1.466.x before 1.466.10.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Cloudbees JenkinsJenkins | 9/3/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Jenkins before 1.454, Jenkins LTS before 1.424.5, and Jenkins Enterprise 1.400.x before 1.400.0.13 and 1.424.x before 1.424.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0324. | |
| Modificada | Media (4.3) | 1.1% | — | Cloudbees JenkinsJenkins | 9/3/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Jenkins before 1.454, Jenkins LTS before 1.424.5, and Jenkins Enterprise 1.400.x before 1.400.0.13 and 1.424.x before 1.424.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0325. |