Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2570▼ 329 respecto a la semana anterior
Críticas / altas1353▲ 95 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

7 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.81%—Jenkins Collabnet23/8/202217/6/2026
Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
ModificadaAlta (7.4)0.86%—Jenkins Collabnet26/6/201817/6/2026
A man in the middle vulnerability exists in Jenkins CollabNet Plugin 2.0.4 and earlier in CollabNetApp.java, CollabNetPlugin.java, CNFormFieldValidator.java that allows attackers to impersonate any service that Jenkins connects to.
ModificadaAlta (7.8)3.9%—Apache SubversionCollabnet SubversionCanonical Ubuntu LinuxOpensuse31/7/201316/6/2026
The svnserve server in Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote attackers to cause a denial of service (exit) by aborting a connection.
ModificadaAlta (7.1)31%—Apache SubversionCollabnet SubversionOpensuse31/7/201316/6/2026
contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacters in a filename.
ModificadaMedia (5.5)2.8%—Apache SubversionCollabnet SubversionCanonical Ubuntu LinuxOpensuse31/7/201316/6/2026
Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote authenticated users to cause a denial of service (FSFS repository corruption) via a newline character in a file name.
ModificadaMedia (6.5)1.7%—Collabnet Scrumworks8/6/201216/6/2026
The server in CollabNet ScrumWorks Pro before 6.0 allows remote authenticated users to gain privileges and obtain sensitive information via a modified desktop client.
ModificadaMedia (5)1.9%—Collabnet Scrumworks24/1/201116/6/2026
CollabNet ScrumWorks Basic 1.8.4 uses cleartext credentials for network communication and the internal database, which makes it easier for context-dependent attackers to obtain sensitive information by (1) sniffing the network for transmissions of Java objects or (2) reading the database.