Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 329 respecto a la semana anterior
Críticas / altas1353▲ 95 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.81% | — | Jenkins Collabnet | 23/8/2022 | 17/6/2026 | Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Alta (7.4) | 0.86% | — | Jenkins Collabnet | 26/6/2018 | 17/6/2026 | A man in the middle vulnerability exists in Jenkins CollabNet Plugin 2.0.4 and earlier in CollabNetApp.java, CollabNetPlugin.java, CNFormFieldValidator.java that allows attackers to impersonate any service that Jenkins connects to. | |
| Modificada | Alta (7.8) | 3.9% | — | Apache SubversionCollabnet SubversionCanonical Ubuntu LinuxOpensuse | 31/7/2013 | 16/6/2026 | The svnserve server in Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote attackers to cause a denial of service (exit) by aborting a connection. | |
| Modificada | Alta (7.1) | 31% | — | Apache SubversionCollabnet SubversionOpensuse | 31/7/2013 | 16/6/2026 | contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacters in a filename. | |
| Modificada | Media (5.5) | 2.8% | — | Apache SubversionCollabnet SubversionCanonical Ubuntu LinuxOpensuse | 31/7/2013 | 16/6/2026 | Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote authenticated users to cause a denial of service (FSFS repository corruption) via a newline character in a file name. | |
| Modificada | Media (6.5) | 1.7% | — | Collabnet Scrumworks | 8/6/2012 | 16/6/2026 | The server in CollabNet ScrumWorks Pro before 6.0 allows remote authenticated users to gain privileges and obtain sensitive information via a modified desktop client. | |
| Modificada | Media (5) | 1.9% | — | Collabnet Scrumworks | 24/1/2011 | 16/6/2026 | CollabNet ScrumWorks Basic 1.8.4 uses cleartext credentials for network communication and the internal database, which makes it easier for context-dependent attackers to obtain sensitive information by (1) sniffing the network for transmissions of Java objects or (2) reading the database. |