Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2753▼ 55 respecto a la semana anterior
Críticas / altas1422▲ 195 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)106▼ 394 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.5) | 0.25% | — | Adobe Content CredentialsAI | 22/9/2026 | 23/9/2026 | CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a… | |
| Pendiente de análisis | Media (4.3) | 1.0% | — | CAI Content CredentialsAI | 22/9/2026 | 22/9/2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue requires user interaction in that a victim… | |
| En análisis | Media (6.5) | 1.3% | — | CAI Content CredentialsAI | 22/9/2026 | 25/9/2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must… | |
| En análisis | Media (4.3) | 1.0% | — | CAI Content CredentialsAI | 22/9/2026 | 22/9/2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue requires user interaction in that a victim… | |
| En análisis | Media (5.5) | 0.24% | — | CAI Content CredentialsAI | 22/9/2026 | 26/9/2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim… | |
| En análisis | Alta (7.5) | 0.90% | — | CAI Content CredentialsAI | 22/9/2026 | 23/9/2026 | CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user… | |
| En análisis | Alta (7.5) | 0.65% | — | CAI Content CredentialsAI | 22/9/2026 | 22/9/2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction. | |
| Pendiente de análisis | Baja (3.7) | 0.27% | — | Jenkins Webhook Secret Credentials Provider PluginAI | 5/8/2026 | 31/8/2026 | Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison function when checking whether the provided and expected webhook bearer token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook bearer token. | |
| Analizada | Alta (7.5) | 0.58% | — | Jenkins Credentials Binding | 27/5/2026 | 17/6/2026 | Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file and zip file credentials, allowing attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem, which can lead to remote code execution if Jenkins is… | |
| Aplazada | Media (5.3) | 0.26% | — | Amazon CredentialsAI | 11/5/2026 | 17/6/2026 | Amazon::Credentials versions through 1.2.0 for Perl uses rand to generate encryption keys. Amazon::Credentials stores credentials in an obfuscated form to prevent access to the secrets from a data dump of the object. Before version 1.3.0, the secrets were encrypted using a 64-bit key that was generated using the… | |
| Analizada | Alta (7.5) | 0.60% | — | Jenkins Credentials Binding | 29/4/2026 | 17/6/2026 | Jenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanitize file names for file and zip file credentials, allowing attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem, which can lead to remote code execution if Jenkins is configured to… | |
| Modificada | Alta (7.3) | 0.36% | — | Jenkins Credentials Binding | 9/7/2025 | 17/6/2026 | Jenkins Credentials Binding Plugin 687.v619cb_15e923f and earlier does not properly mask (i.e., replace with asterisks) credentials present in exception error messages that are written to the build log. | |
| Analizada | Media (6.5) | 0.35% | — | IBM Verify Identity Access Digital Credentials | 6/6/2025 | 17/6/2026 | IBM Verify Identity Access Digital Credentials 24.06 could allow an authenticated user to crash the service with a specially crafted POST request. | |
| Analizada | Media (5.3) | 0.32% | — | IBM Verify Identity Access Digital Credentials | 6/6/2025 | 17/6/2026 | IBM Verify Identity Access Digital Credentials 24.06 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | |
| Modificada | Alta (7.5) | 0.59% | — | Jenkins Credentials | 2/10/2024 | 17/6/2026 | Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type when accessing item `config.xml` via REST API or CLI. | |
| Analizada | Media (4.3) | 0.42% | — | Jenkins Plain Credentials | 26/6/2024 | 17/6/2026 | In rare cases Jenkins Plain Credentials Plugin 182.v468b_97b_9dcb_8 and earlier stores secret file credentials unencrypted (only Base64 encoded) on the Jenkins controller file system, where they can be viewed by users with access to the Jenkins controller file system (global credentials) or with Item/Extended Read… | |
| Modificada | Media (6.5) | 0.64% | — | Jenkins Azure Credentials | 15/2/2023 | 17/6/2026 | A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overall/Read permission to connect to an attacker-specified web server. | |
| Modificada | Alta (8.8) | 0.46% | — | Jenkins Azure Credentials | 15/2/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers to connect to an attacker-specified web server. | |
| Modificada | Media (4.3) | 0.51% | — | Jenkins Azure Credentials | 15/2/2023 | 17/6/2026 | A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Modificada | Media (6.5) | 0.82% | — | Jenkins Kubernetes Credentials Provider | 26/1/2023 | 17/6/2026 | Jenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for Kubernetes credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Kubernetes credentials they are not entitled to. | |
| Modificada | Media (5.4) | 78% | — | Jenkins Credentials | 12/4/2022 | 17/6/2026 | Jenkins Credentials Plugin 1111.v35a_307992395 and earlier, except 1087.1089.v2f1b_9a_b_040e4, 1074.1076.v39c30cecb_0e2, and 2.6.1.1, does not escape the name and description of Credentials parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by… | |
| Modificada | Media (4.3) | 0.74% | — | Jenkins Cloudbees AWS Credentials | 15/3/2022 | 17/6/2026 | A missing permission check in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Overall/Read permission to connect to an AWS service using an attacker-specified token. | |
| Modificada | Alta (8) | 0.51% | — | Jenkins Cloudbees AWS Credentials | 15/3/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Overall/Read permission to connect to an AWS service using an attacker-specified token. | |
| Modificada | Media (4.3) | 0.85% | — | Jenkins Credentials Binding | 12/1/2022 | 17/6/2026 | Jenkins Credentials Binding Plugin 1.27 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read access to validate if a credential ID refers to a secret file credential and whether it's a zip file. | |
| Modificada | Media (6.1) | 11% | — | Jenkins Credentials | 11/5/2021 | 17/6/2026 | Jenkins Credentials Plugin 2.3.18 and earlier does not escape user-controlled information on a view it provides, resulting in a reflected cross-site scripting (XSS) vulnerability. |