Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2546▼ 402 respecto a la semana anterior
Críticas / altas1312▲ 29 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (4.2)0.23%—Jenkins Pipeline Groovy LibrariesAIJenkins PipelineAI16/9/202618/9/2026
Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to the library Pipeline step to a relative path inside the SCM checkout, and follows symbolic links to locations outside of the SCM checkout when retrieving the library, resulting in a path traversal…
Pendiente de análisisMedia (5.4)0.14%—JenkinsAIJenkins Pipeline Groovy LibrariesAI2/9/20263/9/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 798.v5cc688825312 and earlier allows attackers to delete shared library caches.
AplazadaMedia (4.3)0.14%—Grooni Groovy MenuAI26/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in grooni Groovy Menu groovy-menu-free allows Cross Site Request Forgery.This issue affects Groovy Menu: from n/a through <= 1.4.3.
ModificadaCrítica (9.9)1.2%—Jenkins Groovy Libraries19/10/202217/6/2026
A sandbox bypass vulnerability in Jenkins Pipeline: Deprecated Groovy Libraries Plugin 583.vf3b_454e43966 and earlier allows attackers with permission to define untrusted Pipeline libraries and to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the…
ModificadaCrítica (9.9)1.3%—Jenkins Groovy Libraries19/10/202217/6/2026
A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 612.v84da_9c54906d and earlier allows attackers with permission to define untrusted Pipeline libraries and to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of…
ModificadaMedia (5.5)1.0%—Apache GroovyNetapp SnapcenterOracle Agile Engineering Data ManagementOracle Agile PLM Mcad Connector+177/12/202025/8/2026
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods…
ModificadaMedia (5.9)0.72%—Diffplug Eclipse-cdtDiffplug Eclipse-groovyDiffplug Eclipse-wtp5/9/201917/6/2026
In all versions prior to version 3.9.6 for eclipse-wtp, all versions prior to version 9.4.4 for eclipse-cdt, and all versions prior to version 3.0.1 for eclipse-groovy, Spotless was resolving dependencies over an insecure channel (http). If the build occurred over an insecure connection, a malicious user could have…
ModificadaAlta (8.8)2.5%—Jenkins Groovy8/3/201917/6/2026
A sandbox bypass vulnerability exists in Jenkins Groovy Plugin 2.1 and earlier in pom.xml, src/main/java/hudson/plugins/groovy/StringScriptSource.java that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JVM.
ModificadaAlta (8.8)1.6%—Jenkins Groovy6/2/201917/6/2026
A sandbox bypass vulnerability exists in Jenkins Groovy Plugin 2.0 and earlier in src/main/java/hudson/plugins/groovy/StringScriptSource.java that allows attackers with Overall/Read permission to provide a Groovy script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.
ModificadaMedia (5.4)0.72%—Jenkins Groovy Postbuild5/6/201817/6/2026
A persisted cross-site scripting vulnerability exists in Jenkins Groovy Postbuild Plugin 2.3.1 and older in various Jelly files that allows attackers able to control build badge content to define JavaScript that would be executed in another user's browser when that other user performs some UI actions.
ModificadaCrítica (9.8)17%—Apache GroovyRedhat Enterprise Linux Server18/1/201817/6/2026
When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java serialization mechanisms, e.g. to communicate between servers or to store local data, it was possible for an attacker to bake a special serialized object that will execute…
ModificadaAlta (7.5)5.7%—Apache Groovy Ldap18/1/201717/6/2026
main/java/org/apache/directory/groovyldap/LDAP.java in the Groovy LDAP API in Apache allows attackers to conduct LDAP entry poisoning attacks by leveraging setting returnObjFlag to true for all search methods.
ModificadaCrítica (9.8)41%—Apache GroovyOracle Health Sciences Clinical Development CenterOracle Retail Order Broker Cloud ServiceOracle Retail Service Backbone+213/8/201517/6/2026
The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.
ModificadaMedia (6.8)3.6%—Bestwebsharing Groovy Media Player16/4/201316/6/2026
Buffer overflow in Groovy Media Player 3.2.0 allows remote attackers to execute arbitrary code via a long string in a .m3u file.
ModificadaMedia (6.8)3.0%—Bestwebsharing Groovy Media Player12/7/201016/6/2026
Stack-based buffer overflow in Groovy Media Player 1.1.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .m3u playlist file.