Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2546▼ 402 respecto a la semana anterior
Críticas / altas1312▲ 29 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.2) | 0.23% | — | Jenkins Pipeline Groovy LibrariesAIJenkins PipelineAI | 16/9/2026 | 18/9/2026 | Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to the library Pipeline step to a relative path inside the SCM checkout, and follows symbolic links to locations outside of the SCM checkout when retrieving the library, resulting in a path traversal… | |
| Pendiente de análisis | Media (5.4) | 0.14% | — | JenkinsAIJenkins Pipeline Groovy LibrariesAI | 2/9/2026 | 3/9/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 798.v5cc688825312 and earlier allows attackers to delete shared library caches. | |
| Aplazada | Media (4.3) | 0.14% | — | Grooni Groovy MenuAI | 26/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in grooni Groovy Menu groovy-menu-free allows Cross Site Request Forgery.This issue affects Groovy Menu: from n/a through <= 1.4.3. | |
| Modificada | Crítica (9.9) | 1.2% | — | Jenkins Groovy Libraries | 19/10/2022 | 17/6/2026 | A sandbox bypass vulnerability in Jenkins Pipeline: Deprecated Groovy Libraries Plugin 583.vf3b_454e43966 and earlier allows attackers with permission to define untrusted Pipeline libraries and to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the… | |
| Modificada | Crítica (9.9) | 1.3% | — | Jenkins Groovy Libraries | 19/10/2022 | 17/6/2026 | A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 612.v84da_9c54906d and earlier allows attackers with permission to define untrusted Pipeline libraries and to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of… | |
| Modificada | Media (5.5) | 1.0% | — | Apache GroovyNetapp SnapcenterOracle Agile Engineering Data ManagementOracle Agile PLM Mcad Connector+17 | 7/12/2020 | 25/8/2026 | Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods… | |
| Modificada | Media (5.9) | 0.72% | — | Diffplug Eclipse-cdtDiffplug Eclipse-groovyDiffplug Eclipse-wtp | 5/9/2019 | 17/6/2026 | In all versions prior to version 3.9.6 for eclipse-wtp, all versions prior to version 9.4.4 for eclipse-cdt, and all versions prior to version 3.0.1 for eclipse-groovy, Spotless was resolving dependencies over an insecure channel (http). If the build occurred over an insecure connection, a malicious user could have… | |
| Modificada | Alta (8.8) | 2.5% | — | Jenkins Groovy | 8/3/2019 | 17/6/2026 | A sandbox bypass vulnerability exists in Jenkins Groovy Plugin 2.1 and earlier in pom.xml, src/main/java/hudson/plugins/groovy/StringScriptSource.java that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JVM. | |
| Modificada | Alta (8.8) | 1.6% | — | Jenkins Groovy | 6/2/2019 | 17/6/2026 | A sandbox bypass vulnerability exists in Jenkins Groovy Plugin 2.0 and earlier in src/main/java/hudson/plugins/groovy/StringScriptSource.java that allows attackers with Overall/Read permission to provide a Groovy script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM. | |
| Modificada | Media (5.4) | 0.72% | — | Jenkins Groovy Postbuild | 5/6/2018 | 17/6/2026 | A persisted cross-site scripting vulnerability exists in Jenkins Groovy Postbuild Plugin 2.3.1 and older in various Jelly files that allows attackers able to control build badge content to define JavaScript that would be executed in another user's browser when that other user performs some UI actions. | |
| Modificada | Crítica (9.8) | 17% | — | Apache GroovyRedhat Enterprise Linux Server | 18/1/2018 | 17/6/2026 | When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java serialization mechanisms, e.g. to communicate between servers or to store local data, it was possible for an attacker to bake a special serialized object that will execute… | |
| Modificada | Alta (7.5) | 5.7% | — | Apache Groovy Ldap | 18/1/2017 | 17/6/2026 | main/java/org/apache/directory/groovyldap/LDAP.java in the Groovy LDAP API in Apache allows attackers to conduct LDAP entry poisoning attacks by leveraging setting returnObjFlag to true for all search methods. | |
| Modificada | Crítica (9.8) | 41% | — | Apache GroovyOracle Health Sciences Clinical Development CenterOracle Retail Order Broker Cloud ServiceOracle Retail Service Backbone+2 | 13/8/2015 | 17/6/2026 | The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object. | |
| Modificada | Media (6.8) | 3.6% | — | Bestwebsharing Groovy Media Player | 16/4/2013 | 16/6/2026 | Buffer overflow in Groovy Media Player 3.2.0 allows remote attackers to execute arbitrary code via a long string in a .m3u file. | |
| Modificada | Media (6.8) | 3.0% | — | Bestwebsharing Groovy Media Player | 12/7/2010 | 16/6/2026 | Stack-based buffer overflow in Groovy Media Player 1.1.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .m3u playlist file. |