Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2667▼ 241 respecto a la semana anterior
Críticas / altas1361▲ 103 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.39% | — | KojiAI | 20/8/2026 | 20/8/2026 | Unauthenticated Broken Access Control in Koji <= 2.2.1 versions. | |
| Aplazada | Media (5.4) | 0.29% | — | KojiAI | 24/12/2024 | 17/6/2026 | A vulnerability in Koji was found. An unsanitized input allows for an XSS attack. Javascript code from a malicious link could be reflected in the resulting web page. It is not expected to be able to submit an action or make a change in Koji due to existing XSS protections in the code | |
| Modificada | Media (6.5) | 2.8% | — | Koji Project Koji | 9/10/2019 | 17/6/2026 | Koji through 1.18.0 allows remote Directory Traversal, with resultant Privilege Escalation. | |
| Modificada | Media (5.9) | 1.5% | — | Jenkins Koji | 30/4/2019 | 17/6/2026 | Jenkins Koji Plugin disables SSL/TLS and hostname verification globally for the Jenkins master JVM. | |
| Modificada | Alta (8.8) | 1.7% | — | Jenkins Koji | 4/4/2019 | 17/6/2026 | Jenkins Koji Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | |
| Modificada | Crítica (9.1) | 1.7% | — | Koji Project Koji | 4/4/2018 | 17/6/2026 | Koji version 1.12, 1.13, 1.14 and 1.15 contain an incorrect access control vulnerability resulting in arbitrary filesystem read/write access. This vulnerability has been fixed in versions 1.12.1, 1.13.1, 1.14.1 and 1.15.1. | |
| Modificada | Alta (7.5) | 1.2% | — | Koji Project Koji | 6/10/2017 | 17/6/2026 | Koji 1.13.0 does not properly validate SCM paths, allowing an attacker to work around blacklisted paths for build submission. |