Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2630▼ 308 respecto a la semana anterior
Críticas / altas1351▲ 88 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

38 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.5)1.0%—RenovateAIApache MavenAI10/9/202629/9/2026
Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attackers can inject shell commands through unescaped distributionType values to achieve…
AplazadaBaja (1.1)0.11%—Antlr4AIAntlr4-maven-pluginAI28/6/202629/6/2026
A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the function ObjectInputStream.readObject of the file antlr4-maven-plugin/src/main/java/org/antlr/mojo/antlr4/GrammarDependencies.java of the component Maven Plugin. This manipulation causes time-of-check time-of-use. The attack is restricted to local…
Pendiente de análisisBaja (1.6)0.13%—Vaadin Flow Maven PluginAIVaadin Flow Gradle PluginAIVaadin Flow Plugin BaseAI19/5/202614/9/2026
A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes the full set of environment variables in build logs whenever the frontend build process exits with a non-zero status. Because the build environment may contain credentials supplied as secrets, any…
AplazadaBaja (2.3)0.53%—Openapi-to-java-records-mustache-templatesAIApache Maven-dependency-pluginAI18/3/202617/6/2026
openapi-to-java-records-mustache-templates allows users to generate Java Records from OpenAPI specifications. Starting in version 5.1.1 and prior to version 5.5.1, the parent POM file of this project (`openapi-to-java-records-mustache-templates-parent`), which is used to centralize plugin configurations for multiple…
AplazadaMedia (4.3)0.14%—UsermavenAI28/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in usermaven Usermaven usermaven allows Cross Site Request Forgery.This issue affects Usermaven: from n/a through <= 1.2.1.
AplazadaBaja (3.5)0.60%—Mavenir SCE Application Provisioning PortalAI12/2/202517/6/2026
A directory traversal vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_24_0, which allows an administrative user to access system files with the file permissions of the privileged system user running the application.
AplazadaAlta (8.8)0.39%—Mavenir SCE Application Provisioning PortalAI12/2/202517/6/2026
An authorization bypass vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_24_0, which allows an authenticated 'guest' user to perform unauthorized administrative actions, such as accessing the 'add user' feature, by bypassing client-side access controls.
ModificadaAlta (7.5)0.84%—Apache Maven Archetype26/9/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in Maven Archetype Plugin. This issue affects Maven Archetype Plugin: from 3.2.1 before 3.3.0. Users are recommended to upgrade to version 3.3.0, which fixes the issue. Archetype integration testing…
ModificadaMedia (5.3)0.65%—Jenkins Pipeline Maven Integration6/9/202317/6/2026
Jenkins Pipeline Maven Integration Plugin 1330.v18e473854496 and earlier does not properly mask (i.e., replace with asterisks) usernames of credentials specified in custom Maven settings in Pipeline build logs if "Treat username as secret" is checked.
ModificadaMedia (6.5)0.67%—Jenkins Maven Artifact Choicelistprovider (nexus)16/8/202317/6/2026
Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.14 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.
ModificadaMedia (5.4)0.62%—Jenkins Maven Repository Server14/6/202317/6/2026
Jenkins Maven Repository Server Plugin 1.10 and earlier does not escape project and build display names on the Build Artifacts As Maven Repository page, resulting in a stored cross-site scripting (XSS) vulnerability.
ModificadaMedia (5.4)0.62%—Jenkins Maven Repository Server14/6/202317/6/2026
Jenkins Maven Repository Server Plugin 1.10 and earlier does not escape the versions of build artifacts on the Build Artifacts As Maven Repository page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control maven project versions in `pom.xml`.
ModificadaMedia (6.3)3.1%—Snyk CLISnyk Cocoapods CLISnyk Docker CLISnyk Gradle CLI+430/11/202217/6/2026
The package snyk before 1.1064.0; the package snyk-mvn-plugin before 2.31.3; the package snyk-gradle-plugin before 3.24.5; the package @snyk/snyk-cocoapods-plugin before 2.5.3; the package snyk-sbt-plugin before 2.16.2; the package snyk-python-plugin before 1.24.2; the package snyk-docker-plugin before 5.6.5; the…
ModificadaMedia (5.4)0.63%—Jenkins Maven Metadata27/7/202217/6/2026
Jenkins Maven Metadata Plugin for Jenkins CI server Plugin 2.2 and earlier does not perform URL validation for the Repository Base URL of List maven artifact versions parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
ModificadaMedia (5.4)0.64%—Jenkins Maven Metadata23/6/202217/6/2026
Jenkins Maven Metadata Plugin for Jenkins CI server Plugin 2.1 and earlier does not escape the name and description of List maven artifact versions parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
ModificadaCrítica (9.8)4.4%—Apache Maven Shared UtilsDebian Linux23/5/202217/6/2026
In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.
ModificadaCrítica (9.1)8.7%—Apache MavenQuarkusOracle Financial Services Analytical Applications InfrastructureOracle Goldengate BIG Data AND Application Adapters23/4/202117/6/2026
Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the…
ModificadaAlta (7.8)62%—Microsoft Vscode-maven13/4/202117/6/2026
Visual Studio Code Maven for Java Extension Remote Code Execution Vulnerability
ModificadaAlta (7.8)62%—Microsoft Maven FOR Java11/3/202119/8/2026
Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability
ModificadaMedia (6.5)1.4%—Gradle Enterprise Test Distribution AgentGradle MavenGradle Test Distribution9/2/202117/6/2026
A directory traversal issue was discovered in Gradle gradle-enterprise-test-distribution-agent before 1.3.2, test-distribution-gradle-plugin before 1.3.2, and gradle-enterprise-maven-extension before 1.8.2. A malicious actor (with certain credentials) can perform a registration step such that crafted TAR archives lead…
ModificadaAlta (7.8)0.58%—Redhat Fabric8-maven22/10/202017/6/2026
A flaw was found in the fabric8-maven-plugin 4.0.0 and later. When using a wildfly-swarm or thorntail custom configuration, a malicious YAML configuration file on the local machine executing the maven plug-in could allow for deserialization of untrusted data resulting in arbitrary code execution. The highest threat…
ModificadaMedia (6.5)0.54%—Barchart Maven Cascade Release8/10/202017/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Maven Cascade Release Plugin 1.3.2 and earlier allows attackers to start cascade builds and layout builds, and reconfigure the plugin.
ModificadaMedia (6.5)0.81%—Barchart Maven Cascade Release8/10/202017/6/2026
Jenkins Maven Cascade Release Plugin 1.3.2 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to start cascade builds and layout builds, and reconfigure the plugin.
ModificadaMedia (5.4)0.73%—Jenkins Pipeline Maven Integration16/9/202017/6/2026
Jenkins Pipeline Maven Integration Plugin 3.9.2 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
ModificadaAlta (7.8)1.0%—Gradle Maven25/8/202017/6/2026
An issue was discovered in the Maven Extension plugin before 1.6 for Gradle Enterprise. The extension uses a socket connection to send serialized Java objects. Deserialization is not restricted to an allow-list, thus allowing an attacker to achieve code execution via a malicious deserialization gadget chain. The…