Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2636▼ 272 respecto a la semana anterior
Críticas / altas1349▲ 92 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
120 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.2) | 0.23% | — | Jenkins Pipeline Groovy LibrariesAIJenkins PipelineAI | 16/9/2026 | 18/9/2026 | Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to the library Pipeline step to a relative path inside the SCM checkout, and follows symbolic links to locations outside of the SCM checkout when retrieving the library, resulting in a path traversal… | |
| Pendiente de análisis | Baja (3.1) | 0.22% | — | Jenkins Pipeline Multibranch PluginAI | 16/9/2026 | 18/9/2026 | Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials lookup in the resolveScm Pipeline step, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to. | |
| Pendiente de análisis | Media (6.5) | 0.59% | — | Pipelines-as-codeAITektonAI | 15/9/2026 | 30/9/2026 | Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, a GitHub App installation token created during webhook processing is not scoped to the repository that triggered the event when the App is installed across multiple… | |
| Pendiente de análisis | Alta (8.2) | 0.27% | — | Cd.foundation Pipelines AS CodeAI | 15/9/2026 | 30/9/2026 | Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the GitHub App provider accepts X-GitHub-Enterprise-Host as the API host while processing webhook events containing an installation.id, before webhook signature… | |
| Pendiente de análisis | Media (5.4) | 0.14% | — | JenkinsAIJenkins Pipeline Groovy LibrariesAI | 2/9/2026 | 3/9/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 798.v5cc688825312 and earlier allows attackers to delete shared library caches. | |
| Pendiente de análisis | Media (5.4) | 0.36% | — | Jenkins Pipeline Build StepAI | 2/9/2026 | 3/9/2026 | A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes downstream builds awaited by the `waitForBuild` step when the `propagateAbort` parameter is used to be canceled even when the build's authentication lacks Item/Cancel permission on the downstream job. | |
| Pendiente de análisis | Media (5.4) | 0.36% | — | Jenkins Pipeline Build StepAIJenkins PipelineAI | 2/9/2026 | 3/9/2026 | A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes downstream builds triggered by the `build` step to be canceled even when the build's authentication lacks Item/Cancel permission on the downstream job. | |
| Aplazada | Crítica (10) | 0.62% | — | Kubeflow PipelinesAI | 28/8/2026 | 9/9/2026 | Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ route in frontend/server/proxy-middleware.ts. The _routePathWithReferer()… | |
| Pendiente de análisis | Alta (7.6) | 0.51% | — | Data Science PipelinesAIArgoproj Argo WorkflowsAI | 10/8/2026 | 8/9/2026 | A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of the attacker.… | |
| Pendiente de análisis | Alta (7.1) | 0.48% | — | Kubeflow Data Science PipelinesAI | 10/8/2026 | 21/9/2026 | A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServiceAccount function. By specifying a more privileged ServiceAccount (SA) during a CreateRun request, an attacker can bypass authorization checks. This allows the tenant to… | |
| Pendiente de análisis | Alta (8.8) | 0.73% | — | Data Science Pipelines OperatorAIMysqlAI | 10/8/2026 | 21/9/2026 | A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for the injection of dangerous parameters into the MySQL Data Source Name (DSN) string. By manipulating these parameters, an attacker can enable… | |
| Pendiente de análisis | Alta (7.5) | 0.61% | — | MariadbAIMinioAIRedhat Data Science Pipelines OperatorAI | 10/8/2026 | 21/9/2026 | A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive sensitive credentials, such as MariaDB root/user passwords and MinIO access/secret keys, if they can access the MinIO Route or MariaDB Service. The flaw occurs because the operator uses a… | |
| Pendiente de análisis | Alta (8.7) | 0.70% | — | Kubeflow Data Science Pipelines OperatorAI | 10/8/2026 | 21/9/2026 | A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the ability to execute commands within pods and manage cluster-wide roles, could be… | |
| Analizada | Media (4.3) | 0.34% | — | Jenkins Pipeline\ | 24/6/2026 | 26/6/2026 | Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through the Pipeline Snippet Generator, allowing attackers to instantiate types related to job or system configuration other than Pipeline steps. | |
| Analizada | Media (4.3) | 0.24% | — | Jenkins Pipeline\ | 24/6/2026 | 26/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier allows attackers to instantiate types related to job or system configuration other than Pipeline steps through the Pipeline Snippet Generator. | |
| Pendiente de análisis | Alta (7.1) | 0.22% | — | Openshift Pipelines OperatorAITektonAIKueueAICert-managerAI | 4/6/2026 | 6/9/2026 | A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. When Kueue or cert-manager CRDs are present on the cluster, any… | |
| Analizada | Alta (7.5) | 0.43% | — | Jenkins Pipeline\ | 27/5/2026 | 17/6/2026 | Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers able to control the content of a library used by a Pipeline job to read arbitrary files on the Jenkins controller filesystem. | |
| Modificada | Alta (8.5) | 0.90% | — | Linuxfoundation Tekton Pipelines | 21/4/2026 | 24/8/2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the git resolver's revision parameter is passed directly as a positional argument to git fetch without any validation that it does not begin… | |
| Modificada | Media (6.5) | 0.47% | — | Linuxfoundation Tekton Pipelines | 21/4/2026 | 17/6/2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the HTTP resolver's FetchHttpResource function calls io.ReadAll(resp.Body) with no response body size limit. Any tenant with permission to… | |
| Modificada | Media (5.4) | 0.32% | — | Linuxfoundation Tekton Pipelines | 21/4/2026 | 17/6/2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, a validation bypass in the VolumeMount path restriction allows mounting volumes under restricted /tekton/ internal paths by using .. path… | |
| Modificada | Media (6.5) | 0.43% | — | Linuxfoundation Tekton Pipelines | 21/4/2026 | 17/6/2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the Tekton Pipelines git resolver in API mode sends the system-configured Git API token to a user-controlled serverURL when the user omits… | |
| Modificada | Media (6.5) | 0.39% | — | Linuxfoundation Tekton Pipelines | 21/4/2026 | 17/6/2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 0.43.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, trusted resources verification policies match a resource source string (refSource.URI) against spec.resources[].pattern using… | |
| Modificada | Crítica (9.6) | 0.70% | — | Linuxfoundation Tekton Pipelines | 24/3/2026 | 7/9/2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter. A tenant with permission to create… | |
| Analizada | Media (6.5) | 0.45% | — | Linuxfoundation Tekton Pipelines | 20/3/2026 | 17/6/2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Versions 0.60.0 through 1.0.0, 1.1.0 through 1.3.2, 1.4.0 through 1.6.0, 1.7.0 through 1.9.0, 1.10.0, and 1.10.1 have a denial-of-service vulnerability in that allows any user who can create a TaskRun or PipelineRun to crash the… | |
| Analizada | Media (4.3) | 0.34% | — | Jenkins Redpen - Pipeline Reporter FOR Jira | 10/12/2025 | 17/6/2026 | Jenkins Redpen - Pipeline Reporter for Jira Plugin 1.054.v7b_9517b_6b_202 and earlier does not correctly perform path validation of the workspace directory while uploading artifacts to Jira, allowing attackers with Item/Configure permission to retrieve files present on the Jenkins controller workspace directory. |