Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2567▼ 333 respecto a la semana anterior
Críticas / altas1341▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
–

35 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8)0.41%—Jenkins Sonarqube ScannerAISonarsource SonarqubeAI2/9/20263/9/2026
Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard links it creates based on SonarQube scanner results, allowing the `javascript:` scheme, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
AplazadaAlta (7.9)1.9%—Qubes Core-admin-linuxAI30/8/20268/9/2026
Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, because the "system" library function is used to process an error message that may have shell metacharacters. This occurs in core-admin-linux/file-copy-vm/qfile-dom0-agent.c.
AplazadaMedia (4.8)0.22%—Themeum QubelyAI23/7/202623/7/2026
Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.
AplazadaMedia (5.9)0.24%—Themeum QubelyAI8/4/202624/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Qubely qubely allows Stored XSS.This issue affects Qubely: from n/a through <= 1.8.14.
AplazadaAlta (8.5)0.14%—Sonarsource SonarqubeAI29/1/202617/6/2026
SonarQube 8.3.1 contains an unquoted service path vulnerability that allows local attackers to gain SYSTEM privileges by exploiting the service executable path. Attackers can replace the wrapper.exe in the service path with a malicious executable to execute code with highest system privileges during service restart.
AplazadaMedia (4.3)0.22%—Sonarsource SonarqubeAI10/10/202517/6/2026
In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/users-management/users endpoint and obtain user fields intended for administrators only, including the email addresses of other accounts.
AplazadaAlta (7.7)1.5%—Sonarqube Github ActionAI26/9/202517/6/2026
SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. A command injection vulnerability exists in SonarQube GitHub Action in version 4.0.0 to before version 6.0.0 when workflows pass user-controlled input to the args parameter on Windows runners without proper…
AplazadaMedia (4.3)0.24%—Themeum QubelyAI22/9/202517/6/2026
Missing Authorization vulnerability in Themeum Qubely qubely allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Qubely: from n/a through <= 1.8.14.
AplazadaMedia (4.3)0.27%—Themeum QubelyAI22/9/202517/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Themeum Qubely qubely allows Retrieve Embedded Sensitive Data.This issue affects Qubely: from n/a through <= 1.8.14.
AplazadaAlta (7.8)1.1%—Sonarqube ServerAISonarqube CloudAISonarqube Scan Github ActionAI2/9/202517/6/2026
SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. In versions 4 to 5.3.0, a command injection vulnerability was discovered in the SonarQube Scan GitHub Action that allows untrusted input arguments to be processed without proper sanitization. Arguments sent to…
AnalizadaMedia (6.5)0.37%—Themeum Qubely11/3/202517/6/2026
The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.13 via the 'qubely_get_content'. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending,…
ModificadaMedia (5.4)0.22%—Themeum Qubely16/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Qubely qubely allows Stored XSS.This issue affects Qubely: from n/a through <= 1.8.12.
ModificadaMedia (5.4)0.33%—Themeum Qubely14/2/202517/6/2026
The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ and 'UniqueID' parameter in all versions up to, and including, 1.8.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AnalizadaAlta (7.2)0.45%—Sonarsource Sonarqube4/10/202417/6/2026
In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-memberships API endpoint that allows SonarQube users with the administrator role to inject blind SQL commands.
AplazadaAlta (7.2)0.48%—Sonarsource SonarqubeAI4/10/202417/6/2026
An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5. A SonarQube user with the Administrator role can modify an existing configuration of a GitHub integration to exfiltrate a pre-signed JWT.
ModificadaMedia (6.5)0.33%—Sonarsource Sonarqube16/6/202417/6/2026
In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part of the URL parameters in the logs (such as SonarQube Access Logs, Proxy Logs, etc).
AplazadaAlta (7.6)0.69%—Qube ONE LTD Wpcf7 RedirectAI17/5/202417/6/2026
Improper Privilege Management vulnerability in Qube One Ltd. Redirection for Contact Form 7 wpcf7-redirect allows Privilege Escalation.This issue affects Redirection for Contact Form 7: from n/a through 2.7.0.
ModificadaMedia (5.4)0.74%—Themeum Qubely16/1/202417/6/2026
The Qubely WordPress plugin before 1.8.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaAlta (7.5)1.7%—Themeum Qubely7/8/202317/6/2026
The Qubely WordPress plugin before 1.8.6 allows unauthenticated user to send arbitrary e-mails to arbitrary addresses via the qubely_send_form_data AJAX action.
ModificadaAlta (7.5)0.97%—Xerox Colorqube 8580 Firmware4/4/202217/6/2026
Xerox ColorQube 8580 was discovered to contain an access control issue which allows attackers to print, view the status, and obtain sensitive information.
ModificadaMedia (6.5)0.43%—Themeum Qubely24/1/202217/6/2026
The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure that the block to be deleted belong to the plugin, as a result, any authenticated users, such as subscriber can delete arbitrary posts
ModificadaCrítica (9.8)2.2%—Sonarsource Sonarqube Docker Image16/12/202017/6/2026
The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user. System using the sonarqube docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
ModificadaMedia (5.3)1.1%—Sonarsource Sonarqube2/11/202017/6/2026
In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner. With an empty value for the -D sonar.login option, anonymous authentication is forced. This allows creating and overwriting public and private projects via the /api/ce/submit endpoint.
ModificadaAlta (7.5)16%—Sonarsource Sonarqube28/10/202017/6/2026
SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for SMTP and SVN is "it is the administrator's responsibility to configure it.
ModificadaCrítica (9.8)1.2%—Xerox Colorqube 9201 FirmwareXerox Colorqube 9202 FirmwareXerox Colorqube 9203 FirmwareXerox Workcentre 6400 Firmware+813/2/202017/6/2026
Xerox ColorCube and WorkCenter devices in 2013 had hardcoded FTP and shell user accounts.