Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2628▼ 312 respecto a la semana anterior
Críticas / altas1351▲ 89 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.6) | 0.51% | — | RundeckAI | 16/9/2026 | 24/9/2026 | Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project archive import endpoint. Attackers with only the import action can replace project configuration files including security-relevant settings like node executors and SSH key paths that affect job execution. | |
| Modificada | Media (5.4) | 0.45% | — | Pagerduty Rundeck | 16/11/2023 | 17/6/2026 | Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In affected versions access to two URLs used in both Rundeck Open Source and Process Automation products could allow authenticated users to access the URL path, which would allow access to view or delete jobs, without the… | |
| Modificada | Media (4.3) | 0.51% | — | Pagerduty Rundeck | 16/11/2023 | 17/6/2026 | Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In affected versions access to two URLs used in both Rundeck Open Source and Process Automation products could allow authenticated users to access the URL path, which provides a list of job names and groups for any… | |
| Modificada | Alta (8.8) | 0.97% | — | Jenkins Rundeck | 21/9/2022 | 17/6/2026 | Jenkins Rundeck Plugin 3.6.11 and earlier does not protect access to the /plugin/rundeck/webhook/ endpoint, allowing users with Overall/Read permission to trigger jobs that are configured to be triggerable via Rundeck. | |
| Modificada | Media (4.3) | 0.62% | — | Jenkins Rundeck | 21/9/2022 | 17/6/2026 | Jenkins Rundeck Plugin 3.6.11 and earlier does not perform Run/Artifacts permission checks in multiple HTTP endpoints, allowing attackers with Item/Read permission to obtain information about build artifacts of a given job, if the optional Run/Artifacts permission is enabled. | |
| Modificada | Alta (7.5) | 0.67% | — | Pagerduty Rundeck | 15/6/2022 | 17/6/2026 | Rundeck is an open source automation service with a web console, command line tools and a WebAPI. The Key Storage converter plugin mechanism was not enabled correctly in Rundeck 4.2.0 and 4.2.1, resulting in use of the encryption layer for Key Storage possibly not working. Any credentials created or overwritten using… | |
| Modificada | Crítica (9.8) | 1.2% | — | Pagerduty Rundeck | 20/5/2022 | 17/6/2026 | Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Rundeck community and rundeck-enterprise docker images contained a pre-generated SSH keypair. If the id_rsa.pub public key of the keypair was copied to authorized_keys files on remote host, those hosts would allow access… | |
| Modificada | Media (5.4) | 73% | — | Jenkins Rundeck | 17/5/2022 | 17/6/2026 | Jenkins Rundeck Plugin 3.6.10 and earlier does not restrict URL schemes in Rundeck webhook submissions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to submit crafted Rundeck webhook payloads. | |
| Modificada | Alta (8.1) | 0.75% | — | Pagerduty Rundeck | 28/2/2022 | 17/6/2026 | Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In versions prior to 3.4.5, authenticated users could craft a request to modify or delete System or Project level Calendars, without appropriate authorization. Modifying or removing calendars could cause Scheduled Jobs to… | |
| Modificada | Media (5.4) | 0.56% | — | Pagerduty Rundeck | 28/2/2022 | 17/6/2026 | Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to versions 3.4.5 and 3.3.15, an authenticated user with authorization to read webhooks in one project can craft a request to reveal Webhook definitions and tokens in another project. The user could use the revealed… | |
| Modificada | Media (6.8) | 0.45% | — | Pagerduty Rundeck | 30/8/2021 | 17/6/2026 | Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to version 3.3.14 and version 3.4.3, a user with `admin` access to the `system` resource type is potentially vulnerable to a CSRF attack that could cause the server to run untrusted code on all Rundeck editions.… | |
| Modificada | Alta (8.8) | 1.7% | — | Pagerduty Rundeck | 30/8/2021 | 17/6/2026 | Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to version 3.3.14 and version 3.4.3, an authorized user can upload a zip-format plugin with a crafted plugin.yaml, or a crafted aclpolicy yaml file, or upload an untrusted project archive with a crafted aclpolicy… | |
| Modificada | Media (6.5) | 1.4% | — | Pagerduty Rundeck | 29/4/2020 | 17/6/2026 | In Rundeck before version 3.2.6, authenticated users can craft a request that reveals Execution data and logs and Job details that they are not authorized to see. Depending on the configuration and the way that Rundeck is used, this could result in anything between a high severity risk, or a very low risk. If access… | |
| Modificada | Alta (7.1) | 1.1% | — | Jenkins Rundeck | 9/3/2020 | 17/6/2026 | Jenkins Rundeck Plugin 3.6.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Modificada | Media (6.5) | 0.85% | — | Jenkins Rundeck | 17/12/2019 | 17/6/2026 | Jenkins Rundeck Plugin 3.6.5 and earlier stores credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system. | |
| Modificada | Media (4.3) | 0.64% | — | Jenkins Rundeck | 16/10/2019 | 17/6/2026 | A missing permission check in Jenkins Rundeck Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials. | |
| Modificada | Media (4.3) | 0.66% | — | Jenkins Rundeck | 16/10/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Rundeck Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials. | |
| Modificada | Media (6.1) | 5.3% | — | Pagerduty Rundeck | 25/1/2019 | 17/6/2026 | An XSS issue was discovered on the Job Edit page in Rundeck Community Edition before 3.0.13, related to assets/javascripts/workflowStepEditorKO.js and views/execution/_wfitemEdit.gsp. |