Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8)0.41%—Jenkins Sonarqube ScannerAISonarsource SonarqubeAI2/9/20263/9/2026
Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard links it creates based on SonarQube scanner results, allowing the `javascript:` scheme, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
AplazadaAlta (8.5)0.14%—Sonarsource SonarqubeAI29/1/202617/6/2026
SonarQube 8.3.1 contains an unquoted service path vulnerability that allows local attackers to gain SYSTEM privileges by exploiting the service executable path. Attackers can replace the wrapper.exe in the service path with a malicious executable to execute code with highest system privileges during service restart.
AplazadaMedia (4.3)0.22%—Sonarsource SonarqubeAI10/10/202517/6/2026
In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/users-management/users endpoint and obtain user fields intended for administrators only, including the email addresses of other accounts.
AplazadaAlta (7.7)1.5%—Sonarqube Github ActionAI26/9/202517/6/2026
SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. A command injection vulnerability exists in SonarQube GitHub Action in version 4.0.0 to before version 6.0.0 when workflows pass user-controlled input to the args parameter on Windows runners without proper…
AplazadaAlta (7.8)1.1%—Sonarqube ServerAISonarqube CloudAISonarqube Scan Github ActionAI2/9/202517/6/2026
SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. In versions 4 to 5.3.0, a command injection vulnerability was discovered in the SonarQube Scan GitHub Action that allows untrusted input arguments to be processed without proper sanitization. Arguments sent to…
AnalizadaAlta (7.2)0.45%—Sonarsource Sonarqube4/10/202417/6/2026
In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-memberships API endpoint that allows SonarQube users with the administrator role to inject blind SQL commands.
AplazadaAlta (7.2)0.48%—Sonarsource SonarqubeAI4/10/202417/6/2026
An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5. A SonarQube user with the Administrator role can modify an existing configuration of a GitHub integration to exfiltrate a pre-signed JWT.
ModificadaMedia (6.5)0.33%—Sonarsource Sonarqube16/6/202417/6/2026
In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part of the URL parameters in the logs (such as SonarQube Access Logs, Proxy Logs, etc).
ModificadaCrítica (9.8)2.2%—Sonarsource Sonarqube Docker Image16/12/202017/6/2026
The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user. System using the sonarqube docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
ModificadaMedia (5.3)1.1%—Sonarsource Sonarqube2/11/202017/6/2026
In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner. With an empty value for the -D sonar.login option, anonymous authentication is forced. This allows creating and overwriting public and private projects via the /api/ce/submit endpoint.
ModificadaAlta (7.5)16%—Sonarsource Sonarqube28/10/202017/6/2026
SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for SMTP and SVN is "it is the administrator's responsibility to configure it.
ModificadaMedia (6.1)0.66%—Sonarsource Sonarqube14/10/201917/6/2026
SonarSource SonarQube before 7.8 has XSS in project links on account/projects.
ModificadaAlta (7.8)0.34%—Sonarsource Sonarqube Scanner9/1/201917/6/2026
An insufficiently protected credentials vulnerability exists in Jenkins SonarQube Scanner Plugin 2.8 and earlier in SonarInstallation.java that allows attackers with local file system access to obtain the credentials used to connect to SonarQube.
ModificadaMedia (4.3)1.1%—Sonarsource Sonarqube14/12/201817/6/2026
A vulnerability in the API of SonarSource SonarQube before 7.4 could allow an authenticated user to discover sensitive information such as valid user-account logins in the web application. The vulnerability occurs because of improperly configured access controls that cause the API to return the externalIdentity field…