Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3090▲ 519 respecto a la semana anterior
Críticas / altas1463▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.40% | — | Doco-cdAIDocker ComposeAIDocker SwarmAI | 11/9/2026 | 30/9/2026 | Doco-CD es una herramienta de entrega continua GitOps que implementa y actualiza automáticamente proyectos/servicios de Docker Compose y stacks de Swarm. Antes de la versión 0.90.1, un fallo de límite de confianza en la verificación de artefactos OCI permitía que la configuración de implementación proporcionada por el… | |
| Aplazada | Alta (7.7) | 0.51% | — | SwarmsAI | 30/7/2026 | 30/7/2026 | Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery vulnerability in the _is_safe_url function that fails to validate hostnames through DNS resolution, allowing attackers to bypass the blocklist. Attackers can supply user-controlled image or audio URLs that resolve to private,… | |
| Analizada | Baja (2.1) | 0.30% | — | Macrozheng Mall-swarm | 4/12/2025 | 17/6/2026 | A security vulnerability has been detected in macrozheng mall-swarm up to 1.0.3. Affected is the function delete of the file /member/readHistory/delete. Such manipulation of the argument ids leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.… | |
| Modificada | Baja (2.1) | 0.24% | — | Macrozheng MallMacrozheng Mall-swarm | 13/11/2025 | 17/6/2026 | A vulnerability was detected in macrozheng mall-swarm up to 1.0.3. Affected by this issue is the function paySuccess of the file /order/paySuccess. The manipulation of the argument orderID results in improper authorization. The attack can be launched remotely. The exploit is now public and may be used. The vendor was… | |
| Analizada | Baja (2.1) | 0.30% | — | Macrozheng MallMacrozheng Mall-swarm | 13/11/2025 | 17/6/2026 | A security vulnerability has been detected in macrozheng mall-swarm and mall up to 1.0.3. Affected by this vulnerability is the function cancelOrder of the file /order/cancelOrder. The manipulation of the argument orderId leads to improper authorization. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 0.30% | — | Macrozheng MallMacrozheng Mall-swarm | 13/11/2025 | 17/6/2026 | A weakness has been identified in macrozheng mall-swarm and mall up to 1.0.3. Affected is the function cancelUserOrder of the file /order/cancelUserOrder. Executing manipulation of the argument orderId can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been made available… | |
| Analizada | Baja (2.1) | 0.33% | — | Macrozheng MallMacrozheng Mall-swarm | 13/11/2025 | 17/6/2026 | A security flaw has been discovered in macrozheng mall-swarm and mall up to 1.0.3. This impacts the function detail of the file /order/detail/ of the component Order Details Handler. Performing manipulation of the argument orderId results in improper authorization. It is possible to initiate the attack remotely. The… | |
| Analizada | Baja (2.1) | 0.24% | — | Macrozheng Mall-swarm | 13/11/2025 | 7/10/2026 | Una vulnerabilidad fue identificada en macrozheng mall-swarm hasta 1.0.3. Esto afecta la función updateAttr del archivo /cart/update/attr. Dicha manipulación conduce a autorización indebida. El ataque puede ser realizado desde remoto. El exploit está disponible públicamente y podría ser utilizado. El proveedor fue… | |
| Modificada | Media (5.4) | 0.59% | — | Jenkins Docker Swarm | 16/8/2023 | 17/6/2026 | Jenkins Docker Swarm Plugin 1.11 and earlier does not escape values returned from Docker before inserting them into the Docker Swarm Dashboard view, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control responses from Docker. | |
| Modificada | Media (6.5) | 0.61% | — | Jenkins Self-organizing Swarm Modules | 3/6/2020 | 17/6/2026 | Una vulnerabilidad de tipo cross-site request forgery en Jenkins Self-Organizing Swarm Plug-in Modules Plugin versiones 3.20 y anteriores, permite a atacantes agregar o eliminar etiquetas de agente. | |
| Modificada | Media (4.3) | 0.66% | — | Jenkins Self-organizing Swarm Modules | 3/6/2020 | 17/6/2026 | Jenkins Self-Organizing Swarm Plug-in Modules Plugin versiones 3.20 y anteriores, no comprueban los permisos en los endpoints de la API que permiten agregar y quitar etiquetas de agente. | |
| Modificada | Crítica (9.3) | 1.8% | — | Jenkins Self-organizing Swarm Modules | 30/4/2019 | 17/6/2026 | En los Plugin Self-Organizing Swarm y Modules de Jenkins, clientes que usan difusión UDP para encontrar servidores maestros Jenkins no impiden el procesamiento de entidades externas XML al procesar las respuestas, lo que permite a los atacantes no autorizados de la misma red leer de manera arbitraria archivos de… | |
| Modificada | Media (5.9) | 0.49% | — | Jenkins Swarm | 26/1/2018 | 17/6/2026 | Jenkins Swarm Plugin Client 2.73.1 y anteriores y 3.4 y anteriores incluía una versión de la biblioteca commons-httpclient con la vulnerabilidad CVE-2012-6153 que verificaba incorrectamente los certificados SSL, volviéndolo susceptible a ataques de Man-in-the-Middle (MitM). |