Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2764▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)245▼ 256 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.2) | 0.21% | — | Jenkins Zowe Zdevops | 24/6/2026 | 26/6/2026 | A missing permission check in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Analizada | Media (4.2) | 0.18% | — | Jenkins Zowe Zdevops | 24/6/2026 | 26/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Analizada | Media (5.3) | 0.21% | — | Linuxfoundation Zowe API Mediation Layer | 10/10/2024 | 17/6/2026 | The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific information about the service, including available endpoints, and swagger. It could advise about the running version of a service to an attacker. The attacker could also… | |
| Analizada | Media (5.3) | 0.23% | — | Linuxfoundation Zowe API Mediation Layer | 10/10/2024 | 17/6/2026 | The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for attackers. | |
| Modificada | Media (5.5) | 0.14% | — | Zowe CLI | 19/7/2024 | 17/6/2026 | A vulnerability in Zowe CLI allows local, privileged actors to display securely stored properties in cleartext within a terminal using the '--show-inputs-only' flag. | |
| Aplazada | Crítica (9) | 0.26% | — | Zowe ApimlAIVmware Cloud GatewayAI | 17/7/2024 | 17/6/2026 | A vulnerability in APIML Spring Cloud Gateway which leverages user privileges by unexpected signing proxied request by Zowe's client certificate. This allows access to a user to the endpoints requiring an internal client certificate without any credentials. It could lead to managing components in there and allow an… | |
| Aplazada | Media (5.9) | 0.14% | — | Zowe CLIAI | 17/7/2024 | 17/6/2026 | A vulnerability in Zowe CLI allows local, privileged actors to store previously entered secure credentials in a plaintext file as part of an auto-init operation. | |
| Modificada | Alta (7.8) | 0.26% | — | Linuxfoundation Zowe | 1/3/2023 | 17/6/2026 | A vulnerability in Imperative framework which allows already-privileged local actors to execute arbitrary shell commands via plugin install/update commands, or maliciously formed environment variables. Impacts Zowe CLI. | |
| Modificada | Media (5.3) | 0.44% | — | Linuxfoundation Zowe API Mediation Layer | 18/1/2023 | 17/6/2026 | It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. This is happening only in the situation when zOSMF doesn’t have the APAR PH12143 applied. This issue affects: 1.16 versions to 1.19. What happens is that the services using the ZAAS… |