Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2534▼ 359 respecto a la semana anterior
Críticas / altas1338▲ 69 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

4 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.3)0.33%—Jenkins Bitbucket Oauth27/5/202617/6/2026
Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.
ModificadaMedia (5.7)0.48%—Jenkins Bitbucket Oauth26/1/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket OAuth Plugin 0.12 and earlier allows attackers to trick users into logging in to the attacker's account.
ModificadaCrítica (9.8)1.1%—Jenkins Bitbucket Oauth26/1/202317/6/2026
Jenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous session on login.
ModificadaAlta (7.8)0.33%—Jenkins Bitbucket Oauth23/10/201917/6/2026
Jenkins Bitbucket OAuth Plugin 0.9 and earlier stored credentials unencrypted in the global config.xml configuration file on the Jenkins master where they could be viewed by users with access to the master file system.