Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2534▼ 359 respecto a la semana anterior
Críticas / altas1338▲ 69 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
4 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.33% | — | Jenkins Bitbucket Oauth | 27/5/2026 | 17/6/2026 | Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks. | |
| Modificada | Media (5.7) | 0.48% | — | Jenkins Bitbucket Oauth | 26/1/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket OAuth Plugin 0.12 and earlier allows attackers to trick users into logging in to the attacker's account. | |
| Modificada | Crítica (9.8) | 1.1% | — | Jenkins Bitbucket Oauth | 26/1/2023 | 17/6/2026 | Jenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous session on login. | |
| Modificada | Alta (7.8) | 0.33% | — | Jenkins Bitbucket Oauth | 23/10/2019 | 17/6/2026 | Jenkins Bitbucket OAuth Plugin 0.9 and earlier stored credentials unencrypted in the global config.xml configuration file on the Jenkins master where they could be viewed by users with access to the master file system. |