Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2760▲ 27 respecto a la semana anterior
Críticas / altas1467▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 441 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8) | 0.41% | — | Jenkins CoverageAI | 16/9/2026 | 18/9/2026 | Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier does not validate the coverage results ID when a job configuration is submitted through the REST API, allowing attackers with Item/Configure permission to use a javascript: scheme URL as identifier, resulting in a stored cross-site scripting (XSS) vulnerability. | |
| Analizada | Media (5.4) | 0.31% | — | Jenkins Coverage | 10/12/2025 | 17/6/2026 | Jenkins Coverage Plugin 2.3054.ve1ff7b_a_a_123b_ and earlier does not validate the configured coverage results ID when creating coverage results, only when submitting the job configuration through the UI, allowing attackers with Item/Configure permission to use a `javascript:` scheme URL as identifier by configuring… | |
| Modificada | Media (5.5) | 0.23% | — | Jenkins Github Pull Request Coverage Status | 26/1/2023 | 17/6/2026 | Jenkins GitHub Pull Request Coverage Status Plugin 2.2.0 and earlier stores the GitHub Personal Access Token, Sonar access token and Sonar password unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Media (5.3) | 0.71% | — | Jenkins Compuware Xpediter Code Coverage | 19/10/2022 | 17/6/2026 | Jenkins Compuware Xpediter Code Coverage Plugin 1.0.7 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from the Jenkins controller process. | |
| Modificada | Media (4.3) | 0.66% | — | Jenkins Compuware Xpediter Code Coverage | 27/7/2022 | 17/6/2026 | A missing permission check in Jenkins Compuware Xpediter Code Coverage Plugin 1.0.7 and earlier allows attackers with Overall/Read permission to enumerate hosts and ports of Compuware configurations and credentials IDs of credentials stored in Jenkins. | |
| Modificada | Alta (8.1) | 1.0% | — | Jenkins Coverage/complexity Scatter Plot | 29/3/2022 | 17/6/2026 | Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Modificada | Alta (8.8) | 2.2% | — | Jenkins Code Coverage API | 31/8/2021 | 17/6/2026 | Jenkins Code Coverage API Plugin 1.4.0 and earlier does not apply Jenkins JEP-200 deserialization protection to Java objects it deserializes from disk, resulting in a remote code execution vulnerability. | |
| Modificada | Media (5.4) | 0.73% | — | Jenkins Coverage/complexity Scatter Plot | 16/9/2020 | 17/6/2026 | Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not escape the method information in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide report files to the plugin's post-build step. | |
| Modificada | Media (4.3) | 0.69% | — | Jenkins Github Coverage Reporter | 2/7/2020 | 17/6/2026 | Jenkins GitHub Coverage Reporter Plugin 1.8 and earlier stores secrets unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system or read permissions on the system configuration. | |
| Modificada | Media (6.5) | 1.1% | — | Jenkins Code Coverage API | 7/4/2020 | 17/6/2026 | Jenkins Code Coverage API Plugin 1.1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Modificada | Media (5.4) | 0.73% | — | Jenkins Code Coverage API | 29/1/2020 | 17/6/2026 | Jenkins Code Coverage API Plugin 1.1.2 and earlier does not escape the filename of the coverage report used in its view, resulting in a stored XSS vulnerability exploitable by users able to change job configurations. | |
| Modificada | Media (4.3) | 3.6% | — | MoodleNimish Pachapurkar Spike Phpcoverage | 16/7/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Spike PHPCoverage (aka spikephpcoverage) library, as used in Moodle 2.0.x before 2.0.2 and other products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |