Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2760▲ 27 respecto a la semana anterior
Críticas / altas1467▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 441 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8)0.41%—Jenkins CoverageAI16/9/202618/9/2026
Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier does not validate the coverage results ID when a job configuration is submitted through the REST API, allowing attackers with Item/Configure permission to use a javascript: scheme URL as identifier, resulting in a stored cross-site scripting (XSS) vulnerability.
AnalizadaMedia (5.4)0.31%—Jenkins Coverage10/12/202517/6/2026
Jenkins Coverage Plugin 2.3054.ve1ff7b_a_a_123b_ and earlier does not validate the configured coverage results ID when creating coverage results, only when submitting the job configuration through the UI, allowing attackers with Item/Configure permission to use a `javascript:` scheme URL as identifier by configuring…
ModificadaMedia (5.5)0.23%—Jenkins Github Pull Request Coverage Status26/1/202317/6/2026
Jenkins GitHub Pull Request Coverage Status Plugin 2.2.0 and earlier stores the GitHub Personal Access Token, Sonar access token and Sonar password unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
ModificadaMedia (5.3)0.71%—Jenkins Compuware Xpediter Code Coverage19/10/202217/6/2026
Jenkins Compuware Xpediter Code Coverage Plugin 1.0.7 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from the Jenkins controller process.
ModificadaMedia (4.3)0.66%—Jenkins Compuware Xpediter Code Coverage27/7/202217/6/2026
A missing permission check in Jenkins Compuware Xpediter Code Coverage Plugin 1.0.7 and earlier allows attackers with Overall/Read permission to enumerate hosts and ports of Compuware configurations and credentials IDs of credentials stored in Jenkins.
ModificadaAlta (8.1)1.0%—Jenkins Coverage/complexity Scatter Plot29/3/202217/6/2026
Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
ModificadaAlta (8.8)2.2%—Jenkins Code Coverage API31/8/202117/6/2026
Jenkins Code Coverage API Plugin 1.4.0 and earlier does not apply Jenkins JEP-200 deserialization protection to Java objects it deserializes from disk, resulting in a remote code execution vulnerability.
ModificadaMedia (5.4)0.73%—Jenkins Coverage/complexity Scatter Plot16/9/202017/6/2026
Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not escape the method information in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide report files to the plugin's post-build step.
ModificadaMedia (4.3)0.69%—Jenkins Github Coverage Reporter2/7/202017/6/2026
Jenkins GitHub Coverage Reporter Plugin 1.8 and earlier stores secrets unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system or read permissions on the system configuration.
ModificadaMedia (6.5)1.1%—Jenkins Code Coverage API7/4/202017/6/2026
Jenkins Code Coverage API Plugin 1.1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
ModificadaMedia (5.4)0.73%—Jenkins Code Coverage API29/1/202017/6/2026
Jenkins Code Coverage API Plugin 1.1.2 and earlier does not escape the filename of the coverage report used in its view, resulting in a stored XSS vulnerability exploitable by users able to change job configurations.
ModificadaMedia (4.3)3.6%—MoodleNimish Pachapurkar Spike Phpcoverage16/7/201216/6/2026
Cross-site scripting (XSS) vulnerability in the Spike PHPCoverage (aka spikephpcoverage) library, as used in Moodle 2.0.x before 2.0.2 and other products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.