Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

1897 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (4.3)0.33%—Jenkins Keycloak Authentication PluginAI16/9/202618/9/2026
Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.
Pendiente de análisisMedia (6.8)0.43%—Jenkins Gitee PluginAI16/9/202618/9/2026
Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in build causes, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to trigger builds via the Jenkins Gitee Plugin webhook endpoint.
Pendiente de análisisMedia (6.5)0.25%—Jenkins Bitbucket Push AND Pull RequestAI16/9/202618/9/2026
Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URLs, allowing attackers to capture Bitbucket credentials stored in Jenkins by sending a crafted webhook payload.
Pendiente de análisisMedia (4.2)0.11%—Jenkins Bitbucket Server Integration PluginAI16/9/202618/9/2026
The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `oauth_callback` URL from the submitted form rather than from the server-side stored request token, allowing attackers to hijack the OAuth flow and obtain an access token on behalf of the victim.
Pendiente de análisisAlta (8.8)0.83%—Jenkins Robot Framework PluginAI16/9/202618/9/2026
Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot Framework report files is contained within the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to create or replace arbitrary files on the Jenkins controller file…
Pendiente de análisisAlta (8)0.41%—Jenkins Owasp Dependency-checkAIJenkinsAI16/9/202618/9/2026
Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Pendiente de análisisAlta (8)0.41%—Jenkins CoverageAI16/9/202618/9/2026
Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier does not validate the coverage results ID when a job configuration is submitted through the REST API, allowing attackers with Item/Configure permission to use a javascript: scheme URL as identifier, resulting in a stored cross-site scripting (XSS) vulnerability.
Pendiente de análisisAlta (8)0.41%—Jenkins WarningsAIJenkinsAI16/9/202618/9/2026
Jenkins Warnings Plugin 13.10258.va_17d49a_78c3b_ and earlier does not validate the analysis results ID when a job configuration is submitted through the REST API, allowing attackers with Item/Configure permission to use a javascript: scheme URL as identifier, resulting in a stored cross-site scripting (XSS)…
Pendiente de análisisMedia (5.4)0.23%—Jenkins Gitlab PluginAI16/9/202618/9/2026
Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API token credentials under a cache key derived from the credentials ID alone, omitting the folder in which the credentials are resolved, allowing attackers with Item/Configure permission to access GitLab…
Pendiente de análisisMedia (5.4)0.25%—Jenkins Gradle PluginAIGradleAIJetbrains DevelocityAI16/9/202618/9/2026
Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected in the build log, even when a Develocity server URL is configured in the global configuration, allowing attackers able to control the build log to capture the Develocity access key configured in the…
Pendiente de análisisMedia (4.2)0.23%—Jenkins Pipeline Groovy LibrariesAIJenkins PipelineAI16/9/202618/9/2026
Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to the library Pipeline step to a relative path inside the SCM checkout, and follows symbolic links to locations outside of the SCM checkout when retrieving the library, resulting in a path traversal…
Pendiente de análisisBaja (3.1)0.22%—Jenkins Pipeline Multibranch PluginAI16/9/202618/9/2026
Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials lookup in the resolveScm Pipeline step, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.
AnalizadaAlta (7.5)0.48%—Jenkins Script Security16/9/202621/9/2026
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods added dynamically to a class at runtime, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute code outside the…
AnalizadaAlta (7.5)0.29%—Jenkins Script Security16/9/202621/9/2026
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirming the approval of the first download and loading the classpath entries from the second, allowing attackers able to define classpath entries to execute arbitrary code in the context of the Jenkins…
AnalizadaAlta (8)0.61%—Jenkins Script Security16/9/202621/9/2026
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item configuration when a user with Overall/Administer permission copies the item, or updates that configuration through the REST API or CLI, allowing attackers able to define classpath entries to…
ModificadaAlta (8.5)0.62%—Jenkins Script Security16/9/202626/9/2026
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrategy member names an arbitrary class, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to execute code outside the sandbox if a suitable class is present on…
AnalizadaAlta (8.8)0.56%—Jenkins Script Security16/9/202621/9/2026
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotation, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to run an arbitrary AST transformation at compile time, bypassing the sandbox protection and…
AnalizadaAlta (8.8)0.63%—Jenkins Script Security16/9/202621/9/2026
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elements it reads from a collection that a sandboxed script casts to another type but performs the cast on the collection itself, allowing attackers with permission to define and run sandboxed scripts,…
AnalizadaAlta (8.8)0.63%—Jenkins Script Security16/9/202621/9/2026
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiver (method calls, property and attribute accesses, and array accesses), allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection…
AnalizadaAlta (8.8)0.63%—Jenkins Script Security16/9/202621/9/2026
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created when a sandboxed script coerces a value to an interface, if the value inherits a method of the same name as an interface method, allowing attackers with permission to define and run sandboxed…
Pendiente de análisisMedia (5.4)0.23%—Jenkins Update-center2AI2/9/20263/9/2026
Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided values (plugin names, descriptions, and version metadata) on plugin download index pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting.
Pendiente de análisisMedia (4.3)0.19%—Jenkins Parameterized Remote Trigger PluginAI2/9/20263/9/2026
Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
Pendiente de análisisAlta (7.4)1.2%—Jenkins Tics PluginAI2/9/20263/9/2026
OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control build environment variable values to execute arbitrary commands on the agent running the build.
Pendiente de análisisMedia (5.4)0.23%—Xebialabs XL DeployAIJenkinsAI2/9/20263/9/2026
Missing permission checks in Jenkins XebiaLabs XL Deploy Plugin 26.1.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Pendiente de análisisAlta (8.8)0.51%—Jenkins Customizable HeaderAI2/9/20263/9/2026
Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows overwriting the plugin's appearance configuration through Stapler data binding, allowing attackers to configure a custom SVG icon containing inline JavaScript, resulting in a stored cross-site scripting (XSS) vulnerability.