Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
1897 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.3) | 0.33% | — | Jenkins Keycloak Authentication PluginAI | 16/9/2026 | 18/9/2026 | Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks. | |
| Pendiente de análisis | Media (6.8) | 0.43% | — | Jenkins Gitee PluginAI | 16/9/2026 | 18/9/2026 | Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in build causes, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to trigger builds via the Jenkins Gitee Plugin webhook endpoint. | |
| Pendiente de análisis | Media (6.5) | 0.25% | — | Jenkins Bitbucket Push AND Pull RequestAI | 16/9/2026 | 18/9/2026 | Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URLs, allowing attackers to capture Bitbucket credentials stored in Jenkins by sending a crafted webhook payload. | |
| Pendiente de análisis | Media (4.2) | 0.11% | — | Jenkins Bitbucket Server Integration PluginAI | 16/9/2026 | 18/9/2026 | The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `oauth_callback` URL from the submitted form rather than from the server-side stored request token, allowing attackers to hijack the OAuth flow and obtain an access token on behalf of the victim. | |
| Pendiente de análisis | Alta (8.8) | 0.83% | — | Jenkins Robot Framework PluginAI | 16/9/2026 | 18/9/2026 | Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot Framework report files is contained within the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to create or replace arbitrary files on the Jenkins controller file… | |
| Pendiente de análisis | Alta (8) | 0.41% | — | Jenkins Owasp Dependency-checkAIJenkinsAI | 16/9/2026 | 18/9/2026 | Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Pendiente de análisis | Alta (8) | 0.41% | — | Jenkins CoverageAI | 16/9/2026 | 18/9/2026 | Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier does not validate the coverage results ID when a job configuration is submitted through the REST API, allowing attackers with Item/Configure permission to use a javascript: scheme URL as identifier, resulting in a stored cross-site scripting (XSS) vulnerability. | |
| Pendiente de análisis | Alta (8) | 0.41% | — | Jenkins WarningsAIJenkinsAI | 16/9/2026 | 18/9/2026 | Jenkins Warnings Plugin 13.10258.va_17d49a_78c3b_ and earlier does not validate the analysis results ID when a job configuration is submitted through the REST API, allowing attackers with Item/Configure permission to use a javascript: scheme URL as identifier, resulting in a stored cross-site scripting (XSS)… | |
| Pendiente de análisis | Media (5.4) | 0.23% | — | Jenkins Gitlab PluginAI | 16/9/2026 | 18/9/2026 | Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API token credentials under a cache key derived from the credentials ID alone, omitting the folder in which the credentials are resolved, allowing attackers with Item/Configure permission to access GitLab… | |
| Pendiente de análisis | Media (5.4) | 0.25% | — | Jenkins Gradle PluginAIGradleAIJetbrains DevelocityAI | 16/9/2026 | 18/9/2026 | Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected in the build log, even when a Develocity server URL is configured in the global configuration, allowing attackers able to control the build log to capture the Develocity access key configured in the… | |
| Pendiente de análisis | Media (4.2) | 0.23% | — | Jenkins Pipeline Groovy LibrariesAIJenkins PipelineAI | 16/9/2026 | 18/9/2026 | Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to the library Pipeline step to a relative path inside the SCM checkout, and follows symbolic links to locations outside of the SCM checkout when retrieving the library, resulting in a path traversal… | |
| Pendiente de análisis | Baja (3.1) | 0.22% | — | Jenkins Pipeline Multibranch PluginAI | 16/9/2026 | 18/9/2026 | Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials lookup in the resolveScm Pipeline step, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to. | |
| Analizada | Alta (7.5) | 0.48% | — | Jenkins Script Security | 16/9/2026 | 21/9/2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods added dynamically to a class at runtime, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute code outside the… | |
| Analizada | Alta (7.5) | 0.29% | — | Jenkins Script Security | 16/9/2026 | 21/9/2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirming the approval of the first download and loading the classpath entries from the second, allowing attackers able to define classpath entries to execute arbitrary code in the context of the Jenkins… | |
| Analizada | Alta (8) | 0.61% | — | Jenkins Script Security | 16/9/2026 | 21/9/2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item configuration when a user with Overall/Administer permission copies the item, or updates that configuration through the REST API or CLI, allowing attackers able to define classpath entries to… | |
| Modificada | Alta (8.5) | 0.62% | — | Jenkins Script Security | 16/9/2026 | 26/9/2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrategy member names an arbitrary class, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to execute code outside the sandbox if a suitable class is present on… | |
| Analizada | Alta (8.8) | 0.56% | — | Jenkins Script Security | 16/9/2026 | 21/9/2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotation, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to run an arbitrary AST transformation at compile time, bypassing the sandbox protection and… | |
| Analizada | Alta (8.8) | 0.63% | — | Jenkins Script Security | 16/9/2026 | 21/9/2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elements it reads from a collection that a sandboxed script casts to another type but performs the cast on the collection itself, allowing attackers with permission to define and run sandboxed scripts,… | |
| Analizada | Alta (8.8) | 0.63% | — | Jenkins Script Security | 16/9/2026 | 21/9/2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiver (method calls, property and attribute accesses, and array accesses), allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection… | |
| Analizada | Alta (8.8) | 0.63% | — | Jenkins Script Security | 16/9/2026 | 21/9/2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created when a sandboxed script coerces a value to an interface, if the value inherits a method of the same name as an interface method, allowing attackers with permission to define and run sandboxed… | |
| Pendiente de análisis | Media (5.4) | 0.23% | — | Jenkins Update-center2AI | 2/9/2026 | 3/9/2026 | Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided values (plugin names, descriptions, and version metadata) on plugin download index pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting. | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Jenkins Parameterized Remote Trigger PluginAI | 2/9/2026 | 3/9/2026 | Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system. | |
| Pendiente de análisis | Alta (7.4) | 1.2% | — | Jenkins Tics PluginAI | 2/9/2026 | 3/9/2026 | OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control build environment variable values to execute arbitrary commands on the agent running the build. | |
| Pendiente de análisis | Media (5.4) | 0.23% | — | Xebialabs XL DeployAIJenkinsAI | 2/9/2026 | 3/9/2026 | Missing permission checks in Jenkins XebiaLabs XL Deploy Plugin 26.1.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Pendiente de análisis | Alta (8.8) | 0.51% | — | Jenkins Customizable HeaderAI | 2/9/2026 | 3/9/2026 | Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows overwriting the plugin's appearance configuration through Stapler data binding, allowing attackers to configure a custom SVG icon containing inline JavaScript, resulting in a stored cross-site scripting (XSS) vulnerability. |