Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2719▼ 93 respecto a la semana anterior
Críticas / altas1415▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)101▼ 398 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 1.9% | — | Apache SubversionDebian Linux | 9/12/2024 | 17/6/2026 | Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users with commit access to commit a corrupted revision, leading to disruption for users of the repository. All versions of Subversion up to and including Subversion 1.14.4 are… | |
| Analizada | Alta (7.8) | 0.61% | — | Apache Subversion | 9/10/2024 | 17/6/2026 | On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead to unexpected command line argument interpretation, including argument injection and execution of other programs, if a specially crafted command line argument string is… | |
| Analizada | Media (6.8) | 0.79% | — | Jenkins Subversion Partial Release Manager | 2/5/2024 | 17/6/2026 | Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically disables the fix for CVE-2016-3721 whenever a build is triggered from a release tag, by setting the Java system property 'hudson.model.ParametersAction.keepUndefinedParameters'. | |
| Analizada | Media (4.3) | 0.50% | — | Jenkins Subversion Partial Release Manager | 6/3/2024 | 17/6/2026 | A missing permission check in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers with Item/Read permission to trigger a build. | |
| Analizada | Media (4.3) | 0.31% | — | Jenkins Subversion Partial Release Manager | 6/3/2024 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers to trigger a build. | |
| Modificada | Media (4.3) | 1.9% | — | Jenkins SubversionApple Macos | 12/4/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Subversion Plugin 2.15.3 and earlier allows attackers to connect to an attacker-specified URL. | |
| Modificada | Media (5.4) | 2.5% | — | Jenkins SubversionApple Macos | 12/4/2022 | 17/6/2026 | Jenkins Subversion Plugin 2.15.3 and earlier does not escape the name and description of List Subversion tags (and more) parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Alta (7.5) | 9.5% | — | Apache SubversionDebian LinuxFedoraproject FedoraApple Macos | 12/4/2022 | 17/6/2026 | Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (inclusive). Servers that do not use mod_dav_svn are not affected. | |
| Modificada | Media (4.3) | 2.8% | — | Apache SubversionDebian LinuxFedoraproject FedoraApple Macos | 12/4/2022 | 17/6/2026 | Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, users with access to the copy can see the 'copyfrom' path of the… | |
| Modificada | Media (6.1) | 0.76% | — | Siemens Polarion ALMSiemens Polarion Subversion Webclient | 8/3/2022 | 17/6/2026 | A vulnerability has been identified in Polarion ALM (All versions < V21 R2 P2), Polarion WebClient for SVN (All versions). A cross-site scripting is present due to improper neutralization of data sent to the web page through the SVN WebClient in the affected product. An attacker could exploit this to execute arbitrary… | |
| Modificada | Alta (7.5) | 2.1% | — | Jenkins Subversion | 4/11/2021 | 17/6/2026 | Jenkins Subversion Plugin 2.15.0 and earlier does not restrict the name of a file when looking up a subversion key file on the controller from an agent. | |
| Modificada | Alta (7.5) | 40% | — | Apache SubversionDebian Linux | 17/3/2021 | 17/6/2026 | Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead to disruption for users of the service. This issue was fixed in mod_dav_svn+mod_authz_svn servers… | |
| Modificada | Media (6.5) | 1.5% | — | Jenkins Subversion | 4/11/2020 | 17/6/2026 | Jenkins Subversion Plugin 2.13.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Modificada | Alta (8.1) | 0.49% | — | Siemens Polarion Subversion Webclient | 9/9/2020 | 17/6/2026 | A vulnerability has been identified in Polarion Subversion Webclient (All versions). The web interface could allow a Cross-Site Request Forgery (CSRF) attack if an unsuspecting user is tricked into accessing a malicious link. Successful exploitation requires user interaction by a legitimate user, who must be… | |
| Modificada | Media (6.1) | 0.67% | — | Siemens Polarion Subversion Webclient | 9/9/2020 | 17/6/2026 | A vulnerability has been identified in Polarion Subversion Webclient (All versions). The Polarion subversion web application does not filter user input in a way that prevents Cross-Site Scripting. If a user is enticed into passing specially crafted, malicious input to the web client (e.g. by clicking on a malicious… | |
| Modificada | Media (6.1) | 6.2% | — | Jenkins Subversion Partial Release Manager | 3/6/2020 | 17/6/2026 | Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier does not escape the error message for the repository URL field form validation, resulting in a reflected cross-site scripting vulnerability. | |
| Modificada | Media (6.1) | 5.2% | — | Atlassian Subversion Application Lifecycle Management | 20/3/2020 | 17/6/2026 | Subversion ALM for the enterprise before 8.8.2 allows reflected XSS at multiple locations. | |
| Modificada | Media (6.1) | 1.3% | — | Jenkins Subversion Release Manager | 9/3/2020 | 17/6/2026 | Jenkins Subversion Release Manager Plugin 1.2 and earlier does not escape the error message for the Repository URL field form validation, resulting in a reflected cross-site scripting vulnerability. | |
| Modificada | Media (5.4) | 0.93% | — | Jenkins Subversion | 12/2/2020 | 17/6/2026 | Jenkins Subversion Plugin 2.13.0 and earlier does not escape the error message for the Project Repository Base URL field form validation, resulting in a stored cross-site scripting vulnerability. | |
| Modificada | Alta (7.5) | 3.4% | — | Apache Subversion | 26/9/2019 | 17/6/2026 | In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a client sends certain sequences of protocol commands. This can lead to disruption for users of the server. | |
| Modificada | Media (6.5) | 2.4% | — | Apache Subversion | 26/9/2019 | 17/6/2026 | In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a well-formed read-only request produces a particular answer. This can lead to disruption for users of the server. | |
| Modificada | Alta (7.5) | 58% | — | Apache SubversionCanonical Ubuntu Linux | 5/2/2019 | 17/6/2026 | Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory listing operation. | |
| Modificada | Media (5.3) | 0.90% | — | Jenkins Subversion | 13/3/2018 | 17/6/2026 | An improper authorization vulnerability exists in Jenkins Subversion Plugin version 2.10.2 and earlier in SubversionStatus.java and SubversionRepositoryStatus.java that allows an attacker with network access to obtain a list of nodes and users. | |
| Modificada | Alta (8.8) | 2.8% | — | Apache Subversion | 30/10/2017 | 16/6/2026 | libsvn_fs_fs/fs_fs.c in Apache Subversion 1.8.x before 1.8.2 might allow remote authenticated users with commit access to corrupt FSFS repositories and cause a denial of service or obtain sensitive information by editing packed revision properties. | |
| Modificada | Media (6.5) | 6.4% | — | Apache SubversionDebian Linux | 16/10/2017 | 17/6/2026 | Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory. |