Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2494▼ 451 respecto a la semana anterior
Críticas / altas1280▼ 7 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
3658 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.7) | 0.22% | — | Gitroom PostizAI | 15/7/2026 | 15/7/2026 | Postiz is an AI social media scheduling tool. Prior to 2.21.8, Postiz fails to verify Nowpayments IPN callback authenticity against the payment provider shared secret and reads the target subscription identifier from the untrusted request body, allowing a low-privileged account to grant arbitrary organizations… | |
| Aplazada | Alta (8.7) | 0.40% | — | Digital-peak DP CalendarAIJoomlaAI | 15/7/2026 | 23/7/2026 | Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2 - The Joomla extension DP Calendar is vulnerable to an unauthenticated SQL injection. | |
| Aplazada | Alta (7.7) | 0.39% | — | Redhat Openshift GitopsAIArgoproj Argo CDAI | 15/7/2026 | 16/7/2026 | A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objects. A namespace-scoped Argo CD instance can trigger deletion of a ClusterRole owned by a cluster-scoped Argo CD instance by crafting a name collision, resulting in a… | |
| Aplazada | Crítica (9.8) | 1.1% | — | Openasset Digital Asset ManagementAI | 14/7/2026 | 15/7/2026 | An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name and description parameter of the Add/Update Project function | |
| Analizada | Alta (7.8) | 0.36% | — | Microsoft Github Copilot | 14/7/2026 | 22/7/2026 | Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally. | |
| Pendiente de análisis | Alta (8.9) | 0.47% | — | Redhat Openshift GitopsAIArgoproj Argo CDAI | 14/7/2026 | 11/8/2026 | A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticated attacker with network access to the Argo CD repo-server to achieve remote code execution. Under certain conditions, the attacker may then manipulate cached data to deploy malicious Kubernetes… | |
| Aplazada | Crítica (9.2) | 0.51% | — | Mcp-gitlabAI | 13/7/2026 | 13/7/2026 | mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to escape the intended path prefix and access arbitrary GitLab API resources using the… | |
| Modificada | Alta (8.1) | 0.74% | — | Apache-airflow-providers-git | 13/7/2026 | 16/9/2026 | The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification. An attacker who can intercept the network path between an Airflow worker and the Git server can impersonate the server (man-in-the-middle), capturing the SSH deploy key or… | |
| Pendiente de análisis | Media (4.4) | 0.33% | — | Github CLIAIGithub CodespaceAIMicrosoft Visual Studio CodeAI | 9/7/2026 | 14/7/2026 | GitHub CLI (gh) is GitHub’s official command line tool. From 2.10.0 through 2.95.0, connecting to a malicious Codespace with gh codespace jupyter can allow command execution because the command opens a JupyterLab URL supplied by a process inside the Codespace without validating that it is a loopback HTTP or HTTPS… | |
| Analizada | Media (4.3) | 0.39% | — | Gitlab | 8/7/2026 | 10/7/2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with minimal access permissions to read work item metadata from private projects due to missing authorization… | |
| Analizada | Media (5.3) | 0.35% | — | Gitlab | 8/7/2026 | 9/7/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an unauthenticated user to determine the existence of a private project due to improper authorization controls on cross-project… | |
| Analizada | Media (5.4) | 0.40% | — | Gitlab | 8/7/2026 | 9/7/2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary scripts in another user's browser session due to improper… | |
| Analizada | Baja (2.7) | 0.36% | — | Gitlab | 8/7/2026 | 9/7/2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with auditor-level access to modify compliance violation records due to improper authorization on certain… | |
| Analizada | Alta (7.1) | 0.41% | — | Jupyterlab-git | 8/7/2026 | 15/7/2026 | JupyterLab Git is a Git extension for JupyterLab. Prior to 0.54.0, jupyterlab-git uses fnmatch.fnmatchcase() in GitHandler.prepare() in jupyterlab_git/handlers.py to enforce excluded_paths, allowing an authenticated user on a case-insensitive filesystem to vary URL path casing and read excluded directories. This issue… | |
| Analizada | Crítica (9.3) | 0.53% | — | Jupyterlab-git | 8/7/2026 | 15/7/2026 | JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames directly to innerHTML when rendering renamed files in commit history, allowing a crafted filename to execute JavaScript when a victim views the rename diff in the Git History… | |
| Analizada | Media (5.4) | 0.39% | — | Gitlab | 8/7/2026 | 9/7/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to execute arbitrary scripts in another user's browser session due to improper sanitization of user-supplied… | |
| Analizada | Media (4.9) | 0.44% | — | Gitlab | 8/7/2026 | 9/7/2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 9.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to obtain another user's stored credentials due to improper authorization… | |
| Analizada | Media (4.3) | 0.33% | — | Gitlab | 8/7/2026 | 29/9/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to create a repository where the content displayed in the web interface differed from the content available… | |
| Analizada | Media (5.3) | 0.08% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Lemans AU Lgit Firmware+75 | 6/7/2026 | 7/7/2026 | Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits. | |
| Analizada | Alta (7.1) | 0.10% | — | Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Lemans AU Lgit FirmwareQualcomm Lemansau Firmware+49 | 6/7/2026 | 8/7/2026 | Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security. | |
| Analizada | Media (5.3) | 0.08% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm G3X GEN 2 Firmware+87 | 6/7/2026 | 7/7/2026 | Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values. | |
| Analizada | Media (5.3) | 0.08% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+105 | 6/7/2026 | 7/7/2026 | Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification. | |
| Analizada | Media (5.3) | 0.08% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm G3X GEN 2 Firmware+87 | 6/7/2026 | 7/7/2026 | Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks. | |
| Aplazada | Media (5.5) | 0.54% | — | Tiddly Gittly Tidgi DesktopAI | 5/7/2026 | 6/7/2026 | A vulnerability was found in tiddly-gittly TidGi-Desktop up to 0.13.0. This impacts an unknown function of the file src/services/wiki/wikiWorker/loadWikiTiddlersWithSubWikis.ts of the component Git Repository Import. The manipulation results in code injection. The attack may be performed from remote. The exploit has… | |
| Aplazada | Crítica (9.6) | 0.30% | — | GiteaAI | 3/7/2026 | 6/7/2026 | Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write |