Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2494▼ 451 respecto a la semana anterior
Críticas / altas1280▼ 7 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
–

3658 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.7)0.22%—Gitroom PostizAI15/7/202615/7/2026
Postiz is an AI social media scheduling tool. Prior to 2.21.8, Postiz fails to verify Nowpayments IPN callback authenticity against the payment provider shared secret and reads the target subscription identifier from the untrusted request body, allowing a low-privileged account to grant arbitrary organizations…
AplazadaAlta (8.7)0.40%—Digital-peak DP CalendarAIJoomlaAI15/7/202623/7/2026
Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2 - The Joomla extension DP Calendar is vulnerable to an unauthenticated SQL injection.
AplazadaAlta (7.7)0.39%—Redhat Openshift GitopsAIArgoproj Argo CDAI15/7/202616/7/2026
A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objects. A namespace-scoped Argo CD instance can trigger deletion of a ClusterRole owned by a cluster-scoped Argo CD instance by crafting a name collision, resulting in a…
AplazadaCrítica (9.8)1.1%—Openasset Digital Asset ManagementAI14/7/202615/7/2026
An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name and description parameter of the Add/Update Project function
AnalizadaAlta (7.8)0.36%—Microsoft Github Copilot14/7/202622/7/2026
Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.
Pendiente de análisisAlta (8.9)0.47%—Redhat Openshift GitopsAIArgoproj Argo CDAI14/7/202611/8/2026
A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticated attacker with network access to the Argo CD repo-server to achieve remote code execution. Under certain conditions, the attacker may then manipulate cached data to deploy malicious Kubernetes…
AplazadaCrítica (9.2)0.51%—Mcp-gitlabAI13/7/202613/7/2026
mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to escape the intended path prefix and access arbitrary GitLab API resources using the…
ModificadaAlta (8.1)0.74%—Apache-airflow-providers-git13/7/202616/9/2026
The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification. An attacker who can intercept the network path between an Airflow worker and the Git server can impersonate the server (man-in-the-middle), capturing the SSH deploy key or…
Pendiente de análisisMedia (4.4)0.33%—Github CLIAIGithub CodespaceAIMicrosoft Visual Studio CodeAI9/7/202614/7/2026
GitHub CLI (gh) is GitHub’s official command line tool. From 2.10.0 through 2.95.0, connecting to a malicious Codespace with gh codespace jupyter can allow command execution because the command opens a JupyterLab URL supplied by a process inside the Codespace without validating that it is a loopback HTTP or HTTPS…
AnalizadaMedia (4.3)0.39%—Gitlab8/7/202610/7/2026
GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with minimal access permissions to read work item metadata from private projects due to missing authorization…
AnalizadaMedia (5.3)0.35%—Gitlab8/7/20269/7/2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an unauthenticated user to determine the existence of a private project due to improper authorization controls on cross-project…
AnalizadaMedia (5.4)0.40%—Gitlab8/7/20269/7/2026
GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary scripts in another user's browser session due to improper…
AnalizadaBaja (2.7)0.36%—Gitlab8/7/20269/7/2026
GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with auditor-level access to modify compliance violation records due to improper authorization on certain…
AnalizadaAlta (7.1)0.41%—Jupyterlab-git8/7/202615/7/2026
JupyterLab Git is a Git extension for JupyterLab. Prior to 0.54.0, jupyterlab-git uses fnmatch.fnmatchcase() in GitHandler.prepare() in jupyterlab_git/handlers.py to enforce excluded_paths, allowing an authenticated user on a case-insensitive filesystem to vary URL path casing and read excluded directories. This issue…
AnalizadaCrítica (9.3)0.53%—Jupyterlab-git8/7/202615/7/2026
JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames directly to innerHTML when rendering renamed files in commit history, allowing a crafted filename to execute JavaScript when a victim views the rename diff in the Git History…
AnalizadaMedia (5.4)0.39%—Gitlab8/7/20269/7/2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to execute arbitrary scripts in another user's browser session due to improper sanitization of user-supplied…
AnalizadaMedia (4.9)0.44%—Gitlab8/7/20269/7/2026
GitLab has remediated an issue in GitLab EE affecting all versions from 9.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to obtain another user's stored credentials due to improper authorization…
AnalizadaMedia (4.3)0.33%—Gitlab8/7/202629/9/2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to create a repository where the content displayed in the web interface differed from the content available…
AnalizadaMedia (5.3)0.08%—Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Lemans AU Lgit Firmware+756/7/20267/7/2026
Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits.
AnalizadaAlta (7.1)0.10%—Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Lemans AU Lgit FirmwareQualcomm Lemansau Firmware+496/7/20268/7/2026
Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security.
AnalizadaMedia (5.3)0.08%—Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm G3X GEN 2 Firmware+876/7/20267/7/2026
Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.
AnalizadaMedia (5.3)0.08%—Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+1056/7/20267/7/2026
Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification.
AnalizadaMedia (5.3)0.08%—Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm G3X GEN 2 Firmware+876/7/20267/7/2026
Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks.
AplazadaMedia (5.5)0.54%—Tiddly Gittly Tidgi DesktopAI5/7/20266/7/2026
A vulnerability was found in tiddly-gittly TidGi-Desktop up to 0.13.0. This impacts an unknown function of the file src/services/wiki/wikiWorker/loadWikiTiddlersWithSubWikis.ts of the component Git Repository Import. The manipulation results in code injection. The attack may be performed from remote. The exploit has…
AplazadaCrítica (9.6)0.30%—GiteaAI3/7/20266/7/2026
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write