Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2556▼ 352 respecto a la semana anterior
Críticas / altas1335▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
259 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.69% | — | Refined-github Project Refined-github | 9/6/2021 | 17/6/2026 | The Refined GitHub browser extension before 21.6.8 might allow XSS via a link in a document. NOTE: github.com sends Content-Security-Policy headers to, in general, address XSS and other concerns. | |
| Modificada | Media (4.4) | 0.40% | — | Github Codeql Action | 25/5/2021 | 17/6/2026 | Github's CodeQL action is provided to run CodeQL-based code scanning on non-GitHub CI/CD systems and requires a GitHub access token to connect to a GitHub repository. The runner and its documentation previously suggested passing the GitHub token as a command-line parameter to the process instead of reading it from a… | |
| Modificada | Alta (8.8) | 1.0% | — | Github Enterprise Server | 14/5/2021 | 17/6/2026 | A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be granted during a GitHub App's user-authorization web flow than was displayed to the user during approval. To exploit this vulnerability, an attacker would need to create a GitHub App on the instance and… | |
| Modificada | Alta (7.8) | 2.3% | — | Microsoft Visual Studio Code Github Pull Requests AND Issues | 13/4/2021 | 17/6/2026 | Visual Studio Code GitHub Pull Requests and Issues Extension Remote Code Execution Vulnerability | |
| Modificada | Media (6.5) | 1.3% | — | Github Enterprise Server | 2/4/2021 | 17/6/2026 | An improper access control vulnerability was identified in GitHub Enterprise Server that allowed access tokens generated from a GitHub App's web authentication flow to read private repository metadata via the REST API without having been granted the appropriate permissions. To exploit this vulnerability, an attacker… | |
| Modificada | Alta (8.8) | 2.5% | — | Github Enterprise Server | 23/3/2021 | 17/6/2026 | A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it possible to override environment variables leading to code execution on the… | |
| Modificada | Alta (8.1) | 1.0% | — | Github | 3/3/2021 | 17/6/2026 | An improper access control vulnerability was identified in the GitHub Enterprise Server GraphQL API that allowed authenticated users of the instance to modify the maintainer collaboration permission of a pull request without proper authorization. By exploiting this vulnerability, an attacker would be able to gain… | |
| Modificada | Media (6.5) | 0.84% | — | Github | 3/3/2021 | 17/6/2026 | An improper access control vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with the ability to fork a repository to disclose Actions secrets for the parent repository of the fork. This vulnerability existed due to a flaw that allowed the base reference of a pull request to… | |
| Modificada | Media (6.5) | 0.95% | — | Github | 3/3/2021 | 17/6/2026 | An improper access control vulnerability was identified in GitHub Enterprise Server that allowed authenticated users of the instance to gain write access to unauthorized repositories via specifically crafted pull requests and REST API requests. An attacker would need to be able to fork the targeted repository, a… | |
| Modificada | Alta (8.8) | 3.1% | — | Github | 3/3/2021 | 17/6/2026 | A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration of the underlying parsers used by GitHub Pages were not sufficiently restricted and made it possible to execute commands on the GitHub Enterprise… | |
| Modificada | Alta (8.8) | 3.7% | — | Github | 27/8/2020 | 17/6/2026 | A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration of the underlying parsers used by GitHub Pages were not sufficiently restricted and made it possible to execute commands on the GitHub Enterprise… | |
| Modificada | Media (4.3) | 1.1% | — | Github | 27/8/2020 | 17/6/2026 | An improper access control vulnerability was identified in GitHub Enterprise Server that allowed authenticated users of the instance to determine the names of unauthorized private repositories given their numerical IDs. This vulnerability did not allow unauthorized access to any repository content besides the name.… | |
| Modificada | Media (4.3) | 0.69% | — | Jenkins Github Coverage Reporter | 2/7/2020 | 17/6/2026 | Jenkins GitHub Coverage Reporter Plugin 1.8 and earlier stores secrets unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system or read permissions on the system configuration. | |
| Modificada | Media (6.5) | 1.6% | — | Github Flavored Markdown Project Github Flavored MarkdownFedoraproject Fedora | 1/7/2020 | 17/6/2026 | The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to parse certain inputs. An attacker could craft a markdown table which would take an unreasonably long time to process, causing a denial of service. This issue does not affect the upstream cmark project. The issue has been… | |
| Modificada | Crítica (9.8) | 1.6% | — | Github | 3/6/2020 | 17/6/2026 | An improper access control vulnerability was identified in the GitHub Enterprise Server API that allowed an organization member to escalate permissions and gain access to unauthorized repositories within an organization. This vulnerability affected all versions of GitHub Enterprise Server prior to 2.21 and was fixed… | |
| Modificada | Media (4.3) | 0.68% | — | Jenkins Pipeline Github Notify Step | 12/2/2020 | 17/6/2026 | A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins. | |
| Modificada | Media (4.3) | 0.68% | — | Jenkins Pipeline Github Notify Step | 12/2/2020 | 17/6/2026 | A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Alta (8.8) | 0.68% | — | Jenkins Pipeline Github Notify Step | 12/2/2020 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Alta (8.8) | 2.1% | — | Jenkins Github Authentication | 30/4/2019 | 17/6/2026 | Jenkins GitHub Authentication Plugin 0.31 and earlier did not use the state parameter of OAuth to prevent CSRF. | |
| Modificada | Crítica (9.8) | 21% | — | Github | 28/3/2019 | 17/6/2026 | The Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated remote attackers to execute arbitrary code. This occurs because the enterprise session secret is always the same, and can be found in the product's source code. By sending a crafted cookie signed with… | |
| Modificada | Media (5.9) | 0.85% | — | Jenkins Github Oauth | 6/2/2019 | 17/6/2026 | An session fixation vulnerability exists in Jenkins GitHub Authentication Plugin 0.29 and earlier in GithubSecurityRealm.java that allows unauthorized attackers to impersonate another user if they can control the pre-authentication session. | |
| Modificada | Media (4.3) | 1.1% | — | Jenkins Github Oauth | 6/2/2019 | 17/6/2026 | An exposure of sensitive information vulnerability exists in Jenkins GitHub Authentication Plugin 0.29 and earlier in GithubSecurityRealm/config.jelly that allows attackers able to view a Jenkins administrator's web browser output, or control the browser (e.g. malicious extension) to retrieve the configured client… | |
| Modificada | Alta (8.8) | 91% | — | Jenkins Github | 26/6/2018 | 17/6/2026 | A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows attackers to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Media (6.5) | 0.99% | — | Jenkins Github Pull Request Builder | 5/6/2018 | 17/6/2026 | A exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin 1.41.0 and older in GhprbGitHubAuth.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing… | |
| Modificada | Media (4.3) | 0.64% | — | Jenkins Github Branch Source | 5/6/2018 | 17/6/2026 | A server-side request forgery vulnerability exists in Jenkins GitHub Branch Source Plugin 2.3.4 and older in Endpoint.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL. |