Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2616▼ 309 respecto a la semana anterior
Críticas / altas1342▲ 71 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

3658 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.45%—GiteaAI3/7/20267/7/2026
Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches.
AplazadaAlta (7.5)0.48%—GiteaAI3/7/20267/7/2026
Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized.
AplazadaCrítica (9.6)0.46%—GiteaAI3/7/20267/7/2026
Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.
AplazadaAlta (8.1)0.43%—GiteaAI3/7/20266/7/2026
Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets.
AplazadaCrítica (9.1)0.52%—GiteaAI3/7/20267/7/2026
Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited template fields and trust model or object format values.
AplazadaMedia (5.3)0.29%—GiteaAI3/7/20267/7/2026
Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.
AplazadaCrítica (9.8)2.8%—Gitea Docker ImageAI3/7/20267/7/2026
Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.
AplazadaAlta (7.1)0.48%—GiteaAI3/7/20267/7/2026
Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be accepted more than once across web two-factor authentication flows and the Basic Auth X-Gitea-OTP path.
AplazadaCrítica (9.1)0.56%—GiteaAI3/7/20266/7/2026
Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint.
AnalizadaMedia (5.3)0.43%—Github Enterprise Server1/7/20266/7/2026
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token scoped to a GitHub App installation to perform certain write operations on public repositories outside the token's intended scope. This was possible because the authorization check only verified that…
AnalizadaMedia (6.3)0.32%—Github Enterprise Server30/6/20262/7/2026
A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to execute arbitrary JavaScript in another user's browser by injecting a crafted payload into the title of a Discussion in the Q&A category. The AnsweredQuestionStructuredDataComponent did not…
AnalizadaMedia (6)0.41%—Github Enterprise Server30/6/20262/7/2026
—
AnalizadaMedia (4.8)0.36%—Github Enterprise Server30/6/20262/7/2026
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth application requesting the manage_runners:org scope and directing a victim user to…
AplazadaCrítica (9.2)0.72%—GitlabAIGiteaAIForgejoAIGithubAI+230/6/202614/7/2026
Woodpecker before 3.15.0 matches the ApprovalAllowedUsers bypass list against pipeline.Author. For the GitLab forge driver, pipeline.Author is populated from the git commit author name (commit.author.name) carried in the webhook payload, which is attacker-controlled and not verified by GitLab. A user who can open a…
AplazadaBaja (2.1)0.37%—GitbucketAI29/6/202629/6/2026
A security flaw has been discovered in GitBucket up to 4.46.1. This affects the function Git.cloneRepository.setURI of the file src/main/scala/gitbucket/core/service/RepositoryCreationService.scala. Performing a manipulation of the argument url results in server-side request forgery. The attack is possible to be…
AplazadaCrítica (9.4)0.44%—Gitea ACT RunnerAIACTAI28/6/202630/6/2026
Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such as --pid=host, --cap-add, and --security-opt unchanged. A user…
AplazadaMedia (6)0.21%—Github MCP ServerAI26/6/202627/6/2026
GitHub MCP Server is GitHub's official MCP Server. From 0.22.0 until 1.1.2, when running in HTTP mode with --lockdown-mode enabled, the RepoAccessCache is implemented as a process-global singleton initialized with the first authenticated user's GraphQL client. All subsequent requests from different users share this…
AplazadaBaja (2)0.43%—Pretix-digitalAI25/6/202625/6/2026
Malicious HTML content could be injected into the content rendered by the pretix-digital plugin.
AnalizadaMedia (4.4)0.20%—Gitlab25/6/202626/6/2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed sensitive information to be written to application logs due to insufficient filtering in a CI/CD API endpoint.
AnalizadaMedia (4.3)0.34%—Gitlab25/6/202626/6/2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to bypass package protection rules and overwrite protected Maven package…
AnalizadaMedia (4.3)0.39%—Gitlab25/6/202626/6/2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with Reporter-level group permissions to view package metadata from projects with the Package Registry…
AnalizadaMedia (5.4)0.29%—Gitlab25/6/202626/6/2026
GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to read or modify another group's virtual registry cleanup policy settings without authorization.
AnalizadaBaja (3.1)0.29%—Gitlab25/6/202626/6/2026
GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with limited permissions to access project information due to insufficient authorization checks.
AnalizadaMedia (5.3)0.47%—Gitlab25/6/202626/6/2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to view confidential issue references on public projects due to improper authorization checks.
AnalizadaMedia (4.3)0.36%—Gitlab25/6/202626/6/2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.8 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to conceal content within a Snippet due to improper input validation.