Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2616▼ 309 respecto a la semana anterior
Críticas / altas1342▲ 71 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
3658 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.45% | — | GiteaAI | 3/7/2026 | 7/7/2026 | Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches. | |
| Aplazada | Alta (7.5) | 0.48% | — | GiteaAI | 3/7/2026 | 7/7/2026 | Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized. | |
| Aplazada | Crítica (9.6) | 0.46% | — | GiteaAI | 3/7/2026 | 7/7/2026 | Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering. | |
| Aplazada | Alta (8.1) | 0.43% | — | GiteaAI | 3/7/2026 | 6/7/2026 | Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets. | |
| Aplazada | Crítica (9.1) | 0.52% | — | GiteaAI | 3/7/2026 | 7/7/2026 | Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited template fields and trust model or object format values. | |
| Aplazada | Media (5.3) | 0.29% | — | GiteaAI | 3/7/2026 | 7/7/2026 | Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries. | |
| Aplazada | Crítica (9.8) | 2.8% | — | Gitea Docker ImageAI | 3/7/2026 | 7/7/2026 | Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled. | |
| Aplazada | Alta (7.1) | 0.48% | — | GiteaAI | 3/7/2026 | 7/7/2026 | Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be accepted more than once across web two-factor authentication flows and the Basic Auth X-Gitea-OTP path. | |
| Aplazada | Crítica (9.1) | 0.56% | — | GiteaAI | 3/7/2026 | 6/7/2026 | Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint. | |
| Analizada | Media (5.3) | 0.43% | — | Github Enterprise Server | 1/7/2026 | 6/7/2026 | An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token scoped to a GitHub App installation to perform certain write operations on public repositories outside the token's intended scope. This was possible because the authorization check only verified that… | |
| Analizada | Media (6.3) | 0.32% | — | Github Enterprise Server | 30/6/2026 | 2/7/2026 | A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to execute arbitrary JavaScript in another user's browser by injecting a crafted payload into the title of a Discussion in the Q&A category. The AnsweredQuestionStructuredDataComponent did not… | |
| Analizada | Media (6) | 0.41% | — | Github Enterprise Server | 30/6/2026 | 2/7/2026 | — | |
| Analizada | Media (4.8) | 0.36% | — | Github Enterprise Server | 30/6/2026 | 2/7/2026 | A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth application requesting the manage_runners:org scope and directing a victim user to… | |
| Aplazada | Crítica (9.2) | 0.72% | — | GitlabAIGiteaAIForgejoAIGithubAI+2 | 30/6/2026 | 14/7/2026 | Woodpecker before 3.15.0 matches the ApprovalAllowedUsers bypass list against pipeline.Author. For the GitLab forge driver, pipeline.Author is populated from the git commit author name (commit.author.name) carried in the webhook payload, which is attacker-controlled and not verified by GitLab. A user who can open a… | |
| Aplazada | Baja (2.1) | 0.37% | — | GitbucketAI | 29/6/2026 | 29/6/2026 | A security flaw has been discovered in GitBucket up to 4.46.1. This affects the function Git.cloneRepository.setURI of the file src/main/scala/gitbucket/core/service/RepositoryCreationService.scala. Performing a manipulation of the argument url results in server-side request forgery. The attack is possible to be… | |
| Aplazada | Crítica (9.4) | 0.44% | — | Gitea ACT RunnerAIACTAI | 28/6/2026 | 30/6/2026 | Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such as --pid=host, --cap-add, and --security-opt unchanged. A user… | |
| Aplazada | Media (6) | 0.21% | — | Github MCP ServerAI | 26/6/2026 | 27/6/2026 | GitHub MCP Server is GitHub's official MCP Server. From 0.22.0 until 1.1.2, when running in HTTP mode with --lockdown-mode enabled, the RepoAccessCache is implemented as a process-global singleton initialized with the first authenticated user's GraphQL client. All subsequent requests from different users share this… | |
| Aplazada | Baja (2) | 0.43% | — | Pretix-digitalAI | 25/6/2026 | 25/6/2026 | Malicious HTML content could be injected into the content rendered by the pretix-digital plugin. | |
| Analizada | Media (4.4) | 0.20% | — | Gitlab | 25/6/2026 | 26/6/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed sensitive information to be written to application logs due to insufficient filtering in a CI/CD API endpoint. | |
| Analizada | Media (4.3) | 0.34% | — | Gitlab | 25/6/2026 | 26/6/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to bypass package protection rules and overwrite protected Maven package… | |
| Analizada | Media (4.3) | 0.39% | — | Gitlab | 25/6/2026 | 26/6/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with Reporter-level group permissions to view package metadata from projects with the Package Registry… | |
| Analizada | Media (5.4) | 0.29% | — | Gitlab | 25/6/2026 | 26/6/2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to read or modify another group's virtual registry cleanup policy settings without authorization. | |
| Analizada | Baja (3.1) | 0.29% | — | Gitlab | 25/6/2026 | 26/6/2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with limited permissions to access project information due to insufficient authorization checks. | |
| Analizada | Media (5.3) | 0.47% | — | Gitlab | 25/6/2026 | 26/6/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to view confidential issue references on public projects due to improper authorization checks. | |
| Analizada | Media (4.3) | 0.36% | — | Gitlab | 25/6/2026 | 26/6/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.8 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to conceal content within a Snippet due to improper input validation. |