Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2636▼ 301 respecto a la semana anterior
Críticas / altas1348▲ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
3658 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.1) | 0.25% | — | Gitlab | 25/6/2026 | 26/6/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to make requests to internal network resources through mirror synchronization… | |
| Analizada | Alta (7.5) | 0.63% | — | Gitlab | 25/6/2026 | 26/6/2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions could have allowed a user to access sensitive information that had already been committed to a project, due to insufficient output filtering in Duo Workflows. | |
| Analizada | Media (5.3) | 0.30% | — | Gitlab | 25/6/2026 | 26/6/2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 prior to 18.11.6, 19.0 prior to 19.0.3, and 19.1 prior to 19.1.1 in which incorrect authorization in DAST site profile management could allow a user with Developer role to exfiltrate DAST site profile secrets under certain conditions. | |
| Analizada | Media (6.1) | 0.43% | — | Gitlab | 25/6/2026 | 26/6/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to improper path validation under certain… | |
| Analizada | Media (5.4) | 0.35% | — | Gitlab | 25/6/2026 | 26/6/2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code in the context of another user's session,… | |
| Analizada | Baja (3.8) | 0.33% | — | Gitlab | 25/6/2026 | 26/6/2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with custom role permissions to view, create, or delete protected environment configurations despite CI/CD… | |
| Aplazada | Media (4.3) | 0.27% | — | Jenkins Gitee PluginAI | 24/6/2026 | 25/6/2026 | An incorrect permission check in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of credentials stored in Jenkins. | |
| Aplazada | Media (5.4) | 0.14% | — | Jenkins Gitee PluginAI | 24/6/2026 | 25/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method. | |
| Aplazada | Media (5.4) | 0.23% | — | Jenkins Gitee PluginAI | 24/6/2026 | 25/6/2026 | Missing permission checks in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allow attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method. | |
| Analizada | Media (4.3) | 0.28% | — | Jenkins GIT Parameter | 24/6/2026 | 26/6/2026 | A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_ and earlier allows attackers with Item/Read permission to obtain information about the SCM repository used by a job, such as branch names, tag names, and revision metadata. | |
| Analizada | Media (4.3) | 0.28% | — | Jenkins Github Branch Source | 24/6/2026 | 26/6/2026 | A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v205fd594c821 and earlier allows attackers with Overall/Read permission to obtain the URLs of GitHub Enterprise servers configured in the global plugin configuration. | |
| Analizada | Media (5) | 0.25% | — | Jenkins GIT Client | 24/6/2026 | 26/6/2026 | Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH wrapper script, allowing attackers able to control the name of a build's working directory to execute arbitrary operating system commands on the agent. | |
| Aplazada | Media (5.5) | 0.18% | — | TortoisegitAITortoisegitblameAI | 24/6/2026 | 25/6/2026 | Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary File Write in TortoiseGit | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft Github Copilot | 22/6/2026 | 5/10/2026 | GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is indirect prompt injection. | |
| Aplazada | Alta (8.8) | 0.22% | — | Centraldogma-server-mirror-gitAI | 22/6/2026 | 22/6/2026 | A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-the-middle attacks and compromise mirrored repositories. | |
| Analizada | Alta (7.5) | 0.92% | — | Microsoft Github Copilot Chat | 19/6/2026 | 17/8/2026 | Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. | |
| Aplazada | Media (4.3) | 0.40% | — | Equalize Digital Accessibility CheckerAI | 18/6/2026 | 18/6/2026 | The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.42.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for… | |
| Aplazada | Baja (2.2) | 0.09% | — | Github WorkflowsAI | 17/6/2026 | 22/6/2026 | The github_workflows module constructs local directory paths from user-controlled repository names without validating for symlinks. A local attacker sharing the scan directory can plant a symlink at the predictable output path, causing workflow data to be written to an attacker-chosen location. | |
| Aplazada | Media (4.8) | 0.20% | — | Gitroom PostizAI | 17/6/2026 | 17/6/2026 | Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accepted a signed token and applied subscription-enforcement side effects to the organization referenced in that token's claims, without verifying the token's intended purpose. The endpoint,… | |
| Aplazada | Crítica (9.9) | 0.28% | — | Gitroom PostizAI | 17/6/2026 | 18/6/2026 | Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an attacker-controlled JSON blob into a session-shape JWT using the application's JWT_SECRET, and the auth middleware trusted every claim in that JWT without re-resolving the user from the database. Any… | |
| Aplazada | Alta (8.1) | 0.43% | — | GitaAI | 17/6/2026 | 5/10/2026 | Unauthenticated Local File Inclusion in Gita <= 1.11 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Easydigitaldownloads Easy Digital DownloadsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.6.5 versions. | |
| Aplazada | Alta (8.5) | 1.4% | — | KanadojoAIGithub ActionsAI | 11/6/2026 | 14/7/2026 | KanaDojo contains a command injection vulnerability that allows an attacker with pull request access to execute arbitrary shell commands by inserting shell metacharacters into the version or changes fields of patchNotesData.json, which are interpolated unsanitized into a child_process.execSync() call in the… | |
| Analizada | Media (4.3) | 0.32% | — | Gitlab | 11/6/2026 | 17/6/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions, could have allowed an unauthenticated user to impersonate the GitLab Support Bot and inject arbitrary content via a specially crafted Service Desk… | |
| Analizada | Media (6.5) | 0.36% | — | Gitlab | 11/6/2026 | 17/6/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to read arbitrary files from the Gitaly server and access internal network resources during repository… |