Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2634▼ 301 respecto a la semana anterior
Críticas / altas1351▲ 82 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
–

3658 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.2)0.10%—Qualcomm Qca6391 FirmwareQualcomm Qca6564au FirmwareQualcomm Qca6574 FirmwareQualcomm Qca6574a Firmware+2691/6/202622/7/2026
Memory Corruption when processing display command line information due to improper initialization of a variable.
AnalizadaMedia (6.4)0.06%—Qualcomm Snapdragon G1 GEN 2 Gaming Platform FirmwareQualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm C-v2x 9150 FirmwareQualcomm Cq7790 Firmware+2321/6/202622/7/2026
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
AnalizadaMedia (5.5)0.09%—Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6700 Firmware+1831/6/202622/7/2026
Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.
AnalizadaAlta (7.8)0.07%—Qualcomm Cologne FirmwareQualcomm Cq7790 FirmwareQualcomm Cq8725s FirmwareQualcomm Cq8750m Firmware+1371/6/202622/7/2026
Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization.
AnalizadaAlta (7.8)0.07%—Qualcomm Snapdragon 480 5G Mobile Platform FirmwareQualcomm Snapdragon 480+ 5G Mobile Platform FirmwareQualcomm Snapdragon 6 GEN 1 Mobile Platform FirmwareQualcomm Snapdragon 6 GEN 3 Mobile Platform Firmware+2611/6/202622/7/2026
Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.
AplazadaCrítica (10)0.44%—Cloudpirates Open Source Helm ChartsAIGithub ActionsAI1/6/202622/7/2026
CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (generate-schema.yaml) exposes sensitive credentials (Personal Access Token and SSH signing key) to fork-controlled code due to unsafe checkout and credential handling practices. This issue has been…
AplazadaCrítica (10)0.44%—Cloudpirates Open Source Helm ChartsAIGithub ActionsAI1/6/202622/7/2026
CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (pull-request.yaml) executes attacker-controlled code from fork pull requests in a privileged context, exposing repository secrets including Docker Hub credentials and tokens without requiring…
AnalizadaCrítica (9.1)0.45%—Github CLI29/5/202621/7/2026
GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization header in API requests to TUF repository mirrors via gh attestation, gh release verify, and gh release verify-asset commands. The CLI uses a shared HTTP client with an authentication layer that…
AplazadaBaja (1)0.20%—Indian Motorcycle Scout Bobber Infotainment Digital Round DisplayAIIndian Motorcycle Wireless Control ModuleAI29/5/202621/7/2026
Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. The Infotainment uses presence of Wireless Control Module (WCM) traffic during its boot window as a proxy for whether an…
AplazadaBaja (1)0.20%—Indian Motorcycle Scout Bobber Infotainment Digital Round DisplayAI29/5/202621/7/2026
Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. The Infotainment uses presence of Wireless Control Module (WCM) traffic during its boot window as a proxy for whether an…
AplazadaCrítica (9.3)0.49%—GitbutlerAI28/5/202617/6/2026
GitButler is a modern Git-based version control interface for AI-powered workflows. Prior to 0.19.7, a emote code execution vulnerability exists in the Tauri-based GitButler desktop application. An attacker can inject a malicious link in a pull request body, which if clicked by the user allows for arbitrary script…
Pendiente de análisisAlta (8.2)0.32%—Espressif Shared Github DangerjsAI28/5/202617/6/2026
Espressif Shared GitHub DangerJS is a reusable GitHub Action CI DangerJS workflow for Espressif GitHub projects. Prior to 1.0.1, the action's entrypoint.sh invoked DangerJS from the caller's workspace after copying the fork's checkout into it, creating an untrusted search path for both binary resolution and Node.js…
AnalizadaMedia (4.3)0.33%—Gitlab28/5/202617/6/2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed a blocked Project Access Token to continue accessing private resources due to incorrect authorization enforcement.
AplazadaMedia (4.3)0.47%—Equalize Digital Accessibility CheckerAI28/5/202617/6/2026
The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.42.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for…
AplazadaMedia (4.3)0.20%—Easydigitaldownloads Easy Digital DownloadsAI28/5/202617/6/2026
The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.7. This is due to missing nonce verification in the `handle_oauth_redirect()` function, which is registered on the `admin_init` hook and processes Square OAuth tokens from a…
AplazadaCrítica (9.3)1.3%—Github ActionsAISherlockAI27/5/202617/6/2026
Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.yml is vulnerable to command injection via the pull_request_target trigger. Any GitHub user can execute arbitrary commands on the CI runner and exfiltrate the…
AnalizadaMedia (4.3)0.31%—Gitlab27/5/202617/6/2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to access CI data from a different ref type than intended.
AnalizadaMedia (5.3)0.46%—Gitlab27/5/202617/6/2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an unauthorized user to enumerate private projects due to incorrect authorization checks.
AnalizadaMedia (4.3)0.34%—Gitlab27/5/202617/6/2026
GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that when foundational flows were enabled at the group level, could have allowed an authenticated user with developer-role permissions to bypass flow restrictions under certain…
AnalizadaAlta (8.2)0.36%—Gitlab27/5/202617/6/2026
GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that, under certain conditions, could have allowed an authenticated user to cause specific Duo AI workflows to run under another user's identity due to improper user identity…
AnalizadaMedia (4.3)0.33%—Gitlab27/5/202617/6/2026
GitLab has remediated an issue in GitLab EE affecting all versions from 11.5 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to access sensitive deployment data on projects due to improper authorization…
AnalizadaMedia (6.5)0.47%—Gitlab27/5/202617/6/2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to cause denial of service due to insufficient validation.
AnalizadaMedia (4.3)0.14%—Kostyasha Github Integration27/5/202617/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Integration Plugin 0.7.3 and earlier allows attackers to attackers to trigger a build for a pull request.
AnalizadaMedia (5.4)0.33%—Go-git Project Go-git27/5/202617/6/2026
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside the intended checkout target, including the repository's .git directory. These validations were introduced in upstream…
AnalizadaBaja (2.3)0.43%—Go-git Project Go-git27/5/202617/6/2026
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in single quotes without escaping single quotes embedded inside the path. A repository path containing a single quote can…