Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
3659 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.4) | 0.26% | — | Go-git Project Go-git | 8/5/2026 | 17/6/2026 | go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-git may leak HTTP authentication credentials when following redirects during smart-HTTP clone and fetch operations. This issue has been patched in versions 5.18.0 and 6.0.0-alpha.2. | |
| Analizada | Media (5.9) | 0.26% | — | Github Enterprise Server | 7/5/2026 | 17/6/2026 | A reflected HTML injection vulnerability was identified in the GitHub Enterprise Server Management Console login page that could allow credential theft. The redirect_to query parameter on the /setup/unlock endpoint was reflected into an HTML attribute without proper sanitization, enabling an attacker to inject a form… | |
| Analizada | Alta (7.9) | 0.86% | — | Github Enterprise Server | 7/5/2026 | 17/6/2026 | A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access internal services by exploiting URL parser confusion between the validation layer and the HTTP request library. The hostname validation used a different URL parser than… | |
| Analizada | Media (6.3) | 0.66% | — | Github Enterprise Server | 7/5/2026 | 17/6/2026 | A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause service disruption by sending crafted requests with deeply nested JSON payloads to an unauthenticated API endpoint. The endpoint parsed user-controlled JSON request bodies without size or… | |
| Analizada | Media (6.3) | 0.41% | — | Github Enterprise Server | 7/5/2026 | 17/6/2026 | An authentication bypass vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to create a local user account, bypassing the configured external identity provider. When external authentication was enabled, the signup endpoint did not properly enforce the authentication… | |
| Analizada | Alta (7.8) | 0.22% | — | Gitpython Project Gitpython | 7/5/2026 | 17/6/2026 | GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() converts embedded newlines into indented continuation lines (e.g. \n becomes \n\t), but Git still… | |
| Analizada | Alta (7.8) | 0.44% | — | Gitpython Project Gitpython | 7/5/2026 | 17/6/2026 | GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository’s .git directory via insufficient… | |
| Modificada | Crítica (9.8) | 0.71% | — | Gitpython Project Gitpython | 7/5/2026 | 17/6/2026 | GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options)). A string like "--branch main --config core.hooksPath=/x" passes validation (starts with --branch), but after split… | |
| Analizada | Alta (8.8) | 0.90% | — | Gitpython Project Gitpython | 7/5/2026 | 17/6/2026 | GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes… | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Qxm1096 FirmwareQualcomm Robotics RB2 FirmwareQualcomm Robotics RB5 FirmwareQualcomm Sa4150p Firmware+172 | 4/5/2026 | 29/6/2026 | Memory Corruption when copying data from a freed source while executing performance counter deselect operation. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Qca8695au FirmwareQualcomm Qca9367 FirmwareQualcomm Qca9377 FirmwareQualcomm Qcc710 Firmware+184 | 4/5/2026 | 30/9/2026 | Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified. | |
| Analizada | Alta (7.5) | 0.22% | — | Qualcomm Snapdragon X65 5G Modem-rf FirmwareQualcomm Snapdragon X72 5G Modem-rf FirmwareQualcomm Snapdragon X75 5G Modem-rf FirmwareQualcomm Srv1h Firmware+253 | 4/5/2026 | 30/9/2026 | Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming. | |
| Analizada | Alta (7.5) | 0.22% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+241 | 4/5/2026 | 30/9/2026 | Transient DOS when processing target power rate tables during channel configuration. | |
| Aplazada | Alta (7.1) | 0.60% | — | Videoflow Digital Video Protection DVPAI | 29/4/2026 | 17/6/2026 | VideoFlow Digital Video Protection DVP 2.10 contains an authenticated directory traversal vulnerability that allows attackers with valid credentials to disclose arbitrary files by injecting path traversal sequences in the ID parameter. Attackers can submit requests to downloadsys.pl, download_xml.pl, download.pl,… | |
| Aplazada | Media (5.3) | 0.21% | — | Videoflow Digital Video Protection DVPAI | 29/4/2026 | 17/6/2026 | VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows authenticated attackers to execute arbitrary system commands by exploiting a cross-site request forgery flaw in the web management interface. Attackers with valid credentials can leverage the CSRF… | |
| Analizada | Crítica (9) | 0.50% | — | Jenkins Github | 29/4/2026 | 17/6/2026 | Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITScm polling", resulting in a stored cross-site scripting (XSS) vulnerability exploitable by non-anonymous attackers with Overall/Read permission. | |
| Analizada | Media (4.3) | 0.28% | — | Jenkins Github Branch Source | 29/4/2026 | 17/6/2026 | A missing permission check in Jenkins GitHub Branch Source Plugin 1967.vdea_d580c1a_b_a_ and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL with attacker-specified GitHub App credentials. | |
| Aplazada | Media (5.5) | 3.2% | — | Divyanshu-hash Gitpilot-mcpAI | 25/4/2026 | 17/6/2026 | A vulnerability has been found in Divyanshu-hash GitPilot-MCP up to 9ed9f153ba4158a2ad230ee4871b25130da29ffd. This impacts the function repo_path of the file main.py. Such manipulation of the argument command leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public… | |
| Modificada | Alta (8.2) | 1.0% | — | Simple-git Project Simple-git | 25/4/2026 | 15/7/2026 | Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed… | |
| Analizada | Media (5.4) | 0.24% | — | Gitlab | 22/4/2026 | 17/6/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed a user to use invalidated or incorrectly scoped credentials to access Virtual Registries under certain conditions. | |
| Analizada | Alta (8.1) | 0.59% | — | Gitlab | 22/4/2026 | 17/6/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.4 and 18.11 before 18.11.1 that could have allowed an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to improper path validation under certain conditions. | |
| Analizada | Media (4.3) | 0.39% | — | Gitlab | 22/4/2026 | 17/6/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that could have allowed an authenticated user to access titles of confidential or private issues in public projects due to improper access control in the issue description rendering process. | |
| Analizada | Media (6.1) | 0.36% | — | Gitlab | 22/4/2026 | 17/6/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.1.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an unauthenticated user to access tokens in the Storybook development environment due to improper input validation. | |
| Analizada | Alta (8.1) | 0.29% | — | Gitlab | 22/4/2026 | 17/6/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an unauthenticated user to execute GraphQL mutations on behalf of authenticated users due to insufficient CSRF protection. | |
| Analizada | Baja (3.5) | 0.26% | — | Gitlab | 22/4/2026 | 17/6/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user to load unauthorized content into another user's browser due to improper input validation in the Mermaid sandbox. |