Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
3659 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.40% | — | Gitlab | 22/4/2026 | 17/6/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user to cause denial of service when importing issues due to improper input validation. | |
| Analizada | Baja (2.7) | 0.38% | — | Gitlab | 22/4/2026 | 17/6/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user with project owner permissions to bypass group fork prevention settings due to improper authorization… | |
| Analizada | Media (6.5) | 0.45% | — | Gitlab | 22/4/2026 | 17/6/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service due to insufficient resource allocation limits when retrieving notes under certain conditions. | |
| Analizada | Media (6.5) | 0.40% | — | Gitlab | 22/4/2026 | 17/6/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.4 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service by overwhelming system resources under certain conditions due to insufficient resource allocation limits… | |
| Analizada | Media (6.5) | 0.40% | — | Gitlab | 22/4/2026 | 17/6/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service under certain conditions by exhausting server resources by making crafted requests to a discussions… | |
| Analizada | Alta (8.9) | 0.65% | — | Github Enterprise Server | 21/4/2026 | 17/6/2026 | A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to extract sensitive environment variables from the instance through a timing side-channel attack against the notebook rendering service. When private mode was disabled, the notebook viewer followed… | |
| Analizada | Alta (7.2) | 0.48% | — | Github Enterprise Server | 21/4/2026 | 17/6/2026 | An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server allows an authenticated attacker to access private repositories outside the intended installation scope, which can include write operations, via an authorization fallback that treated a… | |
| Analizada | Media (5.3) | 0.50% | — | Github Enterprise Server | 21/4/2026 | 17/6/2026 | An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to determine the names of private repositories by their numeric ID. The mobile upload policy API endpoint did not perform an early authorization check, and validation error messages included the… | |
| Analizada | Alta (7.5) | 0.74% | — | Github Enterprise Server | 21/4/2026 | 17/6/2026 | An incorrect regular expression vulnerability was identified in GitHub Enterprise Server that allowed an attacker to bypass OAuth redirect URI validation. An attacker with knowledge of a first-party OAuth application's registered callback URL could craft a malicious authorization link that, when clicked by a victim,… | |
| Analizada | Media (5.3) | 0.45% | — | Github Enterprise Server | 21/4/2026 | 17/6/2026 | An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed an attacker with admin access on one repository to modify the secret scanning push protection delegated bypass reviewer list on another repository by manipulating the owner_id parameter in the request body. Authorization was… | |
| Analizada | Alta (8.4) | 0.19% | — | Gitlawb Openclaude | 21/4/2026 | 17/6/2026 | OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Versions prior to 0.5.1 have a logic flaw in `bashToolHasPermission()` inside `src/tools/BashTool/bashPermissions.ts`. When the sandbox auto-allow feature is active and no explicit deny rule is configured, the… | |
| Analizada | Crítica (9) | 0.26% | — | Gitroom Postiz | 18/4/2026 | 17/6/2026 | Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitrary HTML, SVG, or other executable file types to the server by spoofing the `Content-Type` header. The uploaded files are then served by nginx with a Content-Type derived… | |
| Pendiente de análisis | Crítica (9.1) | 0.81% | — | Microsoft Asp.netAIMicrosoft IISAIDigital Knowledge KnowledgedeliverAI | 16/4/2026 | 17/6/2026 | Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState deserialization attacks | |
| Pendiente de análisis | Alta (7.4) | 0.53% | — | GIT FOR WindowsAI | 15/4/2026 | 17/6/2026 | Git for Windows is the Windows port of Git. Versions prior to 2.53.0.windows.3 do not have protections that prevent attackers from obtaining a user's NTLM hash. The NTLM hash can be obtained by tricking users into cloning a malicious repository, or checking out a malicious branch, that accesses an attacker-controlled… | |
| Analizada | Media (6.5) | 0.74% | — | Microsoft Github Copilot Chat | 14/4/2026 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized attacker to disclose information over a network. | |
| Modificada | Alta (8.1) | 0.93% | — | Simple-git Project Simple-git | 13/4/2026 | 15/7/2026 | simple-git enables running native Git commands from JavaScript. Versions up to and including 3.31.1 allow execution of arbitrary commands through Git option manipulation, bypassing safety checks meant to block dangerous options like -u and --upload-pack. The flaw stems from an incomplete fix for CVE-2022-25860, as… | |
| Analizada | Baja (2) | 0.18% | — | Paloaltonetworks Autonomous Digital Experience Manager | 13/4/2026 | 7/7/2026 | A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. | |
| Analizada | Alta (8.2) | 0.52% | — | Gitroom Postiz | 10/4/2026 | 17/6/2026 | Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endpoint is vulnerable to SSRF. Although the application validates the initially supplied URL and blocks direct private/internal hosts, it does not re-validate the final destination after HTTP redirects. As a result, an attacker can… | |
| Analizada | Alta (8.5) | 0.36% | — | Gitlab | 8/4/2026 | 24/7/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to invoke unintended server-side methods through websocket connections due to improper access control. | |
| Analizada | Baja (2.7) | 0.44% | — | Gitlab | 8/4/2026 | 24/7/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with custom role permissions to demote or remove higher-privileged group members due to improper authorization checks on member… | |
| Analizada | Media (5.4) | 0.35% | — | Gitlab | 8/4/2026 | 24/7/2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that, in customizable analytics dashboards, could have allowed an authenticated user to execute arbitrary JavaScript in the context of other users' browsers due to improper input… | |
| Analizada | Media (4.3) | 0.39% | — | Gitlab | 8/4/2026 | 20/7/2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user with auditor privileges to modify vulnerability flag data in private projects due to incorrect authorization. | |
| Analizada | Media (4.3) | 0.31% | — | Gitlab | 8/4/2026 | 25/7/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to access confidential issues assigned to other users via CSV export due to insufficient authorization checks. | |
| Analizada | Media (4.3) | 0.31% | — | Gitlab | 8/4/2026 | 25/7/2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with developer-role permissions to modify protected environment settings due to improper authorization checks in the API. | |
| Analizada | Media (5.7) | 0.43% | — | Gitlab | 8/4/2026 | 25/7/2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.0.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that in Code Quality reports could have allowed an authenticated user to leak IP addresses of users viewing the report via specially crafted content. |