Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2531▼ 362 respecto a la semana anterior
Críticas / altas1338▲ 72 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
3657 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6) | 0.29% | — | Github Enterprise Server | 22/9/2026 | 2/10/2026 | An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of the instance to read the raw diff or patch of pull requests in private repositories without authorization. Access tokens for raw pull request diffs and patches were scoped to the repository name and… | |
| Pendiente de análisis | Crítica (9.1) | 0.52% | — | Gitroom PostizAI | 22/9/2026 | 22/9/2026 | Postiz generates security-sensitive credentials using `Math.random()` instead of a cryptographically secure source. The same helper is used for OAuth access tokens, authorization codes, client secrets, organization API keys, and PKCE verifiers, meaning these credentials depend entirely on V8’s deterministic… | |
| Analizada | Alta (7) | 0.05% | — | Qualcomm Lemans AU Lgit FirmwareQualcomm Lemansau FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p Firmware+25 | 17/9/2026 | 22/9/2026 | Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying. | |
| Analizada | Alta (7.5) | 0.19% | — | Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+372 | 17/9/2026 | 22/9/2026 | Transient DOS when processing authentication frames with invalid FILS information element header lengths. | |
| Pendiente de análisis | Media (6.8) | 0.43% | — | Jenkins Gitee PluginAI | 16/9/2026 | 18/9/2026 | Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in build causes, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to trigger builds via the Jenkins Gitee Plugin webhook endpoint. | |
| Pendiente de análisis | Media (5.4) | 0.23% | — | Jenkins Gitlab PluginAI | 16/9/2026 | 18/9/2026 | Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API token credentials under a cache key derived from the credentials ID alone, omitting the folder in which the credentials are resolved, allowing attackers with Item/Configure permission to access GitLab… | |
| Analizada | Media (4.4) | 0.32% | — | Gitlab | 16/9/2026 | 28/9/2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an authenticated user with Owner or Maintainer permissions could have silently disabled protected environment deployment approval requirements, allowing… | |
| Analizada | Media (4.3) | 0.40% | — | Gitlab | 16/9/2026 | 28/9/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to prevent another user from modifying their group settings due to improper validation of group URL slugs… | |
| Analizada | Media (4.3) | 0.38% | — | Gitlab | 16/9/2026 | 28/9/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that an authenticated user with developer-role permissions could substitute package file content and hide packages from their owners due to improper authorization checks in the… | |
| Analizada | Alta (8.5) | 0.38% | — | Gitlab | 16/9/2026 | 28/9/2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions could have allowed an authenticated user with developer permissions to execute a policy test pipeline on projects within their group and access protected… | |
| Analizada | Media (6.1) | 0.27% | — | Gitlab | 16/9/2026 | 28/9/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an authenticated user could have induced a targeted user to perform unintended state-changing HTTP requests due to improper sanitization of… | |
| Analizada | Media (6.8) | 0.34% | — | Gitlab | 16/9/2026 | 28/9/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user with project-level permissions to access restricted file contents on the server or cause denial of service… | |
| Analizada | Alta (7.5) | 0.49% | — | Gitlab | 16/9/2026 | 28/9/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper resource allocation limits in the GraphQL complexity… | |
| Analizada | Media (4.7) | 0.24% | — | Gitlab | 16/9/2026 | 28/9/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to execute arbitrary JavaScript in the context of a targeted user's session due to improper sanitization of… | |
| Analizada | Media (4.3) | 0.31% | — | Gitlab | 16/9/2026 | 28/9/2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.11 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user with the Security Manager role to execute arbitrary CI/CD jobs and access protected variables within group… | |
| Analizada | Alta (7.5) | 0.50% | — | Gitlab | 16/9/2026 | 28/9/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper resource allocation limits in the GraphQL complexity… | |
| Analizada | Media (6.4) | 0.29% | — | Gitlab | 16/9/2026 | 28/9/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed a developer user to perform actions in the context of another user's merge request commit due to a race condition issue in pipeline… | |
| Aplazada | Crítica (9.8) | 2.9% | — | Zereight Mcp-gitlabAI | 15/9/2026 | 30/9/2026 | `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`SSE=true`) exposes all MCP tools without any authentication. The `upload_markdown` tool reads arbitrary files from the server's local filesystem via an unsanitized `file_path` parameter and uploads… | |
| Aplazada | Crítica (9.6) | 0.53% | — | Zereight Mcp-gitlabAI | 15/9/2026 | 30/9/2026 | `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web page can use DNS rebinding to route browser requests to a victim's local MCP listener while preserving an… | |
| Aplazada | Crítica (9.6) | 0.43% | — | Zereight Mcp-gitlabAI | 15/9/2026 | 30/9/2026 | `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, the server reads the `X-GitLab-API-URL` HTTP request header and uses it as the base URL for all outbound GitLab API calls made… | |
| Analizada | Alta (8.5) | 0.68% | — | Gitlab | 15/9/2026 | 28/9/2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 under certain conditions could allow an authenticated user to achieve remote code execution by importing a specially crafted Git project export to overflow the Unicode conversion buffer… | |
| Analizada | Media (4.3) | 0.23% | — | Gitlab | 15/9/2026 | 28/9/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that certain conditions could have allowed an authenticated user to access sensitive credentials and tokens without transiting the expected proxy due to improper authorization… | |
| Aplazada | Alta (7.1) | 0.53% | — | Github ActionsAI | 15/9/2026 | 30/9/2026 | githubtoplanguages generates a user's top GitHub languages as an SVG. The .github/workflows/discord-issue.yml workflow runs when an issue is opened or closed and interpolates github.event.issue.title directly into the Bash assignment for ISSUE_TITLE before shell parsing. An issue title containing shell… | |
| Analizada | Alta (7.7) | 0.21% | — | Gitlab | 15/9/2026 | 28/9/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to access CI/CD variables outside their intended environment scope due to improper input validation in the… | |
| Analizada | Media (5.4) | 0.19% | — | Gitlab | 15/9/2026 | 28/9/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to bypass SAML SSO sign-in restrictions and authenticate without SSO due to missing authentication enforcement… |