Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 92% | — | Cgit Project CgitDebian Linux | 3/8/2018 | 17/6/2026 | cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cgit/cgit.cgi/git/objects/?path=../ request. | |
| Modificada | Alta (7.5) | 1.1% | — | Ethereumlegit Project Ethereumlegit | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for EthereumLegit, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.5) | 0.99% | — | Ethereumlegit Project Ethereumlegit | 5/7/2018 | 17/6/2026 | The sell function of a smart contract implementation for EthereumLegit, an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets. | |
| Modificada | Alta (7.8) | 0.76% | — | Fs-git Project Fs-git | 2/1/2018 | 17/6/2026 | fs-git is a file system like api for git repository. The fs-git version 1.0.1 module relies on child_process.exec, however, the buildCommand method used to construct exec strings does not properly sanitize data and is vulnerable to command injection across all methods that use it and call exec. | |
| Modificada | Crítica (9.8) | 19% | — | GIT Project GITRedhat Software CollectionsCanonical Ubuntu LinuxOpensuse | 13/4/2016 | 17/6/2026 | The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote attackers to execute arbitrary code via a URL in a (a) .gitmodules file or (b) unknown… | |
| Modificada | Crítica (9.8) | 3.8% | — | Fedoraproject FedoraCgit Project Cgit | 20/1/2016 | 17/6/2026 | Integer overflow in the authenticate_post function in CGit before 0.12 allows remote attackers to have unspecified impact via a large value in the Content-Length HTTP header, which triggers a buffer overflow. | |
| Modificada | Baja (3.7) | 1.9% | — | Fedoraproject FedoraCgit Project Cgit | 20/1/2016 | 17/6/2026 | CRLF injection vulnerability in the cgit_print_http_headers function in ui-shared.c in CGit before 0.12 allows remote attackers with permission to write to a repository to inject arbitrary HTTP headers and conduct HTTP response splitting attacks or cross-site scripting (XSS) attacks via newline characters in a… | |
| Modificada | Baja (3.7) | 1.9% | — | Fedoraproject FedoraCgit Project Cgit | 20/1/2016 | 17/6/2026 | CRLF injection vulnerability in the ui-blob handler in CGit before 0.12 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks or cross-site scripting (XSS) attacks via CRLF sequences in the mimetype parameter, as demonstrated by a request to blob/cgit.c. | |
| Modificada | Alta (10) | 1.7% | — | GIT Project GIT | 11/12/2015 | 17/6/2026 | Multiple unspecified vulnerabilities in Git before 2.5.4, as used in Apple Xcode before 7.2, have unknown impact and attack vectors. NOTE: this CVE is associated only with Xcode use cases. |