Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

2101 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.28%—Enalean Tuleap8/12/202517/6/2026
Tuleap is an Open Source Suite for management of software development and collaboration. Versions below 17.0.99.1762431347 of Tuleap Community Edition and Tuleap Enterprise Edition below 17.0-2, 16.13-7 and 16.12-10 allow attackers to access file release system information in projects they do not have access to. This…
AplazadaMedia (4.6)0.14%—Enalean TuleapAI12/11/202517/6/2026
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap Community Edition prior to version 16.13.99.1762267347 and Tuleap Enterprise Edition prior to versions 17.01-, 16.13-6, and 16.12-9 don't have cross-site request forgery protections in the file release system. An…
AplazadaMedia (4.6)0.14%—Enalean TuleapAI12/11/202517/6/2026
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap Community Edition prior to version 16.13.99.1761813675 and Tuleap Enterprise Edition prior to versions 16.13-5 and 16.12-8 don't have cross-site request forgery protection in the management of SVN commit rules and…
AplazadaMedia (4.3)0.33%—Tuleap Community EditionAITuleap Enterprise EditionAIEnalean TuleapAI18/9/202517/6/2026
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Backlog item representations do not verify the permissions of the child trackers. Users might see tracker names they should not have access to. This vulnerability is fixed in Tuleap Community Edition 16.11.99.1757427600…
AnalizadaMedia (5.3)0.29%—Enalean Tuleap29/8/202517/6/2026
Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition versions before 16.10.99.1754050155 and Tuleap Enterprise Edition versions before 16.9-8 and before 16.10-5, an attacker can access to the content of the special and always there…
AplazadaCrítica (9.3)0.80%💥 ExploitLeapware LeapftpAI20/8/202516/6/2026
LeapFTP < 3.1.x contains a stack-based buffer overflow vulnerability in its FTP client parser. When the client receives a directory listing containing a filename longer than 528 bytes, the application fails to properly bound-check the input and overwrites the Structured Exception Handler (SEH) chain. This allows an…
AnalizadaMedia (4.3)0.32%—Enalean Tuleap29/7/202517/6/2026
Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1752585665 and Tuleap Enterprise Edition prior to 16.8-6 and 16.9-5, users may potentially access confidential information from artifacts that they are not…
AnalizadaMedia (5.4)0.23%—Enalean Tuleap29/7/202517/6/2026
Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1751892857 and Tuleap Enterprise Edition prior to 16.8-5 and 16.9-3, malicious users with some control over certain artifacts could insert malicious code when…
AnalizadaMedia (5.3)0.30%—Enalean Tuleap29/7/202517/6/2026
Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1750843170 and Tuleap Enterprise Edition prior to 16.8-4 and 16.9-2, the forgot password form allows for user enumeration. This is fixed in Tuleap Community…
AnalizadaMedia (5.4)0.19%—Leap13 Premium Addons FOR Elementor4/7/202517/6/2026
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's linkURL in the Mobile Menu element in all versions up to, and including, 4.10.69 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AnalizadaAlta (7.8)55%⚠ Explotación activa💥 ExploitSudo Project SudoCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+430/6/202517/6/2026
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
AnalizadaMedia (4.3)0.17%—Enalean Tuleap25/6/202517/6/2026
Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker could use a cross-site request forgery vulnerability in Tuleap Community Edition prior to version 16.8.99.1749830289 and Tuleap Enterprise Edition prior to version 16.9-1 to trick victims into changing the…
AnalizadaMedia (4.3)0.17%—Enalean Tuleap25/6/202517/6/2026
Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker could use a vulnerability present in Tuleap Community Edition prior to version 16.8.99.1748845907 and Tuleap Enterprise Edition prior to versions 16.8-3 and 16.7-5 to trick victims into changing the canned…
AnalizadaMedia (5.4)0.25%—Leap13 Premium Addons FOR Elementor10/6/202517/6/2026
The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-countdown attribute of Countdown widget in all versions up to, and including, 4.11.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AnalizadaAlta (7.2)0.56%💥 PoCAleapp CSV Mass Importer17/5/202517/6/2026
The CSV Mass Importer WordPress plugin through 1.2 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
AnalizadaBaja (2.7)0.21%—Hcltech Domino Leap30/4/202517/6/2026
Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server's filesystem.
AnalizadaMedia (6.1)0.26%—Hcltech Domino Leap30/4/202517/6/2026
Multiple vectors in HCL Domino Volt and Domino Leap allow client-side script injection in the authoring environment and deployed applications.
AnalizadaMedia (5.4)0.25%—Hcltech Domino Leap30/4/202517/6/2026
Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.
AnalizadaMedia (5.3)0.31%—Hcltech Domino Leap30/4/202517/6/2026
Insufficient default configuration in HCL Leap allows anonymous access to directory information.
AnalizadaMedia (6.1)0.24%—Hcltech Domino Leap30/4/202517/6/2026
Insufficient URI protocol whitelist in HCL Domino Volt and Domino Leap allow script injection through query parameters.
AnalizadaAlta (7.5)0.23%—Hcltech Domino Leap30/4/202517/6/2026
Missing "no cache" headers in HCL Leap permits sensitive data to be cached.
AnalizadaMedia (5.4)0.23%—Hcltech Domino Leap30/4/202517/6/2026
Improper sanitization of SVG files in HCL Domino Volt allows client-side script injection in deployed applications.
AnalizadaMedia (5.4)0.29%—Hcltech Domino Leap30/4/202517/6/2026
Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications
AnalizadaMedia (5.4)0.29%—Hcltech Domino Leap30/4/202517/6/2026
Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications.
AnalizadaBaja (3.2)0.16%—Hcltech HCL Leap24/4/202517/6/2026
Missing "no cache" headers in HCL Leap permits sensitive data to be cached.