Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3020▼ 63 respecto a la semana anterior
Críticas / altas1413▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
83 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.61% | — | SentryAI | 15/1/2025 | 17/6/2026 | Sentry is a developer-first error tracking and performance monitoring tool. A critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity… | |
| Analizada | Media (5.5) | 0.25% | — | Ivanti Standalone Sentry | 10/12/2024 | 17/6/2026 | Insecure permissions in Ivanti Sentry before versions 9.20.2 and 10.0.2 or 10.1.0 allow a local authenticated attacker to modify sensitive application components. | |
| Analizada | Media (5.3) | 0.65% | — | Sentry | 22/11/2024 | 17/6/2026 | Sentry is an error tracking and performance monitoring platform. Version 24.11.0, and only version 24.11.0, is vulnerable to a scenario where a specific error message generated by the Sentry platform could include a plaintext Client ID and Client Secret for an application integration. The Client ID and Client Secret… | |
| Analizada | Media (6.5) | 0.44% | — | Telestream Sentry | 25/10/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Sentry v.6.0.9 allows a remote attacker to execute arbitrary code via the z parameter. | |
| Analizada | Media (5.3) | 0.39% | — | Telestream Sentry | 23/10/2024 | 17/6/2026 | A vulnerability has been found in Telestream Sentry 6.0.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /?page=reports of the component Reports Page. The manipulation of the argument z leads to cross site scripting. The attack can be launched remotely. The… | |
| Analizada | Media (4.3) | 0.36% | — | Sentry | 17/9/2024 | 17/6/2026 | Sentry is a developer-first error tracking and performance monitoring platform. An authenticated user can mute alert rules from arbitrary organizations and projects with a know rule ID. The user does not need to be a member of the organization or have permissions on the project. In our review, we have identified no… | |
| Analizada | Media (4.3) | 0.39% | — | Sentry | 17/9/2024 | 17/6/2026 | Sentry is a developer-first error tracking and performance monitoring platform. An authenticated user delete the user issue alert notifications for arbitrary users given a know alert ID. A patch was issued to ensure authorization checks are properly scoped on requests to delete user alert notifications. Sentry SaaS… | |
| Analizada | Media (5.4) | 0.47% | — | Sentry | 23/7/2024 | 17/6/2026 | Sentry is an error tracking and performance monitoring platform. Starting in version 10.0.0 and prior to version 24.7.1, an unsanitized payload sent by an Integration platform integration allows storing arbitrary HTML tags on the Sentry side with the subsequent rendering them on the Issues page. Self-hosted Sentry… | |
| Aplazada | Media (5.3) | 0.20% | — | Sentry-sdkAI | 18/7/2024 | 17/6/2026 | sentry-sdk is the official Python SDK for Sentry.io. A bug in Sentry's Python SDK < 2.8.0 allows the environment variables to be passed to subprocesses despite the `env={}` setting. In Python's `subprocess` calls, all environment variables are passed to subprocesses by default. However, if you specifically do not want… | |
| Aplazada | Baja (2) | 0.57% | — | SentryAI | 31/5/2024 | 17/6/2026 | Sentry is a developer-first error tracking and performance monitoring platform. Sentry's Slack integration incorrectly records the incoming request body in logs. This request data can contain sensitive information, including the deprecated Slack verification token. With this verification token, it is possible under… | |
| Analizada | Media (6.5) | 0.43% | — | Sentry | 18/4/2024 | 17/6/2026 | Sentry is an error tracking and performance monitoring platform. Prior to 24.4.1, when authenticating as a superuser to Sentry with a username and password, the password is leaked as cleartext in logs under the _event_: `auth-index.validate_superuser`. An attacker with access to the log data could use these leaked… | |
| Modificada | Alta (8.8) | 13% | — | Ivanti Standalone Sentry | 31/3/2024 | 17/6/2026 | A command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat actor to execute arbitrary commands on the underlying operating system of the appliance within the same physical or logical network. | |
| Modificada | Media (5.3) | 0.47% | — | Sentry | 9/2/2024 | 17/6/2026 | Sentry is an error tracking and performance monitoring platform. Sentry’s integration platform provides a way for external services to interact with Sentry. One of such integrations, the Phabricator integration (maintained by Sentry) with version <=24.1.1 contains a constrained SSRF vulnerability. An attacker could… | |
| Modificada | Media (4.3) | 0.47% | — | Sentry Symbolicator | 22/12/2023 | 17/6/2026 | Symbolicator is a service used in Sentry. Starting in Symbolicator version 0.3.3 and prior to version 21.12.1, an attacker could make Symbolicator send GET HTTP requests to arbitrary URLs with internal IP addresses by using an invalid protocol. The responses of those requests could be exposed via Symbolicator's API.… | |
| Modificada | Alta (7.5) | 0.78% | — | Sentry Astro | 20/12/2023 | 17/6/2026 | Sentry-Javascript is official Sentry SDKs for JavaScript. A ReDoS (Regular expression Denial of Service) vulnerability has been identified in Sentry's Astro SDK 7.78.0-7.86.0. Under certain conditions, this vulnerability allows an attacker to cause excessive computation times on the server, leading to denial of… | |
| Modificada | Media (4.3) | 0.70% | — | Sentry Symbolicator | 30/11/2023 | 17/6/2026 | Symbolicator is a symbolication service for native stacktraces and minidumps with symbol server support. An attacker could make Symbolicator send arbitrary GET HTTP requests to internal IP addresses by using a specially crafted HTTP endpoint. The response could be reflected to the attacker if they have an account on… | |
| Modificada | Media (6.1) | 0.63% | — | Sentry Software Development KIT | 10/11/2023 | 17/6/2026 | sentry-javascript provides Sentry SDKs for JavaScript. An unsanitized input of Next.js SDK tunnel endpoint allows sending HTTP requests to arbitrary URLs and reflecting the response back to the user. This issue only affects users who have Next.js SDK tunneling feature enabled. The problem has been fixed in version… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | Ivanti Mobileiron Sentry | 21/8/2023 | 17/6/2026 | A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration. | |
| Modificada | Media (6.8) | 0.36% | — | Sentry | 9/8/2023 | 17/6/2026 | Sentry is an error tracking and performance monitoring platform. Starting in version 10.0.0 and prior to version 23.7.2, an attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be… | |
| Modificada | Alta (8.1) | 1.1% | — | Sentry | 7/8/2023 | 17/6/2026 | Sentry is an error tracking and performance monitoring platform. Starting in version 22.1.0 and prior to version 23.7.2, an attacker with access to a token with few or no scopes can query `/api/0/api-tokens/` for a list of all tokens created by a user, including tokens with greater scopes, and use those tokens in… | |
| Modificada | Media (6.5) | 0.63% | — | Sentry | 25/7/2023 | 17/6/2026 | Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have… | |
| Modificada | Media (5.4) | 0.67% | — | Functional Sentry | 6/7/2023 | 17/6/2026 | Sentry is an error tracking and performance monitoring platform. Starting in version 23.6.0 and prior to version 23.6.2, the Sentry API incorrectly returns the `access-control-allow-credentials: true` HTTP header if the `Origin` request header ends with the `system.base-hostname` option of Sentry installation. This… | |
| Modificada | Media (6.5) | 0.65% | — | Sentry Software Development KIT | 22/3/2023 | 17/6/2026 | Sentry SDK is the official Python SDK for Sentry, real-time crash reporting software. When using the Django integration of versions prior to 1.14.0 of the Sentry SDK in a specific configuration it is possible to leak sensitive cookies values, including the session cookie to Sentry. These sensitive cookies could then… | |
| Modificada | Baja (3.7) | 0.43% | — | Sentry | 10/12/2022 | 17/6/2026 | Sentry is an error tracking and performance monitoring platform. In versions of the sentry python library prior to 22.11.0 an attacker with a known valid invite link could manipulate a cookie to allow the same invite link to be reused on multiple accounts when joining an organization. As a result an attacker with a… | |
| Modificada | Media (5.3) | 0.64% | — | Solarwinds SQL Sentry | 19/10/2022 | 17/6/2026 | Sensitive information could be displayed when a detailed technical error message is posted. This information could disclose environmental details. |