Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
76 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.27% | — | Enalean Tuleap | 4/3/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. The mass emailing features do not sanitize the content of the HTML emails. A malicious user could use this issue to facilitate a phishing attempt or to indirectly exploit issues in the recipients mail clients. This… | |
| Analizada | Media (6.5) | 0.38% | — | Enalean Tuleap | 4/3/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. The password to connect the Redis instance is not purged from the archive generated with tuleap collect-system-data. These archives are likely to be used by support teams that should not have access to this password. The… | |
| Analizada | Media (4.8) | 0.30% | — | Enalean Tuleap | 3/3/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap allows cross-site scripting (XSS) via the tracker names used in the semantic timeframe deletion message. A tracker administrator with a semantic timeframe used by other trackers could use this vulnerability to force… | |
| Analizada | Media (5.4) | 0.36% | — | Enalean Tuleap | 3/3/2025 | 17/6/2026 | Tuleap is an open-source suite designed to improve software development management and collaboration. A malicious user with access to a tracker could force-reset certain field configurations, leading to potential information loss. The display time attribute for the date field, the size attribute for the multiselectbox… | |
| Analizada | Media (5.3) | 0.35% | — | Enalean Tuleap | 3/2/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users (possibly anonymous ones if the widget is used in the dashboard of a public project) might get access to artifacts they should not see. This issue has been addressed in Tuleap Community Edition 16.3.99.1737562605 as… | |
| Analizada | Media (4.3) | 0.33% | — | Enalean Tuleap | 3/2/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. In affected versions an unauthorized user might get access to restricted information. This issue has been addressed in Tuleap Community Edition 16.3.99.1736242932, Tuleap Enterprise Edition 16.2-5, and Tuleap Enterprise… | |
| Analizada | Media (5.4) | 0.32% | — | Enalean Tuleap | 9/12/2024 | 17/6/2026 | Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edition prior to version 16.1.99.50 and Tuleap Enterprise Edition prior to versions 16.1-4 and 16.0-7, a malicious user with the ability to create an artifact in a tracker with a Gantt chart could force… | |
| Analizada | Media (4.3) | 0.44% | — | Enalean Tuleap | 14/10/2024 | 17/6/2026 | Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.113, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-5, users might see tracker names they should not have access to. Tuleap Community Edition 15.13.99.113, Tuleap… | |
| Analizada | Media (4.9) | 0.51% | — | Enalean Tuleap | 14/10/2024 | 17/6/2026 | Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5, and Tuleap Enterprise Edition 15.12-5, administrators of a project can access the content of trackers with permissions restrictions of project they are… | |
| Analizada | Media (5.7) | 0.35% | — | Enalean Tuleap | 14/10/2024 | 17/6/2026 | Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.40, Tuleap Enterprise Edition 15.13-3, and Tuleap Enterprise Edition 15.12-6, users might receive email notification with information they should not have access to. Tuleap Community Edition… | |
| Analizada | Media (4.8) | 0.38% | — | Enalean Tuleap | 14/10/2024 | 17/6/2026 | Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.37, Tuleap Enterprise Edition 15.13-3, and Tuleap Enterprise Edition 15.12-6, a site administrator could create an artifact link type with a forward label allowing them to execute… | |
| Analizada | Media (4.3) | 0.31% | — | Enalean Tuleap | 22/7/2024 | 17/6/2026 | Tuleap is an open source suite to improve management of software developments and collaboration. Prior to Tuleap Community Edition 15.10.99.128 and Tuleap Enterprise Edition 15.10-6 and 15.9-8, the checkbox "Apply same permissions to all sub-items of this folder" in the document manager permissions modal is not taken… | |
| Analizada | Media (4.3) | 0.35% | — | Enalean Tuleap | 25/6/2024 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users are able to see backlog items that they should not see. This issue has been patched in Tuleap Community Edition version 15.9.99.97. | |
| Analizada | Alta (7.1) | 0.62% | — | Enalean Tuleap | 29/3/2024 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. A malicious user could exploit this issue on purpose to delete information on the instance or possibly gain access to restricted artifacts. It is however not possible to control exactly which information is deleted.… | |
| Analizada | Media (6.5) | 0.50% | — | Enalean Tuleap | 22/2/2024 | 17/6/2026 | Tuleap is an open source suite to improve management of software developments and collaboration. Prior to version 15.5.99.76 of Tuleap Community Edition and prior to versions 15.5-4 and 15.4-7 of Tuleap Enterprise Edition, users with a read access to a tracker where the mass update feature is used might get access to… | |
| Modificada | Media (6.5) | 0.53% | — | Enalean Tuleap | 6/2/2024 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Some users might get access to restricted information when a process validates the permissions of multiple users (e.g. mail notifications). This issue has been patched in version 15.4.99.140 of Tuleap Community Edition. | |
| Modificada | Media (5.4) | 0.52% | — | Enalean Tuleap | 11/12/2023 | 17/6/2026 | Tuleap is an open source suite to improve management of software developments and collaboration. Prior to version 15.2.99.103 of Tuleap Community Edition and prior to versions 15.2-4 and 15.1-8 of Tuleap Enterprise Edition, the name of the releases are not properly escaped on the edition page of a release. A malicious… | |
| Modificada | Media (4.8) | 0.56% | — | Enalean Tuleap | 24/8/2023 | 17/6/2026 | Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edition prior to version 14.11.99.28 and Tuleap Enterprise Edition prior to versions 14.10-6 and 14.11-3, content displayed in the "card fields" (visible in the kanban and PV2 apps) is not properly… | |
| Modificada | Media (4.3) | 0.66% | — | Enalean Tuleap | 24/8/2023 | 17/6/2026 | Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edition prior to version 14.11.99.28 and Tuleap Enterprise Edition prior to versions 14.10-6 and 14.11-3, the preview of an artifact link with a type does not respect the project, tracker and artifact… | |
| Modificada | Media (5.9) | 0.59% | — | Jenkins Tuleap Authentication | 16/8/2023 | 17/6/2026 | Jenkins Tuleap Authentication Plugin 1.1.20 and earlier uses a non-constant time comparison function when validating an authentication token allowing attackers to use statistical methods to obtain a valid authentication token. | |
| Modificada | Media (5.4) | 0.47% | — | Enalean Tuleap | 25/7/2023 | 17/6/2026 | Tuleap is a free and open source suite to improve management of software development and collaboration. Prior to version 14.10.99.4 of Tuleap Community Edition and prior to versions 14.10-2 and 14.9-5 of Tuleap Enterprise Edition, content displayed in the "card fields" (visible in the kanban and PV2 apps) is not… | |
| Modificada | Alta (7.2) | 0.59% | — | Enalean Tuleap | 29/6/2023 | 17/6/2026 | Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. When switching from a project visibility that allows restricted users to `Private without restricted`, restricted users that are project administrators keep this access right. Restricted users that were project… | |
| Modificada | Media (4.8) | 0.47% | — | Enalean Tuleap | 29/5/2023 | 17/6/2026 | Tuleap is an open source tool for end to end traceability of application and system developments. Tuleap Community Edition prior to version 14.8.99.60 and Tuleap Enterprise edition prior to 14.8-3 and 14.7-7, the logs of the triggered Jenkins job URLs are not properly escaped. A malicious Git administrator can setup a… | |
| Modificada | Media (5.4) | 0.47% | — | Enalean Tuleap | 4/5/2023 | 17/6/2026 | Tuleap Open ALM is a Libre and Open Source tool for end to end traceability of application and system developments. The title of an artifact is not properly escaped in the tooltip. A malicious user with the capability to create an artifact or to edit a field title could force victim to execute uncontrolled code. This… | |
| Modificada | Media (4.8) | 0.46% | — | Enalean Tuleap | 20/4/2023 | 17/6/2026 | Tuleap is a Free & Source tool for end to end traceability of application and system developments. Affected versions are subject to a cross site scripting attack which can be injected in the name of a color of select box values of a tracker and then reflected in the tracker administration. Administrative privilege is… |