Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2541▼ 407 respecto a la semana anterior
Críticas / altas1311▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
102 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.3) | 0.24% | — | Apple Xcode | 8/5/2023 | 17/6/2026 | This issue was addressed with improved entitlements. This issue is fixed in Xcode 14.3, macOS Big Sur 11.7.7, macOS Monterey 12.6.6. A sandboxed app may be able to collect system logs. | |
| Modificada | Alta (7.8) | 0.31% | — | Apple Xcode | 27/2/2023 | 17/6/2026 | An injection issue was addressed with improved input validation. This issue is fixed in Xcode 14.1. An app may be able to gain root privileges. | |
| Modificada | Media (5.4) | 0.47% | — | Pixelgrade Pixcodes | 30/1/2023 | 17/6/2026 | The PixCodes WordPress plugin before 2.3.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | |
| Modificada | Alta (8.8) | 3.3% | — | Git-scm GITFedoraproject FedoraApple XcodeDebian Linux | 19/10/2022 | 17/6/2026 | Git is an open source, scalable, distributed revision control system. `git shell` is a restricted login shell that can be used to implement Git's push/pull functionality via SSH. In versions prior to 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2.37.4, the function that splits the command arguments into… | |
| Modificada | Media (5.5) | 1.3% | — | Git-scm GITFedoraproject FedoraApple XcodeDebian Linux | 19/10/2022 | 17/6/2026 | Git is an open source, scalable, distributed revision control system. Versions prior to 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2.37.4 are subject to exposure of sensitive information to a malicious actor. When performing a local clone (where the source and target of the clone are on the same… | |
| Modificada | Alta (7.8) | 0.45% | — | Git-scm GITFedoraproject FedoraApple XcodeDebian Linux | 12/7/2022 | 17/6/2026 | Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to privilege escalation in all platforms. An unsuspecting user could still be affected by the issue reported in CVE-2022-24765, for example when navigating as root into… | |
| Modificada | Alta (7.8) | 0.64% | — | Apple Xcode | 26/5/2022 | 17/6/2026 | This issue was addressed with improved checks. This issue is fixed in Xcode 13.4. An app may be able to gain elevated privileges. | |
| Modificada | Alta (7.8) | 1.0% | — | Git-scm GITFedoraproject FedoraApple XcodeDebian Linux | 12/4/2022 | 17/6/2026 | Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted parties could create the folder `C:\.git`, which would be picked up by Git operations run supposedly… | |
| Modificada | Alta (7.8) | 0.88% | — | Apple Xcode | 18/3/2022 | 17/6/2026 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution. | |
| Modificada | Alta (7.8) | 0.88% | — | Apple Xcode | 18/3/2022 | 17/6/2026 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution. | |
| Modificada | Alta (7.8) | 1.0% | — | Apple Xcode | 18/3/2022 | 17/6/2026 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution. | |
| Modificada | Alta (7.8) | 0.83% | — | Apple Xcode | 18/3/2022 | 17/6/2026 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution. | |
| Modificada | Alta (7.8) | 0.97% | — | Apple Xcode | 18/3/2022 | 17/6/2026 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution. | |
| Modificada | Alta (7.8) | 0.97% | — | Apple Xcode | 18/3/2022 | 17/6/2026 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution. | |
| Modificada | Alta (7.8) | 0.97% | — | Apple Xcode | 18/3/2022 | 17/6/2026 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution. | |
| Modificada | Alta (7.8) | 0.97% | — | Apple Xcode | 18/3/2022 | 17/6/2026 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution. | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Alta (7.1) | 1.5% | — | Jenkins Xcode Integration | 11/5/2021 | 17/6/2026 | Jenkins Xcode integration Plugin 2.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Modificada | Media (5.5) | 0.64% | — | Apple Xcode | 2/4/2021 | 17/6/2026 | A path handling issue was addressed with improved validation. This issue is fixed in Xcode 12.4. A malicious application may be able to access arbitrary files on the host device while running an app that uses on-demand resources with Xcode. | |
| Modificada | Alta (7.5) | 89% | — | Git-scm GITFedoraproject FedoraApple XcodeDebian Linux | 9/3/2021 | 17/6/2026 | Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/smudge filter such as Git LFS, may cause just-checked out script to be executed while cloning onto a case-insensitive file system such as… | |
| Modificada | Alta (8.8) | 1.3% | — | Apple Xcode | 27/10/2020 | 17/6/2026 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 11.3. Compiling with untrusted sources may lead to arbitrary code execution with user privileges. | |
| Modificada | Alta (7.8) | 3.0% | — | Apple XcodeApple IpadosApple Iphone OS | 16/10/2020 | 17/6/2026 | This issue was addressed by encrypting communications over the network to devices running iOS 14, iPadOS 14, tvOS 14, and watchOS 7. This issue is fixed in iOS 14.0 and iPadOS 14.0, Xcode 12.0. An attacker in a privileged network position may be able to execute arbitrary code on a paired device during a debug session… | |
| Modificada | Crítica (9.8) | 76% | — | Git-scm GITMercurialApple XcodeEclipse Egit+2 | 12/2/2020 | 17/6/2026 | Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit… | |
| Modificada | Media (5.3) | 15% | — | F5 NginxApple XcodeCanonical Ubuntu LinuxOpensuse Leap+1 | 9/1/2020 | 17/6/2026 | NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer. | |
| Modificada | Alta (7.8) | 0.98% | — | Apple Xcode | 18/12/2019 | 17/6/2026 | A memory corruption issue was addressed with improved validation. This issue is fixed in Xcode 11.2. Processing a maliciously crafted file may lead to arbitrary code execution. |