Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2541▼ 354 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

3657 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.23%—Gitoxide Gix-transportAI15/9/202623/9/2026
gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.
AplazadaMedia (5.3)0.45%—GithackerAI15/9/202630/9/2026
GitHacker is a tool that restores Git repositories from exposed .git directories. In 1.1.7 and earlier, add_head_file_tasks parses an attacker-controlled ref path from .git/HEAD and joins unvalidated path segments onto temp_dst/.git/logs/, allowing a malicious server to make GitHacker read an arbitrary local file when…
AplazadaMedia (6.8)0.19%—GitoxideAIGitoxide Gix-secAI14/9/202623/9/2026
gitoxide is an implementation of git written in Rust. Prior to 0.13.3, the gix-sec crate on Windows incorrectly treats repositories controlled by another user as trusted when an administrator runs a dependent program with an unfiltered elevated token. In gix-sec/src/identity.rs,…
AplazadaBaja (2.1)0.56%—Gitlawb OpenclaudeAI14/9/202614/9/2026
A vulnerability was identified in Gitlawb openclaude up to 0.30.0. Impacted is the function waitForCallback of the file src/services/api/xaiOAuthCallback.ts of the component xAI OAuth Callback Handler. The manipulation of the argument Error leads to denial of service. Remote exploitation of the attack is possible. The…
Pendiente de análisisAlta (8.5)0.11%—Logitech Logi Options PlusAI14/9/202618/9/2026
A local privilege escalation vulnerability in the Logitech Logi Options+ updater service on Windows allows a low-privileged local user to execute arbitrary code as SYSTEM.
AplazadaMedia (6.6)0.23%—Digitaldruid HoteldruidAI14/9/202622/9/2026
HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.
AnalizadaCrítica (9.9)0.57%—Gitlab12/9/202628/9/2026
GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and…
AnalizadaCrítica (10)93%⚠ Explotación activaGitlab12/9/202624/9/2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path…
AplazadaMedia (4.3)0.28%—Arma Digital Media INC Website TemplateAI11/9/202611/9/2026
Improper neutralization of special elements used in a template engine vulnerability in Arma Digital Media Inc. Website Template allows Code Injection. This issue affects Website Template: through 11092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
AplazadaAlta (7.1)0.44%—Isomorphic-gitAI10/9/202623/9/2026
isomorphic-git before 1.42.0 contains a prototype pollution vulnerability in the getRemoteInfo function that allows a malicious Git server operator to pollute Object.prototype by advertising crafted ref names containing '__proto__' path segments during ref negotiation. Attackers controlling a Git server can advertise…
Pendiente de análisisCrítica (9.2)0.50%—RenovateAIGitlabAI10/9/202629/9/2026
Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests. Attackers controlling a compromised GitLab server can specify a Link header pointing to attacker-controlled infrastructure to exfiltrate…
Pendiente de análisisAlta (7.7)0.38%—Gemini CLIAIGemini CLI Github ActionAI10/9/202623/9/2026
A vulnerability in the Gemini CLI prior to version 0.39.1 allows attackers to achieve arbitrary code execution by tricking a victim into starting the CLI within an untrusted directory. The vulnerability is triggered via untrusted .env files overriding GEMINI_CLI_HOME to load malicious configuration files and bypass…
AnalizadaAlta (7.1)0.41%—Gitpython Project Gitpython9/9/202616/9/2026
GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover…
AnalizadaAlta (8.7)0.40%—Gitpython Project Gitpython9/9/202616/9/2026
GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim…
AnalizadaAlta (8.7)0.52%—Gitpython Project Gitpython9/9/202618/9/2026
GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containing an unterminated angle bracket to cause quadratic backtracking, exhausting CPU…
AplazadaCrítica (9.8)0.48%—Digital-infrastructureAI8/9/20269/9/2026
An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any user, including the Admin, without a password.
AplazadaAlta (7.4)0.45%—Zhao-github ApiadminAI4/9/20269/9/2026
SQL injection vulnerability in Zhao-github APiAdmin v.5.0.1 allows a remote attacker to obtain sensitive information via the User.php component
AplazadaAlta (8.1)0.61%—Zhao-github ApiadminAI4/9/202614/9/2026
File Upload vulnerability in Zhao-github ApiAdmin v.5.0.1 allows a remote attacker to execute arbitrary code via a crafted .php file
AplazadaAlta (8.7)0.48%—Git-mcp-serverAI4/9/202623/9/2026
git-mcp-server 2.15.1 contains an argument injection vulnerability in the ref and object parameters of git_log, git_diff, and git_show tools that lack leading-dash validation. Attackers can inject git command-line options like --output= to write files outside the repository to arbitrary paths accessible by the process.
Pendiente de análisisMedia (5.4)0.14%—Jenkins Gitlab PluginAI2/9/20263/9/2026
Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global GitLab connection configuration through Stapler data binding, allowing attackers to connect to an attacker-specified URL using GitLab API tokens already configured by administrators.
AnalizadaMedia (5.3)0.31%—Lakedrops Digital Signage Framework2/9/202616/9/2026
Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Digital Signage Framework versions: from 0.0.0 to 2.6.1.
AnalizadaAlta (7.7)0.83%—Github Enterprise Server1/9/20268/9/2026
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execution on the instance. Insufficient network isolation allowed malicious pre-receive hook code to impersonate an internal service and redirect trusted internal requests to a privileged service,…
AnalizadaAlta (7.7)0.54%—Github Enterprise Server1/9/20268/9/2026
A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution. Exploitation required an authenticated user with write access to a repository and precise timing of concurrent upload requests. This vulnerability affected all versions of GitHub…
ModificadaAlta (8.2)0.29%—Github Enterprise Server1/9/202622/9/2026
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send crafted outbound requests to an attacker-controlled host. An unauthenticated endpoint parsed an attacker-supplied cluster configuration and issued…
En análisisCrítica (9.8)0.37%—Openai Codex DesktopAIGITAI1/9/20262/9/2026
OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a repository with preserved attacker-controlled .git/config, the attr.tree setting and a configured clean or process filter can cause Git to run an…