Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2541▼ 354 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
3657 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.23% | — | Gitoxide Gix-transportAI | 15/9/2026 | 23/9/2026 | gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs. | |
| Aplazada | Media (5.3) | 0.45% | — | GithackerAI | 15/9/2026 | 30/9/2026 | GitHacker is a tool that restores Git repositories from exposed .git directories. In 1.1.7 and earlier, add_head_file_tasks parses an attacker-controlled ref path from .git/HEAD and joins unvalidated path segments onto temp_dst/.git/logs/, allowing a malicious server to make GitHacker read an arbitrary local file when… | |
| Aplazada | Media (6.8) | 0.19% | — | GitoxideAIGitoxide Gix-secAI | 14/9/2026 | 23/9/2026 | gitoxide is an implementation of git written in Rust. Prior to 0.13.3, the gix-sec crate on Windows incorrectly treats repositories controlled by another user as trusted when an administrator runs a dependent program with an unfiltered elevated token. In gix-sec/src/identity.rs,… | |
| Aplazada | Baja (2.1) | 0.56% | — | Gitlawb OpenclaudeAI | 14/9/2026 | 14/9/2026 | A vulnerability was identified in Gitlawb openclaude up to 0.30.0. Impacted is the function waitForCallback of the file src/services/api/xaiOAuthCallback.ts of the component xAI OAuth Callback Handler. The manipulation of the argument Error leads to denial of service. Remote exploitation of the attack is possible. The… | |
| Pendiente de análisis | Alta (8.5) | 0.11% | — | Logitech Logi Options PlusAI | 14/9/2026 | 18/9/2026 | A local privilege escalation vulnerability in the Logitech Logi Options+ updater service on Windows allows a low-privileged local user to execute arbitrary code as SYSTEM. | |
| Aplazada | Media (6.6) | 0.23% | — | Digitaldruid HoteldruidAI | 14/9/2026 | 22/9/2026 | HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function. | |
| Analizada | Crítica (9.9) | 0.57% | — | Gitlab | 12/9/2026 | 28/9/2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and… | |
| Analizada | Crítica (10) | 93% | ⚠ Explotación activa | Gitlab | 12/9/2026 | 24/9/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path… | |
| Aplazada | Media (4.3) | 0.28% | — | Arma Digital Media INC Website TemplateAI | 11/9/2026 | 11/9/2026 | Improper neutralization of special elements used in a template engine vulnerability in Arma Digital Media Inc. Website Template allows Code Injection. This issue affects Website Template: through 11092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Alta (7.1) | 0.44% | — | Isomorphic-gitAI | 10/9/2026 | 23/9/2026 | isomorphic-git before 1.42.0 contains a prototype pollution vulnerability in the getRemoteInfo function that allows a malicious Git server operator to pollute Object.prototype by advertising crafted ref names containing '__proto__' path segments during ref negotiation. Attackers controlling a Git server can advertise… | |
| Pendiente de análisis | Crítica (9.2) | 0.50% | — | RenovateAIGitlabAI | 10/9/2026 | 29/9/2026 | Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests. Attackers controlling a compromised GitLab server can specify a Link header pointing to attacker-controlled infrastructure to exfiltrate… | |
| Pendiente de análisis | Alta (7.7) | 0.38% | — | Gemini CLIAIGemini CLI Github ActionAI | 10/9/2026 | 23/9/2026 | A vulnerability in the Gemini CLI prior to version 0.39.1 allows attackers to achieve arbitrary code execution by tricking a victim into starting the CLI within an untrusted directory. The vulnerability is triggered via untrusted .env files overriding GEMINI_CLI_HOME to load malicious configuration files and bypass… | |
| Analizada | Alta (7.1) | 0.41% | — | Gitpython Project Gitpython | 9/9/2026 | 16/9/2026 | GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover… | |
| Analizada | Alta (8.7) | 0.40% | — | Gitpython Project Gitpython | 9/9/2026 | 16/9/2026 | GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim… | |
| Analizada | Alta (8.7) | 0.52% | — | Gitpython Project Gitpython | 9/9/2026 | 18/9/2026 | GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containing an unterminated angle bracket to cause quadratic backtracking, exhausting CPU… | |
| Aplazada | Crítica (9.8) | 0.48% | — | Digital-infrastructureAI | 8/9/2026 | 9/9/2026 | An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any user, including the Admin, without a password. | |
| Aplazada | Alta (7.4) | 0.45% | — | Zhao-github ApiadminAI | 4/9/2026 | 9/9/2026 | SQL injection vulnerability in Zhao-github APiAdmin v.5.0.1 allows a remote attacker to obtain sensitive information via the User.php component | |
| Aplazada | Alta (8.1) | 0.61% | — | Zhao-github ApiadminAI | 4/9/2026 | 14/9/2026 | File Upload vulnerability in Zhao-github ApiAdmin v.5.0.1 allows a remote attacker to execute arbitrary code via a crafted .php file | |
| Aplazada | Alta (8.7) | 0.48% | — | Git-mcp-serverAI | 4/9/2026 | 23/9/2026 | git-mcp-server 2.15.1 contains an argument injection vulnerability in the ref and object parameters of git_log, git_diff, and git_show tools that lack leading-dash validation. Attackers can inject git command-line options like --output= to write files outside the repository to arbitrary paths accessible by the process. | |
| Pendiente de análisis | Media (5.4) | 0.14% | — | Jenkins Gitlab PluginAI | 2/9/2026 | 3/9/2026 | Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global GitLab connection configuration through Stapler data binding, allowing attackers to connect to an attacker-specified URL using GitLab API tokens already configured by administrators. | |
| Analizada | Media (5.3) | 0.31% | — | Lakedrops Digital Signage Framework | 2/9/2026 | 16/9/2026 | Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Digital Signage Framework versions: from 0.0.0 to 2.6.1. | |
| Analizada | Alta (7.7) | 0.83% | — | Github Enterprise Server | 1/9/2026 | 8/9/2026 | A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execution on the instance. Insufficient network isolation allowed malicious pre-receive hook code to impersonate an internal service and redirect trusted internal requests to a privileged service,… | |
| Analizada | Alta (7.7) | 0.54% | — | Github Enterprise Server | 1/9/2026 | 8/9/2026 | A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution. Exploitation required an authenticated user with write access to a repository and precise timing of concurrent upload requests. This vulnerability affected all versions of GitHub… | |
| Modificada | Alta (8.2) | 0.29% | — | Github Enterprise Server | 1/9/2026 | 22/9/2026 | A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send crafted outbound requests to an attacker-controlled host. An unauthenticated endpoint parsed an attacker-supplied cluster configuration and issued… | |
| En análisis | Crítica (9.8) | 0.37% | — | Openai Codex DesktopAIGITAI | 1/9/2026 | 2/9/2026 | OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a repository with preserved attacker-controlled .git/config, the attr.tree setting and a configured clean or process filter can cause Git to run an… |