Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

2101 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (3.2)0.16%—Hcltech HCL Leap24/4/202517/6/2026
Missing "no cache" headers in HCL Leap permits user directory information to be cached.
AnalizadaMedia (4.6)0.29%—Hcltech HCL Leap24/4/202517/6/2026
Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications.
AnalizadaMedia (5.4)0.23%—Hcltech HCL Leap24/4/202517/6/2026
Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications.
AnalizadaMedia (6.1)0.26%—Hcltech HCL Leap24/4/202517/6/2026
Multiple vectors in HCL Leap allow client-side script injection in the authoring environment and deployed applications.
AnalizadaMedia (5.4)0.24%—Hcltech HCL Leap24/4/202517/6/2026
Insufficient sanitization in HCL Leap allows client-side script injection in the authoring environment.
AnalizadaMedia (5.4)0.30%—Hcltech HCL Leap24/4/202517/6/2026
Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.
AnalizadaMedia (5.3)0.31%—Hcltech HCL Leap24/4/202517/6/2026
Insufficient default configuration in HCL Leap allows anonymous access to directory information.
AnalizadaMedia (6.1)0.24%—Hcltech HCL Leap24/4/202517/6/2026
Insufficient URI protocol whitelist in HCL Leap allows script injection through query parameters.
AnalizadaMedia (4.1)0.27%—Hcltech HCL Leap24/4/202517/6/2026
Improper access control of endpoint in HCL Leap allows certain admin users to import applications from the server's filesystem.
AnalizadaMedia (5.3)0.37%—Enalean Tuleap31/3/202517/6/2026
Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker can access release notes content or information via the FRS REST endpoints it should not have access to. This vulnerability is fixed in Tuleap Community Edition 16.5.99.1742812323 and Tuleap Enterprise Edition…
AnalizadaMedia (4.8)0.30%—Enalean Tuleap31/3/202517/6/2026
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap allows cross-site scripting (XSS) via the content of RSS feeds in the RSS widgets. A project administrator or someone with control over an used RSS feed could use this vulnerability to force victims to execute…
AnalizadaMedia (4.3)0.33%—Enalean Tuleap31/3/202517/6/2026
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap does not enforce read permissions on parent trackers in the REST API. This vulnerability is fixed in Tuleap Community Edition 16.5.99.1742392651 and Tuleap Enterprise Edition 16.5-5 and 16.4-8.
AnalizadaMedia (4.3)0.20%—Enalean Tuleap31/3/202517/6/2026
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap is missing CSRF protection on tracker hierarchy administration. An attacker could use this vulnerability to trick victims into submitting or editing artifacts or follow-up comments. This vulnerability is fixed in…
AnalizadaMedia (4.3)0.20%—Enalean Tuleap31/3/202517/6/2026
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap has missing CSRF protections on artifact submission & edition from the tracker view. An attacker could use this vulnerability to trick victims into submitting or editing artifacts or follow-up comments. The…
AnalizadaMedia (4.6)0.17%—Enalean Tuleap4/3/202517/6/2026
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap is missing CSRF protections on tracker fields administrative operations. An attacker could use this vulnerability to trick victims into removing or updating tracker fields. This vulnerability is fixed in Tuleap…
AnalizadaMedia (4.6)0.33%—Enalean Tuleap4/3/202517/6/2026
Tuleap is an Open Source Suite to improve management of software developments and collaboration. In a standard usages of Tuleap, the issue has a limited impact, it will mostly leave dangling data. However, a malicious user could create and delete reports multiple times to cycle through all the filters of all reports…
AnalizadaMedia (5.4)0.27%—Enalean Tuleap4/3/202517/6/2026
Tuleap is an Open Source Suite to improve management of software developments and collaboration. The mass emailing features do not sanitize the content of the HTML emails. A malicious user could use this issue to facilitate a phishing attempt or to indirectly exploit issues in the recipients mail clients. This…
AnalizadaMedia (6.5)0.38%—Enalean Tuleap4/3/202517/6/2026
Tuleap is an Open Source Suite to improve management of software developments and collaboration. The password to connect the Redis instance is not purged from the archive generated with tuleap collect-system-data. These archives are likely to be used by support teams that should not have access to this password. The…
AnalizadaMedia (4.8)0.30%—Enalean Tuleap3/3/202517/6/2026
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap allows cross-site scripting (XSS) via the tracker names used in the semantic timeframe deletion message. A tracker administrator with a semantic timeframe used by other trackers could use this vulnerability to force…
AnalizadaMedia (5.4)0.36%—Enalean Tuleap3/3/202517/6/2026
Tuleap is an open-source suite designed to improve software development management and collaboration. A malicious user with access to a tracker could force-reset certain field configurations, leading to potential information loss. The display time attribute for the date field, the size attribute for the multiselectbox…
AnalizadaMedia (5.3)0.35%—Enalean Tuleap3/2/202517/6/2026
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users (possibly anonymous ones if the widget is used in the dashboard of a public project) might get access to artifacts they should not see. This issue has been addressed in Tuleap Community Edition 16.3.99.1737562605 as…
AnalizadaMedia (4.3)0.33%—Enalean Tuleap3/2/202517/6/2026
Tuleap is an Open Source Suite to improve management of software developments and collaboration. In affected versions an unauthorized user might get access to restricted information. This issue has been addressed in Tuleap Community Edition 16.3.99.1736242932, Tuleap Enterprise Edition 16.2-5, and Tuleap Enterprise…
AplazadaAlta (7.1)0.20%—Aleapp WP Cookies AlertAI16/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in aleapp WP Cookies Alert wp-cookies-alert allows Cross Site Request Forgery.This issue affects WP Cookies Alert: from n/a through <= 1.1.1.
AplazadaMedia (6.5)0.25%—Leap13 Premium BlocksAI2/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leap13 Premium Blocks – Gutenberg Blocks for WordPress premium-blocks-for-gutenberg allows Stored XSS.This issue affects Premium Blocks – Gutenberg Blocks for WordPress: from n/a through <= 2.1.42.
ModificadaAlta (8.8)0.31%—Leap13 Premium Addons FOR Elementor31/12/202417/6/2026
Missing Authorization vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-elementor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Premium Addons for Elementor: from n/a through <= 4.10.56.