Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
2101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.2) | 0.16% | — | Hcltech HCL Leap | 24/4/2025 | 17/6/2026 | Missing "no cache" headers in HCL Leap permits user directory information to be cached. | |
| Analizada | Media (4.6) | 0.29% | — | Hcltech HCL Leap | 24/4/2025 | 17/6/2026 | Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications. | |
| Analizada | Media (5.4) | 0.23% | — | Hcltech HCL Leap | 24/4/2025 | 17/6/2026 | Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications. | |
| Analizada | Media (6.1) | 0.26% | — | Hcltech HCL Leap | 24/4/2025 | 17/6/2026 | Multiple vectors in HCL Leap allow client-side script injection in the authoring environment and deployed applications. | |
| Analizada | Media (5.4) | 0.24% | — | Hcltech HCL Leap | 24/4/2025 | 17/6/2026 | Insufficient sanitization in HCL Leap allows client-side script injection in the authoring environment. | |
| Analizada | Media (5.4) | 0.30% | — | Hcltech HCL Leap | 24/4/2025 | 17/6/2026 | Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget. | |
| Analizada | Media (5.3) | 0.31% | — | Hcltech HCL Leap | 24/4/2025 | 17/6/2026 | Insufficient default configuration in HCL Leap allows anonymous access to directory information. | |
| Analizada | Media (6.1) | 0.24% | — | Hcltech HCL Leap | 24/4/2025 | 17/6/2026 | Insufficient URI protocol whitelist in HCL Leap allows script injection through query parameters. | |
| Analizada | Media (4.1) | 0.27% | — | Hcltech HCL Leap | 24/4/2025 | 17/6/2026 | Improper access control of endpoint in HCL Leap allows certain admin users to import applications from the server's filesystem. | |
| Analizada | Media (5.3) | 0.37% | — | Enalean Tuleap | 31/3/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker can access release notes content or information via the FRS REST endpoints it should not have access to. This vulnerability is fixed in Tuleap Community Edition 16.5.99.1742812323 and Tuleap Enterprise Edition… | |
| Analizada | Media (4.8) | 0.30% | — | Enalean Tuleap | 31/3/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap allows cross-site scripting (XSS) via the content of RSS feeds in the RSS widgets. A project administrator or someone with control over an used RSS feed could use this vulnerability to force victims to execute… | |
| Analizada | Media (4.3) | 0.33% | — | Enalean Tuleap | 31/3/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap does not enforce read permissions on parent trackers in the REST API. This vulnerability is fixed in Tuleap Community Edition 16.5.99.1742392651 and Tuleap Enterprise Edition 16.5-5 and 16.4-8. | |
| Analizada | Media (4.3) | 0.20% | — | Enalean Tuleap | 31/3/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap is missing CSRF protection on tracker hierarchy administration. An attacker could use this vulnerability to trick victims into submitting or editing artifacts or follow-up comments. This vulnerability is fixed in… | |
| Analizada | Media (4.3) | 0.20% | — | Enalean Tuleap | 31/3/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap has missing CSRF protections on artifact submission & edition from the tracker view. An attacker could use this vulnerability to trick victims into submitting or editing artifacts or follow-up comments. The… | |
| Analizada | Media (4.6) | 0.17% | — | Enalean Tuleap | 4/3/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap is missing CSRF protections on tracker fields administrative operations. An attacker could use this vulnerability to trick victims into removing or updating tracker fields. This vulnerability is fixed in Tuleap… | |
| Analizada | Media (4.6) | 0.33% | — | Enalean Tuleap | 4/3/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. In a standard usages of Tuleap, the issue has a limited impact, it will mostly leave dangling data. However, a malicious user could create and delete reports multiple times to cycle through all the filters of all reports… | |
| Analizada | Media (5.4) | 0.27% | — | Enalean Tuleap | 4/3/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. The mass emailing features do not sanitize the content of the HTML emails. A malicious user could use this issue to facilitate a phishing attempt or to indirectly exploit issues in the recipients mail clients. This… | |
| Analizada | Media (6.5) | 0.38% | — | Enalean Tuleap | 4/3/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. The password to connect the Redis instance is not purged from the archive generated with tuleap collect-system-data. These archives are likely to be used by support teams that should not have access to this password. The… | |
| Analizada | Media (4.8) | 0.30% | — | Enalean Tuleap | 3/3/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap allows cross-site scripting (XSS) via the tracker names used in the semantic timeframe deletion message. A tracker administrator with a semantic timeframe used by other trackers could use this vulnerability to force… | |
| Analizada | Media (5.4) | 0.36% | — | Enalean Tuleap | 3/3/2025 | 17/6/2026 | Tuleap is an open-source suite designed to improve software development management and collaboration. A malicious user with access to a tracker could force-reset certain field configurations, leading to potential information loss. The display time attribute for the date field, the size attribute for the multiselectbox… | |
| Analizada | Media (5.3) | 0.35% | — | Enalean Tuleap | 3/2/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users (possibly anonymous ones if the widget is used in the dashboard of a public project) might get access to artifacts they should not see. This issue has been addressed in Tuleap Community Edition 16.3.99.1737562605 as… | |
| Analizada | Media (4.3) | 0.33% | — | Enalean Tuleap | 3/2/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. In affected versions an unauthorized user might get access to restricted information. This issue has been addressed in Tuleap Community Edition 16.3.99.1736242932, Tuleap Enterprise Edition 16.2-5, and Tuleap Enterprise… | |
| Aplazada | Alta (7.1) | 0.20% | — | Aleapp WP Cookies AlertAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in aleapp WP Cookies Alert wp-cookies-alert allows Cross Site Request Forgery.This issue affects WP Cookies Alert: from n/a through <= 1.1.1. | |
| Aplazada | Media (6.5) | 0.25% | — | Leap13 Premium BlocksAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leap13 Premium Blocks – Gutenberg Blocks for WordPress premium-blocks-for-gutenberg allows Stored XSS.This issue affects Premium Blocks – Gutenberg Blocks for WordPress: from n/a through <= 2.1.42. | |
| Modificada | Alta (8.8) | 0.31% | — | Leap13 Premium Addons FOR Elementor | 31/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-elementor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Premium Addons for Elementor: from n/a through <= 4.10.56. |