Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
76 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.51% | — | Enalean Tuleap | 13/12/2022 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. In versions prior to 14.2.99.104, project level authorizations are not properly verified when accessing the project "homepage"/dashboards. Users not authorized to access a project may still be able to get some information… | |
| Modificada | Media (4.3) | 0.47% | — | Enalean Tuleap | 13/12/2022 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. In versions prior to 14.2.99.148, Authorizations are not properly verified when accessing MediaWiki standalone resources. Users with read only permissions for pages are able to also edit them. This only affects the… | |
| Modificada | Media (5.3) | 0.75% | — | Jenkins Tuleap GIT Branch Source | 19/10/2022 | 17/6/2026 | A missing permission check in Jenkins Tuleap Git Branch Source Plugin 3.2.4 and earlier allows unauthenticated attackers to trigger Tuleap projects whose configured repository matches the attacker-specified value. | |
| Modificada | Media (5.4) | 0.68% | — | Enalean Tuleap | 19/10/2022 | 17/6/2026 | Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions 12.9.99.228 and above, prior to 14.0.99.24, authorizations are not properly verified when updating the branch prefix used by the GitLab repository integration. Authenticated users can change the branch… | |
| Modificada | Media (5.4) | 0.65% | — | Enalean Tuleap | 1/8/2022 | 17/6/2026 | Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versions Tuleap does not properly verify permissions when creating branches with the REST API in Git repositories using the fine grained permissions. Users can create branches via the REST endpoint `POST… | |
| Modificada | Media (5.4) | 0.66% | — | Enalean Tuleap | 29/6/2022 | 17/6/2026 | Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior to 13.9.99.111 the title of a document is not properly escaped in the search result of MyDocmanSearch widget and in the administration page of the locked documents. A malicious user with the… | |
| Modificada | Alta (7.2) | 1.5% | — | Enalean Tuleap | 29/6/2022 | 17/6/2026 | Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior to 13.9.99.95 Tuleap does not sanitize properly user inputs when constructing the SQL query to retrieve data for the tracker reports. An attacker with the capability to create a new tracker can… | |
| Modificada | Media (4.3) | 0.96% | — | Enalean Tuleap | 29/6/2022 | 17/6/2026 | Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior to 13.9.99.58 authorizations are not properly verified when creating projects or trackers from projects marked as templates. Users can get access to information in those template projects because… | |
| Modificada | Media (4.3) | 0.78% | — | Enalean Tuleap | 9/6/2022 | 17/6/2026 | Tuleap is a Free & Open Source Suite to manage software developments and collaboration. In versions prior to 13.7.99.239 Tuleap does not properly verify authorizations when displaying the content of tracker report renderer and chart widgets. Malicious users could use this vulnerability to retrieve the name of a… | |
| Modificada | Alta (8.8) | 1.5% | — | Enalean Tuleap | 15/12/2021 | 17/6/2026 | Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected versions Tuleap does not sanitize properly user settings when constructing the SQL query to browse and search commits in the CVS repositories. A authenticated malicious user with read access to a CVS… | |
| Modificada | Alta (7.2) | 1.4% | — | Enalean Tuleap | 15/12/2021 | 17/6/2026 | Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. This is a follow up to GHSA-887w-pv2r-x8pm/CVE-2021-41276, the initial fix was incomplete. Tuleap does not sanitize properly the search filter built from the ldap_id attribute of a user during the daily… | |
| Modificada | Alta (7.2) | 1.5% | — | Enalean Tuleap | 15/12/2021 | 17/6/2026 | Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected versions Tuleap does not sanitize properly the search filter built from the ldap_id attribute of a user during the daily synchronization. A malicious user could force accounts to be suspended or take… | |
| Modificada | Alta (8.8) | 1.5% | — | Enalean Tuleap | 18/10/2021 | 17/6/2026 | Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versions Tuleap does not sanitize properly user inputs when constructing the SQL query to browse and search revisions in the CVS repositories. The following versions contain the fix: Tuleap Community… | |
| Modificada | Alta (8.8) | 1.5% | — | Enalean Tuleap | 18/10/2021 | 17/6/2026 | Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versions an attacker with read access to a "SVN core" repository could execute arbitrary SQL queries. The following versions contain the fix: Tuleap Community Edition 11.17.99.144, Tuleap Enterprise… | |
| Modificada | Alta (8.8) | 1.5% | — | Enalean Tuleap | 15/10/2021 | 17/6/2026 | Tuleap Open ALM is a libre and open source tool for end to end traceability of application and system developments. Prior to version 11.16.99.173 of Community Edition and versions 11.16-6 and 11.15-8 of Enterprise Edition, an attacker with the ability to add one the CI widget to its personal dashboard could execute… | |
| Modificada | Alta (7.2) | 1.9% | — | Enalean Tuleap | 15/10/2021 | 17/6/2026 | Tuleap Open ALM is a libre and open source tool for end to end traceability of application and system developments. Prior to version 11.16.99.173 of Community Edition and versions 11.16-6 and 11.15-8 of Enterprise Edition, an attacker with admin rights in one agile dashboard service can execute arbitrary SQL queries.… | |
| Modificada | Media (5.4) | 0.73% | — | Enalean Tuleap | 14/10/2021 | 17/6/2026 | Tuleap Open ALM is a libre and open source tool for end to end traceability of application and system developments. There is a cross-site scripting vulnerability in Tuleap Community Edition prior to 12.11.99.25 and Tuleap Enterprise Edition 12.11-2. A malicious user with the capability to add and remove attachment to… | |
| Modificada | Crítica (9.8) | 1.8% | — | Enalean Tuleap | 21/9/2018 | 17/6/2026 | An issue was discovered in Enalean Tuleap before 10.5. Reset password links are not invalidated after a user changes its password. | |
| Modificada | Crítica (9.8) | 4.2% | 💥 Exploit | Enalean Tuleap | 12/3/2018 | 17/6/2026 | A SQL injection vulnerability in the tracker functionality of Enalean Tuleap software engineering platform before 9.18 allows attackers to execute arbitrary SQL commands. | |
| Modificada | Alta (8.8) | 0.79% | — | Enalean Tuleap | 1/3/2018 | 17/6/2026 | An issue was discovered in Enalean Tuleap 9.17. Lack of CSRF attack mitigation while changing an e-mail address makes it possible to abuse the functionality by attackers. By making a CSRF attack, an attacker could make a victim change his registered e-mail address on the application, leading to account takeover. | |
| Modificada | Alta (8.8) | 67% | 💥 Exploit | Enalean Tuleap | 30/10/2017 | 17/6/2026 | An issue was discovered in Enalean Tuleap 9.6 and prior versions. The vulnerability exists because the User::getRecentElements() method is using the unserialize() function with a preference value that can be arbitrarily manipulated by malicious users through the REST API interface, and this can be exploited to inject… | |
| Modificada | Alta (8.8) | 16% | 💥 Exploit | Enalean TuleapPhpwiki Project Phpwiki | 29/4/2017 | 17/6/2026 | Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project Wiki component because the proc_open PHP function is used within PhpWiki before 1.5.5 with a syntax value in its first argument, and an authenticated Tuleap user can control this value, even with… | |
| Modificada | Media (6) | 15% | 💥 Exploit | Enalean Tuleap | 2/12/2014 | 17/6/2026 | project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via the data parameter. | |
| Modificada | Alta (9.3) | 5.1% | 💥 Exploit | Enalean Tuleap | 28/11/2014 | 17/6/2026 | Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is provided to the passthru PHP function. | |
| Modificada | Media (6.5) | 2.2% | 💥 Exploit | Enalean Tuleap | 4/11/2014 | 17/6/2026 | SQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL commands via the lobal_txt parameter to plugins/docman. |