Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
259 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.22% | — | Easy Github Gist ShortcodesAI | 7/1/2026 | 17/6/2026 | The Easy GitHub Gist Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the gist shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… | |
| Analizada | Alta (8.4) | 0.22% | — | Github Enterprise Server | 6/1/2026 | 17/6/2026 | An Improper Neutralization of Input During Web Page Generation vulnerability was identified in GitHub Enterprise Server that allowed attacker controlled HTML to be rendered by the Filter component (search) across GitHub that could be used to exfiltrate sensitive information. An attacker would require permissions to… | |
| Analizada | Alta (8.6) | 0.39% | — | Github Enterprise Server | 11/12/2025 | 17/6/2026 | An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed user-supplied HTML to inject DOM elements with IDs that collided with server-initialized data islands. These collisions could overwrite or shadow critical application state objects used by certain Project views,… | |
| Analizada | Alta (7.8) | 0.36% | — | Microsoft Github Copilot | 9/12/2025 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (6.8) | 0.47% | — | Microsoft Github Copilot Chat | 11/11/2025 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code CoPilot Chat Extension allows an authorized attacker to bypass a security feature locally. | |
| Analizada | Alta (8.8) | 0.75% | — | Microsoft Github Copilot Chat | 11/11/2025 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to execute code over a network. | |
| Aplazada | Media (6.4) | 0.22% | — | Github Gist ShortcodeAI | 11/11/2025 | 17/6/2026 | The GitHub Gist Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the 'gist' shortcode in all versions up to, and including, 0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… | |
| Analizada | Alta (8.6) | 0.65% | — | Github Enterprise Server | 10/11/2025 | 17/6/2026 | An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allows DOM-based cross-site scripting via Issues search label filter that could lead to privilege escalation and unauthorized workflow triggers. Successful exploitation requires an attacker to have access to the target… | |
| Analizada | Alta (7.5) | 0.66% | — | Github Enterprise Server | 10/11/2025 | 17/6/2026 | A privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise admin to gain root SSH access to the appliance by exploiting a symlink escape in pre-receive hook environments. By crafting a malicious repository and environment, an attacker could replace system… | |
| Aplazada | Baja (3.8) | 0.13% | — | Github Workflow UpdaterAIMicrosoft VS CodeAI | 28/10/2025 | 17/6/2026 | GitHub Workflow Updater is a VS Code extension that automatically pins GitHub Actions to specific commits for enhanced security. Before 0.0.7, any provided Github token would be stored in plaintext in the editor configuration as json on disk, rather than through the more secure "securestorage" api. An attacker with… | |
| Aplazada | Alta (7.7) | 1.5% | — | Sonarqube Github ActionAI | 26/9/2025 | 17/6/2026 | SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. A command injection vulnerability exists in SonarQube GitHub Action in version 4.0.0 to before version 6.0.0 when workflows pass user-controlled input to the args parameter on Windows runners without proper… | |
| Aplazada | Media (6.5) | 0.17% | — | Sudar Muthu WP Github GistAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sudar Muthu WP Github Gist wp-github-gist allows Stored XSS.This issue affects WP Github Gist: from n/a through <= 0.5. | |
| Aplazada | Media (5.1) | 0.10% | — | Obsidian Github Copilot PluginAI | 5/9/2025 | 17/6/2026 | Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacker may perform unauthorized operations on the linked Github account. | |
| Aplazada | Alta (7.8) | 1.1% | — | Sonarqube ServerAISonarqube CloudAISonarqube Scan Github ActionAI | 2/9/2025 | 17/6/2026 | SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. In versions 4 to 5.3.0, a command injection vulnerability was discovered in the SonarQube Scan GitHub Action that allows untrusted input arguments to be processed without proper sanitization. Arguments sent to… | |
| Analizada | Alta (7) | 0.31% | — | Github Enterprise Server | 26/8/2025 | 17/6/2026 | An improper access control vulnerability was identified in GitHub Enterprise Server that allowed users with access to any repository to retrieve limited code content from another repository by creating a diff between the repositories. To exploit this vulnerability, an attacker needed to know the name of a private… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Genx FXAIGoogle CloudAIGoogle FirebaseAIGithubAI | 19/8/2025 | 17/6/2026 | GenX_FX is an advance IA trading platform that will focus on forex trading. A vulnerability was identified in the GenX FX backend where API keys and authentication tokens may be exposed if environment variables are misconfigured. Unauthorized users could gain access to cloud resources (Google Cloud, Firebase, GitHub,… | |
| Analizada | Media (5.3) | 0.27% | — | Github Enterprise Server | 15/7/2025 | 17/6/2026 | An incorrect authorization vulnerability allowed unauthorized read access to the contents of internal repositories for contractor accounts when the Contractors API feature was enabled. The Contractors API is a rarely-enabled feature in private preview. This vulnerability affected all versions of GitHub Enterprise… | |
| Aplazada | Alta (8.9) | 1.4% | — | Github Kanban MCP ServerAINodejsAIGithub GHAI | 14/7/2025 | 17/6/2026 | GitHub Kanban MCP Server is a Model Context Protocol (MCP) server for managing GitHub issues in Kanban board format and streamlining LLM task management. Version 0.3.0 of the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MCP Server tool definition… | |
| Analizada | Media (6.3) | 0.33% | — | Github Enterprise Server | 1/7/2025 | 17/6/2026 | An exposure of sensitive information vulnerability was identified in GitHub Enterprise Server that could allow an attacker to disclose the names of private repositories within an organization. This issue could be exploited by leveraging a user-to-server token with no scopes via the Search API endpoint. Successful… | |
| Aplazada | Baja (3.3) | 0.17% | — | Github DesktopAIGITAI | 21/5/2025 | 17/6/2026 | GitHub Desktop is an open-source, Electron-based GitHub app designed for git development. Prior to version 3.4.20-beta3, an attacker convincing a user to view a file in a commit of their making in the history view can cause information disclosure by means of Git attempting to access a network share. This affects… | |
| Aplazada | Crítica (9.8) | 0.57% | — | AdeptAIGithub Actions Upload ArtifactAI | 21/4/2025 | 17/6/2026 | Adept is a language for general purpose programming. Prior to commit a1a41b7, the remoteBuild.yml workflow file uses actions/upload-artifact@v4 to upload the mac-standalone artifact. This artifact is a zip of the current directory, which includes the automatically generated .git/config file containing the run's… | |
| Analizada | Alta (7.1) | 1.3% | — | Github Enterprise Server | 17/4/2025 | 17/6/2026 | A Remote Code Execution (RCE) vulnerability was identified in GitHub Enterprise Server that allowed attackers to execute arbitrary code by exploiting the pre-receive hook functionality, potentially leading to privilege escalation and system compromise. The vulnerability involves using dynamically allocated ports that… | |
| Analizada | Alta (8.6) | 0.30% | — | Github Enterprise Server | 17/4/2025 | 17/6/2026 | An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed cross-site scripting in GitHub Markdown that used `$$..$$` math blocks. Exploitation required access to the target GitHub Enterprise Server instance and privileged user interaction with the malicious elements.… | |
| Analizada | Media (5.3) | 0.42% | — | Github Enterprise Server | 17/4/2025 | 17/6/2026 | A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of private repositories that they wouldn't otherwise have access to in the Security Overview in GitHub Advanced Security. The Security Overview was required to be filtered only using the `archived:`… | |
| Aplazada | Media (6.3) | 0.41% | — | Github GHAI | 14/2/2025 | 17/6/2026 | `gh` is GitHub’s official command line tool. Starting in version 2.49.0 and prior to version 2.67.0, under certain conditions, a bug in GitHub's Artifact Attestation cli tool `gh attestation verify` causes it to return a zero exit status when no attestations are present. This behavior is incorrect: When no… |