Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
3693 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.29% | — | Digitware System Integration Corporation Cross-browser Document Creation ComponentAI | 14/7/2025 | 17/6/2026 | The cross-browser document creation component produced by Digitware System Integration Corporation has a Remote Code Execution vulnerability. If a user visits a malicious website while the component is active, remote attackers can cause the system to download and execute arbitrary programs. | |
| Aplazada | Alta (8.2) | 0.26% | — | Gitroom PostizAI | 11/7/2025 | 17/6/2026 | Postiz is an AI social media scheduling tool. From 1.45.1 to 1.62.3, the Postiz frontend application allows an attacker to inject arbitrary HTTP headers into the middleware pipeline. This flaw enables a server-side request forgery (SSRF) condition, which can be exploited to initiate unauthorized outbound requests from… | |
| Aplazada | Alta (8.5) | 0.57% | — | GIT GUIAI | 10/7/2025 | 17/6/2026 | Git GUI allows you to use the Git source control management tools via a GUI. When a user clones an untrusted repository and is tricked into editing a file located in a maliciously named directory in the repository, then Git GUI can create and overwrite files for which the user has write permission. This vulnerability… | |
| Aplazada | Alta (8.6) | 0.34% | — | GIT GUIAI | 10/7/2025 | 17/6/2026 | Git GUI allows you to use the Git source control management tools via a GUI. A malicious repository can ship versions of sh.exe or typical textconv filter programs such as astextplain. Due to the unfortunate design of Tcl on Windows, the search path when looking for an executable always includes the current directory.… | |
| Aplazada | Alta (8.6) | 0.40% | — | GITAIGitkAI | 10/7/2025 | 17/6/2026 | Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a user who has cloned the repository can be tricked into running any script (e.g., Bourne shell, Perl, Python, ...) supplied by the attacker by invoking gitk filename, where… | |
| Aplazada | Baja (3.6) | 0.56% | — | GitkAI | 10/7/2025 | 17/6/2026 | Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when a user clones an untrusted repository and runs gitk without additional command arguments, files for which the user has write permission can be created and truncated. The option Support per-file encoding must have been enabled before in Gitk's… | |
| Analizada | Alta (8) | 0.53% | — | Gitlab | 10/7/2025 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content. | |
| Analizada | Baja (2.7) | 0.34% | — | Gitlab | 10/7/2025 | 17/6/2026 | An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that could have allowed authenticated maintainers to bypass group-level user invitation restrictions by sending crafted API requests. | |
| Analizada | Baja (2.7) | 0.35% | — | Gitlab | 10/7/2025 | 17/6/2026 | An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that could have allowed authenticated users with invitation privileges to bypass group-level user invitation restrictions by manipulating group invitation functionality. | |
| Analizada | Media (4.3) | 0.34% | — | Gitlab | 10/7/2025 | 17/6/2026 | An issue has been discovered in GitLab EE affecting all versions from 13.3 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that could have allowed authenticated project owners to bypass group-level forking restrictions by manipulating API requests. | |
| Aplazada | Media (6.3) | 0.14% | — | Paloaltonetworks Autonomous Digital Experience ManagerAI | 9/7/2025 | 17/6/2026 | An incorrect privilege assignment vulnerability in Palo Alto Networks Autonomous Digital Experience Manager allows a locally authenticated low privileged user on macOS endpoints to escalate their privileges to root. | |
| Modificada | Alta (8.2) | 0.64% | 💥 PoC | Jenkins GIT Parameter | 9/7/2025 | 17/6/2026 | Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the offered choices, allowing attackers with Item/Build permission to inject arbitrary values into Git parameters. | |
| Aplazada | Media (6.3) | 0.41% | — | GITAI | 8/7/2025 | 17/6/2026 | Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. The wincred credential helper uses a static buffer (target) as a unique key for storing and comparing against internal storage. This credential helper… | |
| Aplazada | Alta (8.6) | 1.0% | — | GITAI | 8/7/2025 | 17/6/2026 | Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When cloning a repository Git knows to optionally fetch a bundle advertised by the remote server, which allows the server-side to offload parts of the… | |
| Analizada | Alta (8) | 4.2% | ⚠ Explotación activa💥 PoC | Git-scm GITDebian LinuxApple Xcode | 8/7/2025 | 24/9/2026 | Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are… | |
| Aplazada | Baja (2.1) | 0.43% | — | Risesoft Y9 Digital InfrastructureAI | 7/7/2025 | 17/6/2026 | A vulnerability classified as critical was found in risesoft-y9 Digital-Infrastructure up to 9.6.7. Affected by this vulnerability is the function deleteFile of the file… | |
| Analizada | Media (6.3) | 0.33% | — | Github Enterprise Server | 1/7/2025 | 17/6/2026 | An exposure of sensitive information vulnerability was identified in GitHub Enterprise Server that could allow an attacker to disclose the names of private repositories within an organization. This issue could be exploited by leveraging a user-to-server token with no scopes via the Search API endpoint. Successful… | |
| Aplazada | Alta (7.5) | 25% | — | Cyanheads Git-mcp-serverAI | 1/7/2025 | 17/6/2026 | @cyanheads/git-mcp-server is an MCP server designed to interact with Git repositories. Prior to version 2.1.5, there is a command injection vulnerability caused by the unsanitized use of input parameters within a call to child_process.exec, enabling an attacker to inject arbitrary system commands. Successful… | |
| Analizada | Alta (7.5) | 0.18% | — | Git-annex Project Git-annex | 26/6/2025 | 17/6/2026 | git-annex had a bug in the S3 and Glacier remotes where if embedcreds=yes was set, and the remote used encryption=pubkey or encryption=hybrid, the embedded AWS credentials were stored in the git repository in (effectively) plaintext, not encrypted as they were supposed to be. This issue affects git-annex: from… | |
| Analizada | Media (4.3) | 0.27% | — | Gitlab | 26/6/2025 | 17/6/2026 | An issue has been discovered in GitLab EE affecting all versions from 16.10 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to assign unrelated compliance frameworks to projects by sending crafted GraphQL mutations that bypassed framework-specific permission… | |
| Analizada | Media (4.3) | 0.26% | — | Gitlab | 26/6/2025 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users with Guest role permissions to add child items to incident work items by sending crafted API requests that bypassed UI-enforced role… | |
| Analizada | Media (6.5) | 0.37% | — | Gitlab | 26/6/2025 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated attackers to create a DoS condition by sending crafted GraphQL requests. | |
| Analizada | Alta (8.8) | 0.31% | — | Gitlab | 26/6/2025 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to gain elevated project privileges by requesting access to projects where role modifications during the approval process resulted in… | |
| Analizada | Media (5.3) | 0.30% | — | Gitlab | 26/6/2025 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed unauthenticated attackers to upload arbitrary files to public projects by sending crafted API requests, potentially leading to resource abuse and unauthorized… | |
| Aplazada | Media (6.6) | 0.47% | — | Gitforge.jlAI | 25/6/2025 | 17/6/2026 | GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 5.9.1 lack input validation of input validation for user-provided values in certain functions. In the `GitHub.repo()` function, the user can provide any string for the `repo_name` field. These inputs are not validated or safely… |