Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
3694 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.32% | — | IBM Verify Identity Access Digital Credentials | 6/6/2025 | 17/6/2026 | IBM Verify Identity Access Digital Credentials 24.06 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | |
| Aplazada | Media (5.3) | 0.42% | — | Ashinigit XueshengzhusuAI | 31/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in ashinigit 天青一白 XueShengZhuSu 学生住宿管理系统 up to 4d3f0ada0e71482c1e51fd5f5615e5a3d8bcbfbb. This issue affects some unknown processing of the file /upload/ of the component Image File Upload. The manipulation of the argument File leads to path traversal.… | |
| Analizada | Alta (8.7) | 0.56% | — | Gitlab | 30/5/2025 | 17/6/2026 | An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1. | |
| Analizada | Media (5.4) | 0.34% | — | Awesomemotive Easy Digital Downloads | 29/5/2025 | 17/6/2026 | The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's edd_receipt shortcode in all versions up to, and including, 3.3.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Modificada | Crítica (9.8) | 0.51% | — | Digitalzoomstudio Zoomsounds | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ZoomIt ZoomSounds dzs-zoomsounds allows Object Injection.This issue affects ZoomSounds: from n/a through <= 6.91. | |
| Aplazada | Media (6.5) | 0.25% | — | Phpaddicted Igit-related-posts-with-thumb-images-after-postsAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phpaddicted IGIT Related Posts With Thumb Image After Posts igit-related-posts-with-thumb-images-after-posts allows Stored XSS.This issue affects IGIT Related Posts With Thumb Image After Posts: from n/a through <=… | |
| Analizada | Alta (7.5) | 0.40% | — | Gitlab | 23/5/2025 | 17/6/2026 | A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11.3 and 18.0 prior to 18.0.1 where an attacker can cause a branch name confusion in confidential MRs. | |
| Analizada | Alta (7.5) | 0.51% | — | Gitlab | 23/5/2025 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A Discord webhook integration may cause DoS. | |
| Analizada | Media (6.5) | 0.51% | — | Gitlab | 22/5/2025 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. This could allow an authenticated attacker to cause a denial of service condition by exhausting server resources. | |
| Analizada | Media (4.3) | 0.33% | — | Gitlab | 22/5/2025 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Under certain conditions un-authorised users can view full email addresses that should be partially obscured. | |
| Analizada | Media (4.3) | 0.29% | — | Gitlab | 22/5/2025 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements. | |
| Analizada | Media (6.8) | 0.47% | — | Gitlab | 22/5/2025 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modified SAML response to bypass 2FA requirement under specialized conditions. | |
| Analizada | Alta (7.5) | 0.44% | — | Gitlab | 22/5/2025 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and observing the HTTP response. | |
| Analizada | Media (6.5) | 0.46% | — | Gitlab | 22/5/2025 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in the Kubernetes integration could allow an authenticated user to cause denial of service.. | |
| Analizada | Media (6.5) | 0.47% | — | Gitlab | 22/5/2025 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of proper validation in GitLab could allow an authenticated user to cause a denial of service condition. | |
| Analizada | Media (4.3) | 0.32% | — | Gitlab | 22/5/2025 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access Job Data via a crafted GraphQL query. | |
| Aplazada | Baja (3.3) | 0.17% | — | Github DesktopAIGITAI | 21/5/2025 | 17/6/2026 | GitHub Desktop is an open-source, Electron-based GitHub app designed for git development. Prior to version 3.4.20-beta3, an attacker convincing a user to view a file in a commit of their making in the history view can cause information disclosure by means of Git attempting to access a network share. This affects… | |
| Analizada | Media (6.8) | 0.81% | — | Eclipse Jgit | 21/5/2025 | 17/6/2026 | In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing… | |
| Analizada | Crítica (9.8) | 16% | 💥 Exploit | Unitedover Digits | 21/5/2025 | 17/6/2026 | The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it straightforward for attackers to bruteforce them. | |
| Analizada | Media (6.1) | 0.51% | 💥 Exploit | Hkdigit Payment Gateway FOR Telcell | 15/5/2025 | 17/6/2026 | The Payment Gateway for Telcell WordPress plugin through 2.0.1 does not validate the api_url parameter before redirecting the user to its value, leading to an Open Redirect issue | |
| Analizada | Media (5.4) | 0.18% | — | Westerndeal Easy Digital Downloads Google Sheet ConnectorEDD Gsheetconnector | 15/5/2025 | 17/6/2026 | The edd-google-sheet-connector-pro WordPress plugin before 1.4, Easy Digital Downloads Google Sheet Connector WordPress plugin before 1.6.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack | |
| Modificada | Baja (2.1) | 0.41% | — | Digitro NGC Explorer | 11/5/2025 | 31/7/2026 | A weakness has been identified in Dígitro NGC Explorer up to 3.48.21. This affects an unknown function. Executing a manipulation can lead to session expiration. The attack can be launched remotely. Upgrading to version 3.48.22 mitigates this issue. It is recommended to upgrade the affected component. The action taken… | |
| Modificada | Baja (2.9) | 0.62% | — | Digitro NGC Explorer | 11/5/2025 | 31/7/2026 | A security flaw has been discovered in Dígitro NGC Explorer up to 3.48.21. The impacted element is an unknown function of the component Password Transmission Handler. Performing a manipulation results in client-side enforcement of server-side security. The attack can be initiated remotely. The complexity of an attack… | |
| Modificada | Baja (2.1) | 0.30% | — | Digitro NGC Explorer | 11/5/2025 | 31/7/2026 | A vulnerability was identified in Dígitro NGC Explorer up to 3.48.21. The affected element is an unknown function of the component Configuration Page. Such manipulation leads to missing password field masking. It is possible to launch the attack remotely. Upgrading to version 3.48.22 is sufficient to fix this issue.… | |
| Analizada | Alta (7.5) | 0.39% | — | Gitlab | 9/5/2025 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 17.11 before 17.11.2. Under certain conditions users could bypass IP access restrictions and view sensitive information. |