Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2622▼ 221 respecto a la semana anterior
Críticas / altas1383▲ 158 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
259 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.39% | — | Github Enterprise Server | 29/1/2025 | 17/6/2026 | A Code Injection vulnerability was identified in GitHub Enterprise Server that allowed attackers to inject malicious code into the query selector via the identity property in the message handling function. This enabled the exfiltration of sensitive data by manipulating the DOM, including authentication tokens. To… | |
| Aplazada | Alta (7.1) | 1.2% | — | Github Codeql ActionAIGithub Codeql CLIAI | 24/1/2025 | 17/6/2026 | In some circumstances, debug artifacts uploaded by the CodeQL Action after a failed code scanning workflow run may contain the environment variables from the workflow run, including any secrets that were exposed as environment variables to the workflow. Users with read access to the repository would be able to access… | |
| Analizada | Alta (7.6) | 1.6% | — | Github Enterprise Server | 21/1/2025 | 17/6/2026 | An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed signature spoofing for unauthorized internal users. Instances not utilizing SAML single sign-on or where the attacker is not already an existing user were not impacted. This vulnerability affected… | |
| Aplazada | Media (6.6) | 0.76% | — | Github DesktopAI | 15/1/2025 | 17/6/2026 | GitHub Desktop is an open-source Electron-based GitHub app designed for git development. An attacker convincing a user to clone a repository directly or through a submodule can allow the attacker access to the user's credentials through the use of maliciously crafted remote URL. GitHub Desktop relies on Git to perform… | |
| Aplazada | Media (6.5) | 0.35% | — | Seinoxygen WP GithubAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in seinoxygen WP Github wp-github allows Stored XSS.This issue affects WP Github: from n/a through <= 1.3.3. | |
| Aplazada | Media (6.3) | 0.63% | — | Github CLIAI | 4/12/2024 | 17/6/2026 | The GitHub CLI is GitHub’s official command line tool. A security vulnerability has been identified in GitHub CLI that could create or overwrite files in unintended directories when users download a malicious GitHub Actions workflow artifact through gh run download. This vulnerability stems from a GitHub Actions… | |
| Aplazada | Media (6.5) | 0.28% | — | Github GH CLIAI | 27/11/2024 | 17/6/2026 | The gh cli is GitHub’s official command line tool. A security vulnerability has been identified in the GitHub CLI that could leak authentication tokens when cloning repositories containing `git` submodules hosted outside of GitHub.com and ghe.com. This vulnerability stems from several `gh` commands used to clone a… | |
| Modificada | Media (5.4) | 0.24% | — | Terryl WP Githuber MD | 18/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Terry L. WP Githuber MD wp-githuber-md allows Stored XSS.This issue affects WP Githuber MD: from n/a through <= 1.16.3. | |
| Analizada | Crítica (9.6) | 0.85% | — | Github CLI | 14/11/2024 | 17/6/2026 | The GitHub CLI version 2.6.1 and earlier are vulnerable to remote code execution through a malicious codespace SSH server when using `gh codespace ssh` or `gh codespace logs` commands. This has been patched in the cli v2.62.0. Developers connect to remote codespaces through an SSH server running within the… | |
| Analizada | Alta (8.7) | 0.44% | — | Github Enterprise Server | 7/11/2024 | 17/6/2026 | A GitHub App installed in organizations could upgrade some permissions from read to write access without approval from an organization administrator. An attacker would require an account with administrator access to install a malicious GitHub App. This vulnerability affected all versions of GitHub Enterprise Server… | |
| Analizada | Media (6) | 0.34% | — | Github Enterprise Server | 7/11/2024 | 17/6/2026 | An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed unauthorized internal users to access sensitive secret scanning alert data intended only for business owners. This issue could be exploited only by organization members with a personal access token (PAT) and required that… | |
| Analizada | Alta (8.7) | 0.84% | — | Github Enterprise Server | 7/11/2024 | 17/6/2026 | A path collision and arbitrary code execution vulnerability was identified in GitHub Enterprise Server that allowed container escape to escalate to root via ghe-firejail path. Exploitation of this vulnerability requires Enterprise Administrator access to the GitHub Enterprise Server instance. This vulnerability… | |
| Analizada | Media (5.7) | 0.64% | — | Github Enterprise Server | 11/10/2024 | 17/6/2026 | An information disclosure vulnerability was identified in GitHub Enterprise Server via attacker uploaded asset URL allowing the attacker to retrieve metadata information of a user who clicks on the URL and further exploit it to create a convincing phishing page. This required the attacker to upload malicious SVG files… | |
| Analizada | Crítica (9.5) | 26% | — | Github Enterprise Server | 10/10/2024 | 17/6/2026 | An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed resulting in unauthorized provisioning of users and access to the instance. Exploitation required the encrypted assertions feature to be enabled, and the… | |
| Analizada | Media (5.8) | 0.37% | — | Github Enterprise Server | 23/9/2024 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server, which allows attackers to steal sensitive user information via social engineering. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15,… | |
| Analizada | Media (6.2) | 0.45% | — | Github Enterprise Server | 23/9/2024 | 17/6/2026 | An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in version 3.10.17, 3.11.15, 3.12.9, 3.13.4, and 3.14.1. This vulnerability was… | |
| Modificada | Alta (7.5) | 3.2% | — | Github Actions/artifactGithub Actions Toolkit | 2/9/2024 | 17/6/2026 | actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when using `downloadArtifactInternal`, `downloadArtifactPublic`, or `streamExtractExternal` for extracting a specifically crafted artifact that… | |
| Analizada | Media (5.3) | 0.50% | — | Github Enterprise Server | 20/8/2024 | 17/6/2026 | An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the title, assignees, and labels of any issue inside a public repository. This was only exploitable inside a public repository. This vulnerability affected GitHub Enterprise Server versions before 3.14… | |
| Analizada | Crítica (9.5) | 1.5% | — | Github Enterprise Server | 20/8/2024 | 17/6/2026 | An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identity providers utilizing publicly exposed signed federation metadata XML. This vulnerability allowed an attacker with direct network access to GitHub Enterprise Server to forge a SAML… | |
| Analizada | Media (5.9) | 0.70% | — | Github Enterprise Server | 20/8/2024 | 17/6/2026 | An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a GitHub App with only content: read and pull_request_write: write permissions to read issue content inside a private repository. This was only exploitable via user access token and installation access token was not… | |
| Modificada | Media (6.3) | 0.49% | — | Github Enterprise Server | 16/7/2024 | 17/6/2026 | An exposure of sensitive information vulnerability in GitHub Enterprise Server would allow an attacker to enumerate the names of private repositories that utilize deploy keys. This vulnerability did not allow unauthorized access to any repository content besides the name. This vulnerability affected all versions of… | |
| Modificada | Media (6.9) | 0.42% | — | Github Enterprise Server | 16/7/2024 | 17/6/2026 | A Security Misconfiguration vulnerability in GitHub Enterprise Server allowed sensitive information disclosure to unauthorized users in GitHub Enterprise Server by exploiting organization ruleset feature. This attack required an organization member to explicitly change the visibility of a dependent repository from… | |
| Modificada | Media (5.9) | 0.51% | — | Github Enterprise Server | 16/7/2024 | 17/6/2026 | An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed read access to issue content via GitHub Projects. This was only exploitable in internal repositories and required the attacker to have access to the corresponding project board. This vulnerability affected all versions of… | |
| Modificada | Media (6.9) | 0.51% | — | Github Enterprise Server | 16/7/2024 | 17/6/2026 | An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a suspended GitHub App to retain access to the repository via a scoped user access token. This was only exploitable in public repositories while private repositories were not impacted. This vulnerability affected all… | |
| Modificada | Media (6.8) | 0.25% | — | Github Enterprise Server | 16/7/2024 | 17/6/2026 | A Cross-Site Request Forgery vulnerability in GitHub Enterprise Server allowed write operations on a victim-owned repository by exploiting incorrect request types. A mitigating factor is that the attacker would have to be a trusted GitHub Enterprise Server user, and the victim would have to visit a tag in the… |