Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2573▼ 368 respecto a la semana anterior
Críticas / altas1324▲ 44 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)97▼ 430 respecto a la semana anterior
3658 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | 93digital Typing EffectAI | 18/8/2026 | 20/8/2026 | Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions. | |
| Analizada | Alta (7.1) | 0.61% | — | Gitlab | 17/8/2026 | 2/9/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could have allowed an unauthenticated user to execute mutations via GET requests due to improper request validation in GraphQL… | |
| Analizada | Crítica (9.1) | 60% | — | Gitlab | 17/8/2026 | 2/9/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive. | |
| Pendiente de análisis | Media (4.3) | 0.29% | — | MattermostAIMattermost Gitlab PluginAI | 17/8/2026 | 18/8/2026 | Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost GitLab plugin fails to verify channel permissions when processing API requests with a caller-supplied_ {{post_id}}_, and fails to validate the_ {{web_url}} _parameter against the configured GitLab instance, which allows an authenticated attacker to… | |
| Aplazada | Baja (1.3) | 0.39% | — | Orange View Limited Dualsafe Password Manager AND Digital Vault ExtensionAI | 17/8/2026 | 20/8/2026 | A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome. Affected is an unknown function of the component postMessage-based Bridge. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. A high complexity level… | |
| Aplazada | Crítica (9.8) | 0.72% | — | Digitialpixies Oauth ClientAI | 16/8/2026 | 26/8/2026 | Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token. Passing a callback to the constructor selects OAuth 1.0a. get_request_token then revokes that choice when the request token response omits oauth_callback_confirmed, with no… | |
| Aplazada | Media (4.3) | 0.41% | — | GiteaAI | 13/8/2026 | 26/8/2026 | Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads | |
| Aplazada | Media (4.3) | 0.33% | — | GiteaAI | 13/8/2026 | 26/8/2026 | GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private | |
| Aplazada | Crítica (9.1) | 0.48% | — | GiteaAI | 13/8/2026 | 26/8/2026 | Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) | |
| Aplazada | Media (6.8) | 0.48% | — | GithubAI | 13/8/2026 | 26/8/2026 | Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`) | |
| Aplazada | Media (5.4) | 0.29% | — | GiteaAI | 13/8/2026 | 26/8/2026 | Gitea LFS Deploy-Key Privilege Escalation | |
| Aplazada | Media (5.9) | 0.43% | — | GiteaAI | 13/8/2026 | 26/8/2026 | Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea | |
| Aplazada | Alta (7.7) | 0.40% | — | GiteaAI | 13/8/2026 | 26/8/2026 | Two SSRF findings in Gitea 1.26.2 | |
| Aplazada | Crítica (9.1) | 0.48% | — | GiteaAI | 13/8/2026 | 26/8/2026 | Gitea Remember-Me Token Theft Not Invalidating Attacker Session | |
| Aplazada | Media (6.2) | 0.17% | — | GiteaAI | 13/8/2026 | 26/8/2026 | Gitea SSH Key Parser Denial of Service | |
| Aplazada | Media (6.5) | 0.41% | — | Github ActionsAI | 13/8/2026 | 26/8/2026 | The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as read-only because it is a GET request. A holder of a leaked read:user-scoped token can therefore mint… | |
| Aplazada | Crítica (9.8) | 0.61% | — | Digitialpixies Oauth ClientAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions. | |
| Analizada | Alta (8.7) | 0.92% | — | Gitpython Project Gitpython | 13/8/2026 | 3/9/2026 | GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted option dictionaries to clone_from, fetch, pull, push, ls_remote, iter_commits, blame, or… | |
| Analizada | Alta (7.7) | 0.83% | — | Gitpython Project Gitpython | 13/8/2026 | 3/9/2026 | GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply --template pointing to a directory containing malicious post-checkout hooks that execute when git clones the… | |
| Analizada | Alta (8.7) | 0.51% | — | Gitpython Project Gitpython | 13/8/2026 | 3/9/2026 | GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to exfiltrate secrets by supplying URLs containing variable references. Attackers can craft URLs with environment variable tokens that are expanded into .git/config and… | |
| Analizada | Media (5.3) | 0.36% | — | Gitpython Project Gitpython | 13/8/2026 | 3/9/2026 | GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to 'git rev-list' without the check_unsafe_options guard present in the sibling iter_items method. An attacker who can control options passed to Commit.count (e.g., via an application… | |
| Analizada | Alta (7.2) | 0.57% | — | Gitpython Project Gitpython | 13/8/2026 | 3/9/2026 | GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary files with repository content or -F to read arbitrary files returned in-band. | |
| Analizada | Alta (7.1) | 0.41% | — | Gitpython Project Gitpython | 13/8/2026 | 3/9/2026 | GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned archive. | |
| Analizada | Alta (7.2) | 0.55% | — | Gitpython Project Gitpython | 13/8/2026 | 28/9/2026 | GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter or output kwarg to write patch content to attacker-chosen file paths at process… | |
| Analizada | Media (4.3) | 0.36% | — | Gitlab | 12/8/2026 | 19/8/2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 12.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to bypass IP-based access restrictions and read limited merge request information from a private project due to… |