Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2584▼ 301 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
259 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.56% | — | Github Enterprise Server | 16/7/2024 | 17/6/2026 | A Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause unbounded resource exhaustion by sending a large payload to the Git server. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in version 3.13.1, 3.12.6, 3.11.12,… | |
| Modificada | Media (6.5) | 0.48% | — | Github Enterprise Server | 16/7/2024 | 17/6/2026 | An improper privilege management vulnerability allowed users to migrate private repositories without having appropriate scopes defined on the related Personal Access Token. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.14 and was fixed in version 3.13.1, 3.12.6, 3.11.12, 3.10.14, and… | |
| Analizada | Alta (7.2) | 0.86% | — | Github Enterprise Server | 20/6/2024 | 17/6/2026 | A Server-Side Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with the Site Administrator role to gain arbitrary code execution capability on the GitHub Enterprise Server instance. Exploitation required authenticated access to GitHub Enterprise Server as a user with… | |
| Analizada | Crítica (10) | 2.6% | — | Github Enterprise Server | 20/5/2024 | 17/6/2026 | An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication with the optional encrypted assertions feature. This vulnerability allowed an attacker to forge a SAML response to provision and/or gain access to a user with site administrator… | |
| Analizada | Media (5.9) | 0.45% | — | Github Enterprise Server | 19/4/2024 | 17/6/2026 | A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on a detached repository by making a GraphQL mutation to alter repository permissions while the repository is detached. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.13 and was fixed in… | |
| Analizada | Alta (7.2) | 1.1% | — | Github Enterprise Server | 19/4/2024 | 17/6/2026 | A server side request forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin access to the appliance when configuring the Artifacts & Logs and Migrations Storage. Exploitation of this vulnerability required access to the… | |
| Analizada | Alta (7.2) | 1.7% | — | Github Enterprise Server | 19/4/2024 | 17/6/2026 | A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the instance when configuring the chat integration. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance… | |
| Analizada | Alta (7.2) | 0.59% | — | Github Enterprise Server | 19/4/2024 | 17/6/2026 | An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use a deploy key pertaining to an organization to bypass an organization ruleset. An attacker would require access to a valid deploy key for a repository in the organization as well as repository… | |
| Modificada | Alta (7.2) | 0.60% | — | Terryl WP Githuber MD | 26/3/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Terry Lin WP Githuber MD.This issue affects WP Githuber MD: from n/a through 1.16.2. | |
| Analizada | Media (6.5) | 0.61% | — | Github Enterprise Server | 21/3/2024 | 17/6/2026 | An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use the Enterprise Actions GitHub Connect download token to fetch private repository data. An attacker would require an account on the server instance with non-default settings for GitHub Connect. This… | |
| Analizada | Media (4.3) | 0.19% | — | Github Enterprise Server | 21/3/2024 | 17/6/2026 | A Cross Site Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker to execute unauthorized actions on behalf of an unsuspecting user. A mitigating factor is that user interaction is required. This vulnerability affected GitHub Enterprise Server 3.12.0 and was fixed in… | |
| Analizada | Alta (7.2) | 1.6% | — | Github Enterprise Server | 20/3/2024 | 17/6/2026 | An attacker with an Administrator role in GitHub Enterprise Server could gain SSH root access via remote code execution. This vulnerability affected GitHub Enterprise Server version 3.8.0 and above and was fixed in version 3.8.17, 3.9.12, 3.10.9, 3.11.7 and 3.12.1. This vulnerability was reported via the GitHub Bug… | |
| Analizada | Alta (7.2) | 2.1% | — | Github Enterprise Server | 20/3/2024 | 17/6/2026 | A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when configuring GeoJSON settings. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance… | |
| Analizada | Media (5.5) | 0.77% | — | Github Codeql CLI | 22/2/2024 | 17/6/2026 | The CodeQL CLI repo holds binaries for the CodeQL command line interface (CLI). Prior to version 2.16.3, an XML parser used by the CodeQL CLI to read various auxiliary files is vulnerable to an XML External Entity attack. If a vulnerable version of the CLI is used to process either a maliciously modified CodeQL… | |
| Analizada | Media (6.5) | 0.42% | — | Github Enterprise Server | 14/2/2024 | 17/6/2026 | An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to create new branches in public repositories and run arbitrary GitHub Actions workflows with permissions from the GITHUB_TOKEN. To exploit this vulnerability, an attacker would need access to the Enterprise… | |
| Modificada | Crítica (9.1) | 2.3% | — | Github Enterprise Server | 13/2/2024 | 17/6/2026 | A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via nomad templates when configuring SMTP options. Exploitation of this vulnerability required access to the GitHub Enterprise… | |
| Modificada | Crítica (9.1) | 2.6% | — | Github Enterprise Server | 13/2/2024 | 17/6/2026 | A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via nomad templates when configuring audit log forwarding. Exploitation of this vulnerability required access to the GitHub… | |
| Modificada | Crítica (9.1) | 2.3% | — | Github Enterprise Server | 13/2/2024 | 17/6/2026 | A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when configuring SAML settings. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and… | |
| Modificada | Crítica (9.1) | 2.3% | — | Github Enterprise Server | 13/2/2024 | 17/6/2026 | A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when setting the username and password for collectd configurations. Exploitation of this vulnerability required access to the… | |
| Modificada | Crítica (9.1) | 2.3% | — | Github Enterprise Server | 13/2/2024 | 17/6/2026 | A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when setting up an HTTP proxy. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and… | |
| Modificada | Crítica (9.1) | 2.4% | — | Github Enterprise Server | 13/2/2024 | 17/6/2026 | A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via the actions-console docker container while setting a service URL. Exploitation of this vulnerability required access to the… | |
| Modificada | Alta (8) | 1.7% | — | Github Enterprise Server | 13/2/2024 | 17/6/2026 | A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via the `syslog-ng` configuration file. Exploitation of this vulnerability required access to the GitHub Enterprise Server… | |
| Modificada | Media (6.1) | 0.47% | — | Github Enterprise Server | 13/2/2024 | 17/6/2026 | Cross-site Scripting in the tag name pattern field in the tag protections UI in GitHub Enterprise Server allows a malicious website that requires user interaction and social engineering to make changes to a user account via CSP bypass with created CSRF tokens. This vulnerability affected all versions of GitHub… | |
| Modificada | Media (6.5) | 0.77% | — | Github Enterprise Server | 13/2/2024 | 17/6/2026 | A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker to gain unauthorized read permission to files by deploying arbitrary symbolic links to a GitHub Pages site with a specially crafted artifact tarball. To exploit this vulnerability, an attacker would need permission to… | |
| Modificada | Media (5.3) | 0.50% | — | Jenkins Github Branch Source | 24/1/2024 | 17/6/2026 | Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token. |