Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
2101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.75% | — | Jenkins Tuleap GIT Branch Source | 19/10/2022 | 17/6/2026 | A missing permission check in Jenkins Tuleap Git Branch Source Plugin 3.2.4 and earlier allows unauthenticated attackers to trigger Tuleap projects whose configured repository matches the attacker-specified value. | |
| Modificada | Media (5.4) | 0.68% | — | Enalean Tuleap | 19/10/2022 | 17/6/2026 | Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions 12.9.99.228 and above, prior to 14.0.99.24, authorizations are not properly verified when updating the branch prefix used by the GitLab repository integration. Authenticated users can change the branch… | |
| Modificada | Media (4.4) | 0.15% | — | Opensuse LeapOpensuse Leap MicroSuse Linux Enterprise Server | 6/10/2022 | 17/6/2026 | A Incorrect Authorization vulnerability in chkstat of SUSE Linux Enterprise Server 12-SP5; openSUSE Leap 15.3, openSUSE Leap 15.4, openSUSE Leap Micro 5.2 did not consider group writable path components, allowing local attackers with access to a group what can write to a location included in the path to a privileged… | |
| Modificada | Media (5.4) | 0.65% | — | Enalean Tuleap | 1/8/2022 | 17/6/2026 | Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versions Tuleap does not properly verify permissions when creating branches with the REST API in Git repositories using the fine grained permissions. Users can create branches via the REST endpoint `POST… | |
| Modificada | Media (5.4) | 0.66% | — | Enalean Tuleap | 29/6/2022 | 17/6/2026 | Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior to 13.9.99.111 the title of a document is not properly escaped in the search result of MyDocmanSearch widget and in the administration page of the locked documents. A malicious user with the… | |
| Modificada | Alta (7.2) | 1.5% | — | Enalean Tuleap | 29/6/2022 | 17/6/2026 | Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior to 13.9.99.95 Tuleap does not sanitize properly user inputs when constructing the SQL query to retrieve data for the tracker reports. An attacker with the capability to create a new tracker can… | |
| Modificada | Media (4.3) | 0.96% | — | Enalean Tuleap | 29/6/2022 | 17/6/2026 | Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior to 13.9.99.58 authorizations are not properly verified when creating projects or trackers from projects marked as templates. Users can get access to information in those template projects because… | |
| Modificada | Media (4.3) | 0.78% | — | Enalean Tuleap | 9/6/2022 | 17/6/2026 | Tuleap is a Free & Open Source Suite to manage software developments and collaboration. In versions prior to 13.7.99.239 Tuleap does not properly verify authorizations when displaying the content of tracker report renderer and chart widgets. Malicious users could use this vulnerability to retrieve the name of a… | |
| Modificada | Media (5.5) | 1.1% | — | Uriparser Project UriparserFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux+3 | 6/1/2022 | 17/6/2026 | An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax. | |
| Modificada | Media (5.5) | 1.1% | — | Uriparser Project UriparserFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux+3 | 6/1/2022 | 17/6/2026 | An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner. | |
| Modificada | Alta (7.5) | 2.9% | — | Ruby-lang CGIRuby-lang RubyRedhat Software CollectionsRedhat Enterprise Linux+5 | 1/1/2022 | 17/6/2026 | CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby. | |
| Modificada | Alta (7.5) | 3.2% | — | Ruby-lang DateRuby-lang RubyRedhat Software CollectionsRedhat Enterprise Linux+5 | 1/1/2022 | 17/6/2026 | Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1. | |
| Modificada | Alta (7.3) | 0.40% | — | Leap Bitmask Riseup VPN | 30/12/2021 | 17/6/2026 | Bitmask Riseup VPN 0.21.6 contains a local privilege escalation flaw due to improper access controls. When the software is installed with a non-default installation directory off of the system root, the installer fails to properly set ACLs. This allows lower privileged users to replace the VPN executable with a… | |
| Modificada | Alta (8.8) | 1.5% | — | Enalean Tuleap | 15/12/2021 | 17/6/2026 | Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected versions Tuleap does not sanitize properly user settings when constructing the SQL query to browse and search commits in the CVS repositories. A authenticated malicious user with read access to a CVS… | |
| Modificada | Alta (7.2) | 1.4% | — | Enalean Tuleap | 15/12/2021 | 17/6/2026 | Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. This is a follow up to GHSA-887w-pv2r-x8pm/CVE-2021-41276, the initial fix was incomplete. Tuleap does not sanitize properly the search filter built from the ldap_id attribute of a user during the daily… | |
| Modificada | Alta (7.2) | 1.5% | — | Enalean Tuleap | 15/12/2021 | 17/6/2026 | Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected versions Tuleap does not sanitize properly the search filter built from the ldap_id attribute of a user during the daily synchronization. A malicious user could force accounts to be suspended or take… | |
| Modificada | Alta (8.8) | 1.5% | — | Enalean Tuleap | 18/10/2021 | 17/6/2026 | Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versions Tuleap does not sanitize properly user inputs when constructing the SQL query to browse and search revisions in the CVS repositories. The following versions contain the fix: Tuleap Community… | |
| Modificada | Alta (8.8) | 1.5% | — | Enalean Tuleap | 18/10/2021 | 17/6/2026 | Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versions an attacker with read access to a "SVN core" repository could execute arbitrary SQL queries. The following versions contain the fix: Tuleap Community Edition 11.17.99.144, Tuleap Enterprise… | |
| Modificada | Alta (8.8) | 1.5% | — | Enalean Tuleap | 15/10/2021 | 17/6/2026 | Tuleap Open ALM is a libre and open source tool for end to end traceability of application and system developments. Prior to version 11.16.99.173 of Community Edition and versions 11.16-6 and 11.15-8 of Enterprise Edition, an attacker with the ability to add one the CI widget to its personal dashboard could execute… | |
| Modificada | Alta (7.2) | 1.9% | — | Enalean Tuleap | 15/10/2021 | 17/6/2026 | Tuleap Open ALM is a libre and open source tool for end to end traceability of application and system developments. Prior to version 11.16.99.173 of Community Edition and versions 11.16-6 and 11.15-8 of Enterprise Edition, an attacker with admin rights in one agile dashboard service can execute arbitrary SQL queries.… | |
| Modificada | Media (5.4) | 0.73% | — | Enalean Tuleap | 14/10/2021 | 17/6/2026 | Tuleap Open ALM is a libre and open source tool for end to end traceability of application and system developments. There is a cross-site scripting vulnerability in Tuleap Community Edition prior to 12.11.99.25 and Tuleap Enterprise Edition 12.11-2. A malicious user with the capability to add and remove attachment to… | |
| Modificada | Media (5.4) | 0.59% | — | Leap13 Premium Addons FOR Elementor | 5/5/2021 | 17/6/2026 | The “Premium Addons for Elementor” WordPress Plugin before 4.2.8 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method. | |
| Modificada | Media (6.5) | 1.2% | — | Intel ConnmanDebian LinuxOpensuse Leap | 9/2/2021 | 17/6/2026 | gdhcp in ConnMan before 1.39 could be used by network-adjacent attackers to leak sensitive stack information, allowing further exploitation of bugs in gdhcp. | |
| Modificada | Alta (8.8) | 1.3% | — | Intel ConnmanDebian LinuxOpensuse Leap | 9/2/2021 | 17/6/2026 | A stack-based buffer overflow in dnsproxy in ConnMan before 1.39 could be used by network adjacent attackers to execute code. | |
| Modificada | Media (5.7) | 0.56% | — | Intel Ax201 FirmwareIntel Ax200 FirmwareIntel AC 9560 FirmwareIntel AC 9462 Firmware+11 | 23/11/2020 | 17/6/2026 | Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access. |