Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2709▼ 126 respecto a la semana anterior
Críticas / altas1231▼ 312 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)257▲ 221 respecto a la semana anterior
3702 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.66% | — | Gitlab | 13/7/2023 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.10 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. It may be possible for users to view new commits to private projects in a fork created while the project was public. | |
| Modificada | Alta (7.8) | 0.73% | — | Github Pull Requests AND Issues | 11/7/2023 | 17/6/2026 | Visual Studio Code GitHub Pull Requests and Issues Extension Remote Code Execution Vulnerability | |
| Modificada | Media (4.3) | 0.58% | — | Gitlab | 11/7/2023 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to leak the email address of a user who created a service desk issue. | |
| Modificada | Alta (8.8) | 0.32% | — | Digitalinspiration Google XML Sitemap FOR Mobile | 10/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Mobile plugin <= 1.6.1 versions. | |
| Modificada | Media (4.4) | 0.48% | — | Gitea | 5/7/2023 | 17/6/2026 | Vulnerabilidad de redireccionamiento abierto en el repositorio de GitHub go-Gitea/Gitea antes de 1.19.4. | |
| Modificada | Crítica (9.8) | 0.69% | — | Westerndigital MY Cloud OS | 1/7/2023 | 17/6/2026 | An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow an attacker to carry out an impersonation attack. This issue affects My Cloud OS 5 devices: before 5.26.202. | |
| Modificada | Alta (8.8) | 0.87% | — | Westerndigital MY Cloud OS | 30/6/2023 | 17/6/2026 | A post-authentication remote command injection vulnerability in a CGI file in Western Digital My Cloud OS 5 devices that could allow an attacker to build files with redirects and execute larger payloads. This issue affects My Cloud OS 5 devices: before 5.26.300. | |
| Modificada | Media (6.7) | 1.3% | — | Westerndigital MY Cloud OS | 30/6/2023 | 17/6/2026 | Post-authentication remote command injection vulnerability in Western Digital My Cloud OS 5 devices that could allow an attacker to execute code in the context of the root user on vulnerable CGI files. This vulnerability can only be exploited over the network and the attacker must already have admin/root privileges to… | |
| Modificada | Media (6.5) | 1.6% | — | Gitlab | 28/6/2023 | 17/6/2026 | An issue has been discovered in GitLab affecting all versions starting from 15.10 before 16.1, leading to a ReDoS vulnerability in the Jira prefix | |
| Modificada | Media (5.3) | 0.76% | — | Gitlab | 28/6/2023 | 17/6/2026 | An issue has been discovered in GitLab affecting all versions starting from 15.7 before 15.8.5, from 15.9 before 15.9.4, and from 15.10 before 15.10.1 that allows for crafted, unapproved MRs to be introduced and merged without authorization | |
| Modificada | Crítica (9.8) | 3.6% | — | Git-commit-info Project Git-commit-info | 28/6/2023 | 17/6/2026 | Versions of the package git-commit-info before 2.0.2 are vulnerable to Command Injection such that the package-exported method gitCommitInfo () fails to sanitize its parameter commit, which later flows into a sensitive command execution API. As a result, attackers may inject malicious commands once they control the… | |
| Modificada | Alta (8.8) | 0.26% | — | Digitalinspiration Google XML Sitemap FOR Videos | 15/6/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Videos plugin <= 2.6.1 versions. | |
| Analizada | Media (6.1) | 0.45% | — | Liferay Digital Experience PlatformLiferay Portal | 15/6/2023 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.73, and Liferay DXP 7.4 update 70 through 73 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL` parameter. | |
| Modificada | Crítica (9.8) | 1.5% | — | HP Laserjet Managed MFP E62665 3gy14a FirmwareHP Laserjet Managed MFP E62665 3gy15a FirmwareHP Laserjet Managed MFP E62665 3gy16a FirmwareHP Laserjet Managed MFP E62665 3gy17a Firmware+953 | 14/6/2023 | 17/6/2026 | A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Buffer Overflow and/or Remote Code Execution when running HP Workpath solutions on potentially affected products. | |
| Modificada | Media (6.5) | 0.66% | — | Jenkins Digital.ai APP Management Publisher | 14/6/2023 | 17/6/2026 | Una verificación de permiso faltante en Jenkins Digital.ai App Management Publisher Plugin 2.6 y versiones anteriores permite a los atacantes con permiso general/de lectura conectarse a una URL especificada por el atacante y capturar las credenciales almacenadas en Jenkins. | |
| Modificada | Media (6.5) | 0.45% | — | Jenkins Digital.ai APP Management Publisher | 14/6/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers to connect to an attacker-specified URL, capturing credentials stored in Jenkins. | |
| Modificada | Media (5.4) | 1.4% | 💥 Exploit | Digitaldruid Hoteldruid | 13/6/2023 | 17/6/2026 | A Reflected XSS was discovered in HotelDruid version 3.0.5, an attacker can issue malicious code/command on affected webpage's parameter to trick user on browser and/or exfiltrate data. | |
| Modificada | Alta (8.8) | 1.5% | 💥 PoC | Digitaldruid Hoteldruid | 13/6/2023 | 17/6/2026 | hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability. | |
| Modificada | Media (5.7) | 0.29% | — | SAP Digital ManufacturingSAP Plant Connectivity | 13/6/2023 | 17/6/2026 | SAP Plant Connectivity - version 15.5 (PCo) or the Production Connector for SAP Digital Manufacturing - version 1.0, do not validate the signature of the JSON Web Token (JWT) in the HTTP request sent from SAP Digital Manufacturing. Therefore, unauthorized callers from the internal network could send service requests… | |
| Modificada | Alta (7.5) | 0.59% | — | Westerndigital MY Cloud Pr2100 FirmwareWesterndigital MY Cloud Pr4100 FirmwareWesterndigital MY Cloud Ex4100 FirmwareWesterndigital MY Cloud EX2 Ultra Firmware+8 | 12/6/2023 | 17/6/2026 | Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data. This issue affects My Cloud OS 5 devices: before 5.25.132; My Cloud Home and My Cloud Home Duo: before 8.13.1-102;… | |
| Modificada | Alta (7.5) | 0.76% | — | Git-url-parse Project Git-url-parse | 12/6/2023 | 17/6/2026 | The git-url-parse crate through 0.4.4 for Rust allows Regular Expression Denial of Service (ReDos) via a crafted URL to normalize_url in lib.rs, a similar issue to CVE-2023-32758 (Python). | |
| Modificada | Media (5.3) | 0.39% | — | Gitlab | 7/6/2023 | 17/6/2026 | Se ha descubierto un problema en GitLab EE que afecta a todas las versiones a partir de la 12.0 hasta la 15.10.8, a todas las versiones a partir de la 15.11 hasta la 15.11.7 y a todas las versiones a partir de la 16.0 hasta la 16.0.2. Un atacante puede clonar un repositorio de un proyecto público, desde una dirección… | |
| Analizada | Media (4.9) | 0.82% | — | Gitlab | 7/6/2023 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A malicious maintainer in a project can escalate other users to Owners in that project if they import members from… | |
| Modificada | Alta (7.5) | 1.3% | — | Gitlab | 7/6/2023 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint. | |
| Modificada | Alta (7.5) | 1.3% | — | Gitlab | 7/6/2023 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint. |