Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2766▼ 23 respecto a la semana anterior
Críticas / altas1275▼ 257 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)241▲ 204 respecto a la semana anterior
3702 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.43% | — | Gitlab | 3/5/2023 | 17/6/2026 | An issue has been discovered in GitLab EE affecting all versions starting from 14.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Lack of verification on RelayState parameter allowed a maliciously crafted URL to obtain access tokens granted for 3rd… | |
| Modificada | Media (5.4) | 0.75% | — | Gitlab | 3/5/2023 | 17/6/2026 | A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. When viewing an XML file in a repository in "raw" mode, it can be made to render as HTML if viewed under… | |
| Modificada | Media (4.5) | 0.78% | — | Gitlab | 3/5/2023 | 17/6/2026 | An issue has been discovered in GitLab affecting all versions starting from 11.9 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The condition allows for a privileged attacker, under certain conditions, to obtain session tokens from all users of a GitLab… | |
| Modificada | Media (4.3) | 0.51% | — | Gitlab | 3/5/2023 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A user could use an unverified email as a public email and commit email by sending a specifically crafted request on… | |
| Modificada | Media (6.5) | 0.96% | — | Gitlab | 3/5/2023 | 17/6/2026 | An issue has been discovered in GitLab affecting all versions starting from 13.11 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible that a project member demoted to a user role to read project updates by doing a diff with a pre-existing fork. | |
| Modificada | Media (5.4) | 0.77% | — | Gitlab | 3/5/2023 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions before 15.8.5, 15.9.4, 15.10.1. Open redirects was possible due to framing arbitrary content on any page allowing user controlled markdown | |
| Modificada | Media (5.4) | 0.66% | 💥 PoC | Digitaldruid Hoteldruid | 3/5/2023 | 17/6/2026 | A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, which allows arbitrary execution of commands. The vulnerable fields are Surname, Name, and Nickname in the Document function. | |
| Modificada | Alta (7.5) | 14% | — | Aigital Wireless-n Repeater Mini Router Firmware | 2/5/2023 | 17/6/2026 | An issue in the time-based authentication mechanism of Aigital Aigital Wireless-N Repeater Mini_Router v0.131229 allows attackers to bypass login by connecting to the web app after a successful attempt by a legitimate user. | |
| Modificada | Crítica (9.8) | 3.1% | 💥 Exploit | Awesomemotive Easy Digital Downloads | 2/5/2023 | 17/6/2026 | Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue affects Easy Digital Downloads: from 3.1 through 3.1.1.4.1. | |
| Modificada | Media (5.9) | 0.65% | — | Gitlab\ \ | 29/4/2023 | 17/6/2026 | GitLab::API::v4 through 0.26 does not verify TLS certificates when connecting to a GitLab server, enabling machine-in-the-middle attacks. | |
| Modificada | Media (5.4) | 29% | — | Aigital Wireless-n Repeater Mini Router Firmware | 28/4/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Aigital Wireless-N Repeater Mini_Router v0.131229 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the wl_ssid parameter at /boafrm/formHomeWlanSetup. | |
| Modificada | Crítica (9.8) | 2.2% | — | Aigital Wireless-n Repeater Mini Router Firmware | 26/4/2023 | 9/7/2026 | Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a remote code execution (RCE) vulnerability via the sysCmd parameter in the formSysCmd function. This vulnerability is exploited via a crafted HTTP request. | |
| Modificada | Alta (7.8) | 0.38% | — | GIT FOR Windows Project GIT FOR Windows | 25/4/2023 | 17/6/2026 | Git for Windows is the Windows port of Git. Prior to version 2.40.1, any user of Git CMD who starts the command in an untrusted directory is impacted by an Uncontrolles Search Path Element vulnerability. Maliciously-placed `doskey.exe` would be executed silently upon running Git CMD. The problem has been patched in… | |
| Modificada | Alta (7.8) | 0.38% | — | GIT FOR Windows Project GIT FOR Windows | 25/4/2023 | 17/6/2026 | Git for Windows, the Windows port of Git, ships with an executable called `connect.exe`, which implements a SOCKS5 proxy that can be used to connect e.g. to SSH servers via proxies when certain ports are blocked for outgoing connections. The location of `connect.exe`'s config file is hard-coded as `/etc/connectrc`… | |
| Modificada | Alta (7.8) | 6.1% | 💥 PoC | Git-scm GITFedoraproject Fedora | 25/4/2023 | 17/6/2026 | Git es un sistema de control de revisiones. Antes de las versiones 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3 y 2.40.1, una versión especialmente El archivo `.gitmodules` elaborado con URL de submódulo que tienen más de 1024 caracteres se puede usar para explotar un error en… | |
| Modificada | Baja (2.2) | 0.96% | — | GIT FOR Windows Project GIT FOR WindowsFedoraproject Fedora | 25/4/2023 | 17/6/2026 | En Git para Windows, la versión de Git para Windows, no se envían mensajes localizados con el instalador. Como consecuencia, se espera que Git no localice ningún mensaje y omita la inicialización de gettext. Sin embargo, debido a un cambio en los paquetes MINGW, la inicialización implícita de la función `gettext()` ya… | |
| Modificada | Alta (7.5) | 52% | — | Git-scm GITFedoraproject Fedora | 25/4/2023 | 17/6/2026 | Git es un sistema de control de revisiones. Antes de las versiones 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3 y 2.40.1, mediante alimentación entrada especialmente manipulada para `git apply --reject`, una ruta fuera del árbol de trabajo se puede sobrescribir con contenidos… | |
| Modificada | Media (4.8) | 0.37% | — | Digitalblue Click TO Call OR Chat Buttons | 25/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in DIGITALBLUE Click to Call or Chat Buttons plugin <= 1.4.0 versions. | |
| Modificada | Media (6.5) | 1.6% | — | Gitlab | 16/4/2023 | 17/6/2026 | An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Gitaly allows injection of command-line flags. This sometimes leads to privilege escalation or remote code execution. | |
| Modificada | Media (5.9) | 0.46% | — | Gitlab | 16/4/2023 | 17/6/2026 | An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Cookies for GitLab Pages (which have access control) could be sent over cleartext HTTP. | |
| Modificada | Media (5.4) | 0.40% | — | Gitlab | 16/4/2023 | 17/6/2026 | An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. blog-viewer has stored XSS during repository browsing, if package.json exists. . | |
| Modificada | Media (5.4) | 0.40% | — | Gitlab | 15/4/2023 | 17/6/2026 | An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the merge request page via project import. | |
| Modificada | Alta (7.5) | 0.62% | — | Gitlab | 15/4/2023 | 17/6/2026 | An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers could obtain sensitive information about group names, avatars, LDAP settings, and descriptions via an insecure direct object reference to the "merge request approvals" feature. | |
| Modificada | Media (5.4) | 0.40% | — | Gitlab | 15/4/2023 | 17/6/2026 | An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the issue details screen. | |
| Modificada | Media (5.3) | 0.52% | — | Gitlab | 15/4/2023 | 17/6/2026 | An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers may have been able to obtain sensitive access-token data from Sentry logs via the GRPC::Unknown exception. |