Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2759▲ 5 respecto a la semana anterior
Críticas / altas1275▼ 253 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)242▲ 224 respecto a la semana anterior
3702 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.80% | — | Gitlab Dynamic Application Security Testing Analyzer | 27/3/2023 | 17/6/2026 | An issue has been discovered in GitLab DAST API scanner affecting all versions starting from 1.6.50 before 2.11.0, where Authorization headers was leaked in vulnerability report evidence. | |
| Modificada | Alta (7.4) | 0.31% | — | Westerndigital Sandisk Privateaccess | 24/3/2023 | 17/6/2026 | SanDisk PrivateAccess versions prior to 6.4.9 support insecure TLS 1.0 and TLS 1.1 protocols which are susceptible to man-in-the-middle attacks thereby compromising confidentiality and integrity of data. | |
| Modificada | Alta (8.8) | 1.6% | — | Github-slug-action Project Github-slug-action | 13/3/2023 | 17/6/2026 | github-slug-action is a GitHub Action to expose slug value of GitHub environment variables inside of one's GitHub workflow. Starting in version 4.0.0` and prior to version 4.4.1, this action uses the `github.head_ref` parameter in an insecure way. This vulnerability can be triggered by any user on GitHub on any… | |
| Modificada | Crítica (9.8) | 0.72% | — | Ibexa Digital Experience PlatformIbexa Ezplatform-http-cache-fastlyIbexa FastlyIbexa EZ Platform Kernel+1 | 12/3/2023 | 17/6/2026 | An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled. | |
| Modificada | Baja (3.7) | 0.46% | — | Ibexa CommerceIbexa Digital Experience PlatformIbexa EZ PlatformIbexa Ezplatform-page-builder+3 | 12/3/2023 | 17/6/2026 | An issue was discovered in eZ Platform Ibexa Kernel before 1.3.19. It allows determining account existence via a timing attack. | |
| Modificada | Alta (7.2) | 0.86% | — | Ibexa Digital Experience PlatformIbexa EZ PlatformIbexa EZ Platform Kernel | 12/3/2023 | 17/6/2026 | An issue was discovered in eZ Platform Ibexa Kernel before 1.3.26. The Company admin role gives excessive privileges. | |
| Modificada | Media (6.5) | 0.75% | — | Gitlab Dynamic Application Security Testing Analyzer | 9/3/2023 | 17/6/2026 | Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host. | |
| Modificada | Media (5.4) | 0.58% | — | Gitlab | 9/3/2023 | 17/6/2026 | An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. Due to improper permissions checks an unauthorised user was able to read, add or edit a users private snippet. | |
| Modificada | Media (5.3) | 0.79% | — | Gitlab | 9/3/2023 | 17/6/2026 | An issue has been discovered in GitLab affecting all versions starting from 9.0 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible to trigger a resource depletion attack due to improper filtering for number of requests to read commits details. | |
| Modificada | Media (5.4) | 92% | — | Gitlab | 9/3/2023 | 17/6/2026 | An issue has been discovered in GitLab affecting all versions starting from 13.7 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A specially crafted Kroki diagram could lead to a stored XSS on the client side which allows attackers to perform arbitrary… | |
| Modificada | Alta (7.3) | 0.74% | — | Gitlab | 9/3/2023 | 17/6/2026 | An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. If a group with SAML SSO enabled is transferred to a new namespace as a child group, it's possible previously removed… | |
| Modificada | Media (5.3) | 0.79% | — | Gitlab | 9/3/2023 | 17/6/2026 | An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. Non-project members could retrieve release descriptions via the API, even if the release visibility is restricted to project… | |
| Modificada | Media (4.3) | 0.69% | — | Gitlab | 9/3/2023 | 17/6/2026 | An issue has been discovered in GitLab affecting all versions starting from 15.3 before 15.7.8, versions of 15.8 before 15.8.4, and version 15.9 before 15.9.2. Google IAP details in Prometheus integration were not hidden, could be leaked from instance, group, or project settings to other users. | |
| Modificada | Media (6.1) | 0.61% | — | Gitlab | 9/3/2023 | 17/6/2026 | An issue has been discovered in GitLab affecting all versions starting from 10.0 to 15.7.8, 15.8 prior to 15.8.4 and 15.9 prior to 15.9.2. A crafted URL could be used to redirect users to arbitrary sites | |
| Modificada | Baja (2.7) | 0.81% | — | Gitlab | 9/3/2023 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A malicious project Maintainer may create a Project Access Token with Owner level privileges using a crafted request. | |
| Modificada | Baja (3.8) | 0.56% | — | Gitlab | 9/3/2023 | 17/6/2026 | An issue has been discovered in GitLab affecting all versions starting from 12.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible for a project maintainer to extract a Datadog integration API key by modifying the site. | |
| Modificada | Media (4.3) | 0.66% | — | Gitlab | 9/3/2023 | 17/6/2026 | An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. This vulnerability could allow a user to unmask the Discord Webhook URL through viewing the raw API response. | |
| Modificada | Media (6.1) | 0.54% | — | Gitlab Dynamic Application Security Testing Analyzer | 9/3/2023 | 17/6/2026 | An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 1.47 before 3.0.51, which sends custom request headers in redirects. | |
| Modificada | Media (6.5) | 0.80% | — | Gitlab Dynamic Application Security Testing Analyzer | 8/3/2023 | 17/6/2026 | An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 2.0 before 3.0.55, which sends custom request headers with every request on the authentication page. | |
| Modificada | Media (6.1) | 0.56% | — | Gitlab | 8/3/2023 | 17/6/2026 | A issue has been discovered in GitLab CE/EE affecting all versions from 15.3 prior to 15.7.8, version 15.8 prior to 15.8.4, and version 15.9 prior to 15.9.2 A cross-site scripting vulnerability was found in the title field of work items that allowed attackers to perform arbitrary actions on behalf of victims at client… | |
| Modificada | Alta (8.8) | 1.0% | — | Github Enterprise Server | 8/3/2023 | 17/6/2026 | A path traversal vulnerability was identified in GitHub Enterprise Server that allowed remote code execution when building a GitHub Pages site. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected… | |
| Modificada | Media (4.3) | 0.57% | — | Github Enterprise Server | 7/3/2023 | 17/6/2026 | An information disclosure vulnerability was identified in GitHub Enterprise Server that allowed private repositories to be added to a GitHub Actions runner group via the API by a user who did not have access to those repositories, resulting in the repository names being shown in the UI. To exploit this vulnerability,… | |
| Modificada | Crítica (9.6) | 0.41% | — | Gitpod | 3/3/2023 | 17/6/2026 | An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to the Gitpod JSONRPC server using a victim’s credentials, because the Origin header is not restricted. This can lead to the… | |
| Modificada | Media (6.1) | 0.37% | — | Asosegitim Bookcites | 3/3/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ASOS Information Technologies Book Cites allows Cross-Site Scripting (XSS). This issue affects Book Cites: before 23.01.05. | |
| Modificada | Media (6.1) | 0.37% | — | Asosegitim Sobiad | 3/3/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ASOS Information Technologies SOBIAD allows Cross-Site Scripting (XSS). This issue affects SOBIAD: before 23.02.01. |