Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2523▼ 417 respecto a la semana anterior
Críticas / altas1297▲ 13 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)60▼ 468 respecto a la semana anterior
3658 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.39% | — | Gitlab | 29/7/2026 | 3/8/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with guest-role permissions to access test report contents they were not authorized to view due to improper… | |
| Analizada | Media (4.7) | 0.29% | — | Gitlab | 29/7/2026 | 3/8/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an attacker to execute arbitrary JavaScript in another user's browser via a crafted URL, due to improper sanitization of… | |
| Analizada | Media (5.4) | 0.32% | — | Gitlab | 29/7/2026 | 3/8/2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed some sensitive information to be disclosed to an unintended host due to improper handling of upstream requests in virtual registries. | |
| Analizada | Alta (7.5) | 0.51% | — | Gitlab | 29/7/2026 | 3/8/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to insufficient resource throttling when processing merge request… | |
| Analizada | Media (4.3) | 0.30% | — | Gitlab | 29/7/2026 | 3/8/2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to bypass administrator-configured tool governance policies due to improper authorization enforcement during token generation. | |
| Analizada | Media (4.3) | 0.31% | — | Gitlab | 29/7/2026 | 3/8/2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to access information from unauthorized projects due to improper neutralization of untrusted content processed by the AI-assisted code… | |
| Analizada | Media (4.3) | 0.40% | — | Gitlab | 29/7/2026 | 3/8/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to view the title of a confidential issue through a publicly accessible merge request due to improper… | |
| Analizada | Media (4.9) | 0.53% | — | Gitlab | 29/7/2026 | 3/8/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Maintainer role to modify protected branch configuration due to improper authorization in a projects API… | |
| Analizada | Media (5.3) | 0.26% | — | Gitlab | 29/7/2026 | 3/8/2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to merge code into a protected branch without the required approvals due to a race condition in approval rule… | |
| Analizada | Alta (8.4) | 0.46% | — | Gitlab | 29/7/2026 | 3/8/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to modify CI/CD configuration belonging to another user due to improper validation of user-supplied attributes… | |
| Analizada | Baja (3.1) | 0.28% | — | Gitlab | 29/7/2026 | 29/9/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to commit changes to a project after being removed as a member, due to… | |
| Aplazada | Alta (7.2) | 1.2% | — | Easydigitaldownloads Easy Digital DownloadsAI | 29/7/2026 | 30/7/2026 | The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3.6.9. This is due to insufficient file type validation in the edd_do_ajax_import_file_upload() function , which only checks the client-supplied $_FILES['edd-import-file']['type'] Content-Type header… | |
| Analizada | Alta (7.5) | 0.77% | — | Github MCP Server | 28/7/2026 | 8/8/2026 | GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.go accesses params.Ref without first checking whether it is nil, so a completion/complete request with a missing or empty ref field triggers a nil pointer dereference and a Go runtime panic; because… | |
| Aplazada | Media (6.1) | 0.25% | — | Thewp Digital Solutions News ThemeAI | 28/7/2026 | 28/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in THEWP Digital Solutions News Theme V8 allows Reflected XSS. This issue affects News Theme V8: through 16.06.2026. | |
| Aplazada | Media (4.9) | 0.50% | — | Easydigitaldownloads Easy Digital DownloadsAI | 27/7/2026 | 27/7/2026 | Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions. | |
| Aplazada | Alta (8.5) | 0.48% | — | Github ActionsAICal.comAI | 23/7/2026 | 1/10/2026 | cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_request_target trigger with the repository's default write permissions and passes them down to check-types.yml. check-types.yml then performs a… | |
| Aplazada | Media (6.5) | 0.42% | — | Easydigitaldownloads Easy Digital DownloadsAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions. | |
| Aplazada | Media (6.5) | 0.47% | — | Premium Packages Sell Digital Products SecurelyAI | 23/7/2026 | 23/7/2026 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes… | |
| Aplazada | Media (6.4) | 0.42% | — | Equalize Digital Accessibility CheckerAI | 23/7/2026 | 23/7/2026 | The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'html' parameter in all versions up to, and including, 1.46.0 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Pendiente de análisis | Alta (8.1) | 0.21% | — | GitleaksAI | 21/7/2026 | 22/7/2026 | Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report templates to read arbitrary environment variables and exfiltrate sensitive data by leveraging non-hermetic Sprig template functions. Attackers can craft malicious report templates using the… | |
| Aplazada | Media (5.3) | 0.45% | — | Github Enterprise ServerAI | 17/7/2026 | 17/7/2026 | A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with write access to any repository to read metadata from private repositories they did not have access to, including private repository owners and names, branch names, commit SHAs, commit messages, and… | |
| Aplazada | Alta (8.6) | 0.75% | — | Github Enterprise ServerAI | 17/7/2026 | 17/7/2026 | A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write files to arbitrary repository paths, including GitHub Actions workflow files under .github/workflows/ as the path validation did not check the… | |
| Aplazada | Media (5.7) | 0.64% | — | Github Enterprise ServerAI | 17/7/2026 | 17/7/2026 | A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository release notes configuration file containing deeply nested YAML. When release notes were generated, the configuration file was parsed without a nesting… | |
| Aplazada | Alta (8.8) | 0.44% | — | Unitedover DigitsAI | 16/7/2026 | 16/7/2026 | The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.1.0.5. This is due to missing authorization and role validation in the `dig_update_wpwc_custom_fields()` function. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (8.8) | 0.46% | — | Github ActionsAIMaaassistantarknightsAI | 15/7/2026 | 12/8/2026 | MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/release-preparation.yml inlined attacker-controlled github.event.pull_request.title into a run: shell command during the pull_request opened, reopened, and ready_for_review events, so a non-draft fork… |