Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2565▼ 302 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
259 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.5% | — | Github Enterprise Server | 14/12/2022 | 17/6/2026 | An improper limitation of a pathname to a restricted directory vulnerability was identified in GitHub Enterprise Server that enabled remote code execution. A check was added within Pages to ensure the working directory is clean before unpacking new content to prevent an arbitrary file overwrite bug. This vulnerability… | |
| Modificada | Media (6.5) | 0.74% | — | Github Enterprise Server | 1/12/2022 | 17/6/2026 | An improper privilege management vulnerability was identified in GitHub Enterprise Server that allowed users with improper privileges to create or delete pages via the API. To exploit this vulnerability, an attacker would need to be added to an organization's repo with write permissions. This vulnerability affected… | |
| Modificada | Alta (8.8) | 1.2% | — | Github Enterprise Server | 23/11/2022 | 17/6/2026 | CRITICAL: An improper neutralization of argument delimiters in a command vulnerability was identified in GitHub Enterprise Server that enabled remote code execution. To exploit this vulnerability, an attacker would need permission to create and build GitHub Pages using GitHub Actions. This vulnerability affected only… | |
| Modificada | Media (5.7) | 0.68% | — | Github Enterprise Server | 1/11/2022 | 17/6/2026 | An improper cache key vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to access private repository files through a public repository. To exploit this, an actor would need to already be authorized on the GitHub Enterprise Server instance, be able to create a public… | |
| Modificada | Alta (8.8) | 1.3% | — | Kartverket Github-workflows | 25/10/2022 | 17/6/2026 | kartverket/github-workflows are shared reusable workflows for GitHub Actions. Prior to version 2.7.5, all users of the `run-terraform` reusable workflow from the kartverket/github-workflows repo are affected by a code injection vulnerability. A malicious actor could potentially send a PR with a malicious payload… | |
| Modificada | Crítica (9.9) | 1.6% | — | Github Runner | 25/10/2022 | 17/6/2026 | GitHub Actions Runner is the application that runs a job from a GitHub Actions workflow. The actions runner invokes the docker cli directly in order to run job containers, service containers, or container actions. A bug in the logic for how the environment is encoded into these docker commands was discovered in… | |
| Modificada | Alta (8.8) | 2.1% | — | Github Enterprise Server | 19/10/2022 | 17/6/2026 | A deserialization of untrusted data vulnerability was identified in GitHub Enterprise Server that could potentially lead to remote code execution on the SVNBridge. To exploit this vulnerability, an attacker would need to gain access via a server-side request forgery (SSRF) that would let an attacker control the data… | |
| Modificada | Media (6.5) | 2.2% | — | Github Cmark-gfmFedoraproject Fedora | 15/9/2022 | 17/6/2026 | cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0.29.0.gfm.6 a polynomial time complexity issue in cmark-gfm's autolink extension may lead to unbounded resource exhaustion and subsequent denial of service. Users may verify the patch by running… | |
| Modificada | Media (5) | 0.67% | — | Github Toolkit | 15/8/2022 | 17/6/2026 | The GitHub Actions ToolKit provides a set of packages to make creating actions easier. The `core.exportVariable` function uses a well known delimiter that attackers can use to break out of that specific variable and assign values to other arbitrary variables. Workflows that write untrusted values to the `GITHUB_ENV`… | |
| Modificada | Media (5.4) | 0.60% | — | Github Enterprise Server | 2/8/2022 | 17/6/2026 | A stored XSS vulnerability was identified in GitHub Enterprise Server that allowed the injection of arbitrary attributes. This injection was blocked by Github's Content Security Policy (CSP). This vulnerability affected all versions of GitHub Enterprise Server prior to 3.6 and was fixed in versions 3.3.11, 3.4.6 and… | |
| Modificada | Media (5.3) | 0.90% | — | Jenkins Github | 27/7/2022 | 17/6/2026 | Jenkins GitHub Plugin 1.34.4 and earlier uses a non-constant time comparison function when checking whether the provided and computed webhook signatures are equal, allowing attackers to use statistical methods to obtain a valid webhook signature. | |
| Modificada | Media (6.5) | 0.49% | — | Fastify Github Action Merge Dependabot | 31/5/2022 | 17/6/2026 | github-action-merge-dependabot is an action that automatically approves and merges dependabot pull requests (PRs). Prior to version 3.2.0, github-action-merge-dependabot does not check if a commit created by dependabot is verified with the proper GPG key. There is just a check if the actor is set to `dependabot[bot]`… | |
| Modificada | Alta (8.8) | 1.7% | — | Github Enterprise Server | 5/4/2022 | 17/6/2026 | A path traversal vulnerability was identified in GitHub Enterprise Server management console that allowed the bypass of CSRF protections. This could potentially lead to privilege escalation. To exploit this vulnerability, an attacker would need to target a user that was actively logged into the management console.… | |
| Modificada | Media (6.1) | 0.70% | — | Enhanced-github Project Enhanced-github | 22/3/2022 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerabililty exists in enhanced-github v5.0.11 via the file name parameter. | |
| Modificada | Crítica (9.8) | 4.5% | — | Github Cmark-gfmFedoraproject Fedora | 3/3/2022 | 17/6/2026 | cmark-gfm is GitHub's extended version of the C reference implementation of CommonMark. Prior to versions 0.29.0.gfm.3 and 0.28.3.gfm.21, an integer overflow in cmark-gfm's table row parsing `table.c:row_from_string` may lead to heap memory corruption when parsing tables who's marker rows contain more than UINT16_MAX… | |
| Modificada | Media (6.1) | 1.1% | — | Github Viewcomponent | 2/3/2022 | 17/6/2026 | VIewComponent is a framework for building view components in Ruby on Rails. Versions prior to 2.31.2 and 2.49.1 contain a cross-site scripting vulnerability that has the potential to impact anyone using translations with the view_component gem. Data received via user input and passed as an interpolation argument to… | |
| Modificada | Alta (8.8) | 2.2% | — | Github Enterprise Server | 18/2/2022 | 17/6/2026 | A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected all… | |
| Modificada | Media (6.5) | 1.0% | — | Github Gh-ost | 1/2/2022 | 17/6/2026 | gh-ost is a triggerless online schema migration solution for MySQL. Versions prior to 1.1.3 are subject to an arbitrary file read vulnerability. The attacker must have access to the target host or trick an administrator into executing a malicious gh-ost command on a host running gh-ost, plus network access from host… | |
| Modificada | Alta (8.8) | 1.2% | — | Github Enterprise Server | 25/1/2022 | 17/6/2026 | A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be granted during a GitHub App's user-authorization web flow than was displayed to the user during approval. To exploit this vulnerability, an attacker would need to create a GitHub App on the instance and… | |
| Modificada | Media (6.1) | 0.63% | — | Github Readme Stats Project Github Readme Stats | 6/1/2022 | 17/6/2026 | Github Read Me Stats commit 3c7220e4f7144f6cb068fd433c774f6db47ccb95 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the function renderError. | |
| Modificada | Crítica (9.8) | 2.6% | — | Github-todos Project Github-todos | 7/12/2021 | 17/6/2026 | naholyr github-todos 3.1.0 is vulnerable to command injection. The range argument for the _hook subcommand is concatenated without any validation, and is directly used by the exec function. | |
| Modificada | Media (6.5) | 1.1% | — | Github Enterprise Server | 10/11/2021 | 17/6/2026 | A path traversal vulnerability was identified in GitHub Pages builds on GitHub Enterprise Server that could allow an attacker to read system files. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability… | |
| Modificada | Crítica (9.8) | 1.2% | — | Github Enterprise Server | 24/9/2021 | 17/6/2026 | An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted runner group it should not have had access to. This affects customers using self-hosted runner groups for access control. A repository with access to one enterprise runner group could access all of… | |
| Modificada | Media (4.3) | 0.93% | — | Github Enterprise Server | 24/9/2021 | 17/6/2026 | A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it possible to read files on the GitHub Enterprise Server instance. To exploit this… | |
| Modificada | Media (6.5) | 1.2% | — | Github Enterprise Server | 14/7/2021 | 17/6/2026 | A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it possible to read files on the GitHub Enterprise Server instance. To exploit this… |