Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 306 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

37 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.34%—Charm Soft ServeAI15/9/202616/9/2026
Soft Serve versions 0.7.1 through 0.11.6 fail to scope Git LFS lock queries by repository, allowing authenticated users to read lock metadata from repositories they cannot access. Attackers with write access to any repository can enumerate lock IDs globally to recover locked file paths, usernames, and lock timestamps…
AnalizadaAlta (8.4)0.18%—Jetbrains Pycharm17/8/202610/9/2026
In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools
AnalizadaMedia (4.4)0.18%—Jetbrains Pycharm17/8/202610/9/2026
In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible
AnalizadaAlta (8.6)0.18%—Jetbrains Pycharm23/7/20263/8/2026
In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open
AnalizadaMedia (6.1)0.25%—Jetbrains Pycharm29/5/202622/7/2026
In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible
AnalizadaCrítica (9.6)0.51%—Charm Wish7/5/202617/6/2026
Wish is an SSH server with defaults and a collection of middlewares. From version 2.0.0 to before version 2.0.1, the SCP middleware in charm.land/wish/v2 is vulnerable to path traversal attacks. A malicious SCP client can read arbitrary files from the server, write arbitrary files to the server, and create directories…
AnalizadaAlta (7.1)0.41%—Charm Soft Serve24/3/202617/6/2026
Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authorization flaw in repo import allows any authenticated SSH user to clone a server-local Git repository, including another user's private repo, into a new repository they control. This issue has been…
AnalizadaCrítica (9.1)0.39%—Charm Soft Serve7/3/202617/6/2026
Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.4, an authenticated SSH user can force the server to make HTTP requests to internal/private IP addresses by running repo import with a crafted --lfs-endpoint URL. The initial batch request is blind (the response…
AnalizadaMedia (6.1)0.26%—Jetbrains Pycharm9/2/202617/6/2026
In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible
AnalizadaAlta (8.1)0.59%—Charm Soft Serve22/1/202617/6/2026
Soft Serve is a self-hostable Git server for the command line. Versions 0.11.2 and below have a critical authentication bypass vulnerability that allows an attacker to impersonate any user (including admin) by "offering" the victim's public key during the SSH handshake before authenticating with their own valid key.…
AnalizadaMedia (5.4)0.31%—Charm Soft Serve8/1/202617/6/2026
Soft Serve is a self-hostable Git server for the command line. Prior to version 0.11.2, an authorization bypass in the LFS lock deletion endpoint allows any authenticated user with repository write access to delete locks owned by other users by setting the force flag. The vulnerable code path processes force deletions…
AnalizadaAlta (7.6)0.34%—Charm Soft Serve10/11/202517/6/2026
Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where webhook URLs are not validated, allowing repository administrators to create webhooks targeting internal services, private networks, and cloud metadata endpoints. Version 0.11.1 fixes the…
AplazadaMedia (4.6)0.18%—Charm Soft ServeAI8/11/202517/6/2026
Soft Serve is a self-hostable Git server for the command line. In versions prior to 0.10.0, there are several places where the user can insert data (e.g. names) and ANSI escape sequences are not being removed, which can then be used, for example, to show fake alerts. In the same token, git messages, when printed, are…
AplazadaAlta (7.7)0.35%—Charm Soft ServeAI4/9/202517/6/2026
Soft Serve is a self-hostable Git server for the command line. In versions 0.9.1 and below, attackers can create or override arbitrary files with uncontrolled data through its SSH API. This issue is fixed in version 0.10.0.
AplazadaMedia (5.4)0.29%—Pythoncharmers Python-futureAI14/8/202517/6/2026
A vulnerability in the Python-Future 1.0.0 module allows for arbitrary code execution via the unintended import of a file named test.py. When the module is loaded, it automatically imports test.py, if present in the same directory or in the sys.path. This behavior can be exploited by an attacker who has the ability to…
AplazadaAlta (8.8)0.34%—Anthropic Claude CodeAIMicrosoft VscodeAIJetbrains IntellijAIJetbrains PycharmAI+124/6/202517/6/2026
Claude Code is an agentic coding tool. Claude Code extensions in VSCode and forks (e.g., Cursor, Windsurf, and VSCodium) and JetBrains IDEs (e.g., IntelliJ, Pycharm, and Android Studio) are vulnerable to unauthorized websocket connections from an attacker when visiting attacker-controlled webpages. Claude Code for…
AplazadaMedia (5)0.17%—Canonical Charmed Mysql K8S OperatorAI9/4/202517/6/2026
Charmed MySQL K8s operator is a Charmed Operator for running MySQL on Kubernetes. Before revision 221, the method for calling a SQL DDL or python based mysql-shell scripts can leak database users credentials. The method mysql-operator calls mysql-shell application rely on writing to a temporary script file containing…
AnalizadaMedia (5.3)0.68%—Charm Soft Serve8/1/202517/6/2026
Soft Serve is a self-hostable Git server for the command line. Prior to 0.8.2 , a path traversal attack allows existing non-admin users to access and take over other user's repositories. A malicious user then can modify, delete, and arbitrarily repositories as if they were an admin user without explicitly giving them…
ModificadaAlta (7.1)0.42%—Kmfoysal06 Simplecharm7/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kmfoysal06 SimpleCharm simplecharm allows Reflected XSS.This issue affects SimpleCharm: from n/a through <= 1.4.3.
AplazadaAlta (8.1)0.51%—Charm Soft ServeAI1/8/202417/6/2026
Soft Serve is a self-hostable Git server for the command line. Prior to 0.7.5, it is possible for a user who can commit files to a repository hosted by Soft Serve to execute arbitrary code via environment manipulation and Git. The issue is that Soft Serve passes all environment variables given by the client to git…
ModificadaAlta (7.5)3.8%—Jetbrains AquaJetbrains ClionJetbrains DatagripJetbrains Dataspell+910/6/202417/6/2026
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell…
ModificadaAlta (7.5)1.2%—Charm Soft Serve4/10/202317/6/2026
Soft Serve is a self-hostable Git server for the command line. Prior to version 0.6.2, a security vulnerability in Soft Serve could allow an unauthenticated, remote attacker to bypass public key authentication when keyboard-interactive SSH authentication is active, through the `allow-keyless` setting, and the public…
ModificadaAlta (7.5)1.9%—Pythoncharmers Python-future23/12/202217/6/2026
An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server.
ModificadaMedia (5.5)0.19%—Samsung Charm Firmware5/8/202217/6/2026
Unprotected provider vulnerability in Charm by Samsung prior to version 1.2.3 allows attackers to read connection state without permission.
ModificadaMedia (5.5)0.18%—Samsung Charm Firmware5/8/202217/6/2026
PendingIntent hijacking vulnerability in cancelAlarmManager in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent.