Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2534▼ 410 respecto a la semana anterior
Críticas / altas1307▲ 25 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.40% | — | Dradis Community EditionAI | 25/8/2026 | 24/9/2026 | In Dradis Community Edition, the ProvidersController and AgentsController gate their admin_required before_action on `defined?(Dradis::Pro)`, a constant that is never defined in CE, so the authorization check is never applied. As a result, any authenticated (non-admin) user can create an AI provider pointing to an… | |
| Analizada | Media (4.3) | 0.20% | — | Dradisframework Dradis | 10/7/2025 | 17/6/2026 | In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs. | |
| Analizada | Media (4.3) | 0.26% | — | Dradisframework Dradis | 5/7/2025 | 17/6/2026 | Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images. This can be leveraged by an authorized author to attempt to steal the Net-NTLM hashes of other authors on a Windows domain network. | |
| Modificada | Media (5.4) | 0.51% | — | Dradisframework Dradis | 25/4/2023 | 17/6/2026 | Dradis before 4.8.0 allows persistent XSS by authenticated author users, related to avatars. | |
| Modificada | Media (5.9) | 0.52% | — | Dradisframework Dradis | 24/6/2022 | 17/6/2026 | Dradis Professional Edition before 4.3.0 allows attackers to change an account password via reusing a password reset token. | |
| Modificada | Media (6.5) | 1.2% | — | Dradisframework Dradis | 16/3/2020 | 17/6/2026 | The API in Dradis Pro 3.4.1 allows any user to extract the content of a project, even if this user is not part of the project team. | |
| Modificada | Media (5.4) | 0.82% | — | Dradisframework Dradis | 12/3/2019 | 17/6/2026 | Cross-site scripting vulnerability in Dradis Community Edition Dradis Community Edition v3.11 and earlier and Dradis Professional Edition v3.1.1 and earlier allow remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors. |