Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2534▼ 410 respecto a la semana anterior
Críticas / altas1307▲ 25 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
–

7 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.40%—Dradis Community EditionAI25/8/202624/9/2026
In Dradis Community Edition, the ProvidersController and AgentsController gate their admin_required before_action on `defined?(Dradis::Pro)`, a constant that is never defined in CE, so the authorization check is never applied. As a result, any authenticated (non-admin) user can create an AI provider pointing to an…
AnalizadaMedia (4.3)0.20%—Dradisframework Dradis10/7/202517/6/2026
In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs.
AnalizadaMedia (4.3)0.26%—Dradisframework Dradis5/7/202517/6/2026
Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of forcing the use of embedded (uploaded) images. This can be leveraged by an authorized author to attempt to steal the Net-NTLM hashes of other authors on a Windows domain network.
ModificadaMedia (5.4)0.51%—Dradisframework Dradis25/4/202317/6/2026
Dradis before 4.8.0 allows persistent XSS by authenticated author users, related to avatars.
ModificadaMedia (5.9)0.52%—Dradisframework Dradis24/6/202217/6/2026
Dradis Professional Edition before 4.3.0 allows attackers to change an account password via reusing a password reset token.
ModificadaMedia (6.5)1.2%—Dradisframework Dradis16/3/202017/6/2026
The API in Dradis Pro 3.4.1 allows any user to extract the content of a project, even if this user is not part of the project team.
ModificadaMedia (5.4)0.82%—Dradisframework Dradis12/3/201917/6/2026
Cross-site scripting vulnerability in Dradis Community Edition Dradis Community Edition v3.11 and earlier and Dradis Professional Edition v3.1.1 and earlier allow remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.