Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.4) | 0.46% | — | GIT FOR WindowsAI | 21/8/2026 | 25/9/2026 | Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, a malicious remote Git server can advertise a bundle URI that reaches transport_get_remote_bundle_uri(), fetch_bundle_uri_internal(), and copy_uri_to_file() in bundle-uri.c during clone or fetch when transfer.bundleuri=true. Non-HTTP(S) values are… | |
| Pendiente de análisis | Alta (7.4) | 0.53% | — | GIT FOR WindowsAI | 15/4/2026 | 17/6/2026 | Git for Windows is the Windows port of Git. Versions prior to 2.53.0.windows.3 do not have protections that prevent attackers from obtaining a user's NTLM hash. The NTLM hash can be obtained by tricking users into cloning a malicious repository, or checking out a malicious branch, that accesses an attacker-controlled… | |
| Modificada | Alta (7.8) | 0.38% | — | GIT FOR Windows Project GIT FOR Windows | 25/4/2023 | 17/6/2026 | Git for Windows is the Windows port of Git. Prior to version 2.40.1, any user of Git CMD who starts the command in an untrusted directory is impacted by an Uncontrolles Search Path Element vulnerability. Maliciously-placed `doskey.exe` would be executed silently upon running Git CMD. The problem has been patched in… | |
| Modificada | Alta (7.8) | 0.38% | — | GIT FOR Windows Project GIT FOR Windows | 25/4/2023 | 17/6/2026 | Git for Windows, the Windows port of Git, ships with an executable called `connect.exe`, which implements a SOCKS5 proxy that can be used to connect e.g. to SSH servers via proxies when certain ports are blocked for outgoing connections. The location of `connect.exe`'s config file is hard-coded as `/etc/connectrc`… | |
| Modificada | Baja (2.2) | 0.96% | — | GIT FOR Windows Project GIT FOR WindowsFedoraproject Fedora | 25/4/2023 | 17/6/2026 | In Git for Windows, the Windows port of Git, no localized messages are shipped with the installer. As a consequence, Git is expected not to localize messages at all, and skips the gettext initialization. However, due to a change in MINGW-packages, the `gettext()` function's implicit initialization no longer uses the… | |
| Modificada | Alta (7.8) | 0.39% | — | GIT FOR Windows Project GIT FOR Windows | 14/2/2023 | 17/6/2026 | Git for Windows is the Windows port of the revision control system Git. Prior to Git for Windows version 2.39.2, when `gitk` is run on Windows, it potentially runs executables from the current directory inadvertently, which can be exploited with some social engineering to trick users into running untrusted code. A… | |
| Modificada | Alta (7.3) | 0.35% | — | GIT FOR Windows Project GIT FOR Windows | 14/2/2023 | 17/6/2026 | Git for Windows is the Windows port of the revision control system Git. Prior to Git for Windows version 2.39.2, by carefully crafting DLL and putting into a subdirectory of a specific name living next to the Git for Windows installer, Windows can be tricked into side-loading said DLL. This potentially allows users… | |
| Modificada | Alta (7.8) | 1.5% | — | Microsoft Visual Studio 2017Microsoft Visual Studio 2019Microsoft Visual Studio 2022GIT FOR Windows Project GIT FOR Windows | 12/4/2022 | 17/6/2026 | GitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user account. | |
| Modificada | Alta (7.8) | 0.90% | — | GIT FOR Windows Project GIT FOR Windows | 11/11/2016 | 17/6/2026 | Untrusted search path vulnerability in Git 1.x for Windows allows local users to gain privileges via a Trojan horse git.exe file in the current working directory. NOTE: 2.x is unaffected. |