Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 86 respecto a la semana anterior
Críticas / altas1460▲ 350 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)91▼ 420 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.33% | — | Go-git Project Go-git | 27/5/2026 | 17/6/2026 | go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside the intended checkout target, including the repository's .git directory. These validations were introduced in upstream… | |
| Analizada | Baja (2.3) | 0.43% | — | Go-git Project Go-git | 27/5/2026 | 17/6/2026 | go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in single quotes without escaping single quotes embedded inside the path. A repository path containing a single quote can… | |
| Analizada | Alta (7) | 0.16% | — | Go-git Project Go-git | 27/5/2026 | 17/6/2026 | go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git objects in a way that differs from upstream Git. When commit or tag objects contain ambiguous or malformed headers, go-git’s decoded representation may expose values differently from… | |
| Analizada | Alta (7.4) | 0.26% | — | Go-git Project Go-git | 8/5/2026 | 17/6/2026 | go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-git may leak HTTP authentication credentials when following redirects during smart-HTTP clone and fetch operations. This issue has been patched in versions 5.18.0 and 6.0.0-alpha.2. | |
| Modificada | Alta (8.2) | 1.0% | — | Simple-git Project Simple-git | 25/4/2026 | 15/7/2026 | Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed… | |
| Modificada | Alta (8.1) | 0.93% | — | Simple-git Project Simple-git | 13/4/2026 | 15/7/2026 | simple-git enables running native Git commands from JavaScript. Versions up to and including 3.31.1 allow execution of arbitrary commands through Git option manipulation, bypassing safety checks meant to block dangerous options like -u and --upload-pack. The flaw stems from an incomplete fix for CVE-2022-25860, as… | |
| Analizada | Media (5) | 0.15% | — | Go-git Project Go-git | 31/3/2026 | 24/7/2026 | go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can cause asymmetric memory consumption, potentially exhausting available memory and resulting in a denial-of-service (DoS)… | |
| Analizada | Baja (2.8) | 0.15% | — | Go-git Project Go-git | 31/3/2026 | 24/7/2026 | go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder for format version 4 fails to validate the path name prefix length before applying it to the previously decoded path name. A maliciously crafted index file can trigger an out-of-bounds slice… | |
| Modificada | Crítica (9.8) | 1.3% | — | Simple-git Project Simple-git | 10/3/2026 | 15/7/2026 | `simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacker to bypass two prior CVE fixes (CVE-2022-25860 and CVE-2022-25912) and achieve full remote code execution on the host machine. Version 3.23.0 contains an updated fix for… | |
| Analizada | Media (4.3) | 0.16% | — | Go-git Project Go-git | 9/2/2026 | 17/6/2026 | go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not properly verified. This resulted in go-git potentially consuming corrupted files, which would likely result in… | |
| Analizada | Alta (7.5) | 0.72% | — | Go-git Project Go-git | 6/1/2025 | 17/6/2026 | go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers… | |
| Analizada | Crítica (9.2) | 1.3% | — | Go-git Project Go-git | 6/1/2025 | 17/6/2026 | go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file… | |
| Modificada | Crítica (9.8) | 1.5% | — | Go-git Project Go-git | 12/1/2024 | 17/6/2026 | A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to create and amend files across the filesystem. In the worse case scenario, remote code execution could be achieved. Applications are only affected if they are using the ChrootOS… | |
| Modificada | Alta (7.5) | 0.70% | — | Go-git Project Go-git | 12/1/2024 | 17/6/2026 | A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Applications using only the in-memory… | |
| Modificada | Crítica (9.8) | 2.7% | — | Simple-git Project Simple-git | 26/1/2023 | 17/6/2026 | Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemote() methods, due to improper input sanitization. This vulnerability exists due to an incomplete fix of [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221). | |
| Modificada | Alta (8) | 1.4% | — | Ruby-git Project Ruby-gitDebian LinuxFedoraproject Fedora | 17/1/2023 | 17/6/2026 | ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-46648. | |
| Modificada | Alta (8) | 1.4% | — | Ruby-git Project Ruby-gitDebian Linux | 17/1/2023 | 17/6/2026 | ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-47318. | |
| Modificada | Crítica (9.8) | 2.9% | — | Simple-git Project Simple-git | 6/12/2022 | 17/6/2026 | The package simple-git before 3.15.0 are vulnerable to Remote Code Execution (RCE) when enabling the ext transport protocol, which makes it exploitable via clone() method. This vulnerability exists due to an incomplete fix of [CVE-2022-24066](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-2434306). | |
| Modificada | Crítica (9.8) | 3.9% | — | Simple-git Project Simple-git | 1/4/2022 | 17/6/2026 | The package simple-git before 3.5.0 are vulnerable to Command Injection due to an incomplete fix of [CVE-2022-24433](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-2421199) which only patches against the git fetch attack vector. A similar use of the --upload-pack feature of git is also supported for git clone, which… | |
| Modificada | Alta (8.8) | 35% | — | Ungit Project Ungit | 21/3/2022 | 17/6/2026 | The package ungit before 1.5.20 are vulnerable to Remote Code Execution (RCE) via argument injection. The issue occurs when calling the /api/fetch endpoint. User controlled values (remote and ref) are passed to the git fetch command. By injecting some git options it was possible to get arbitrary command execution. | |
| Modificada | Crítica (9.8) | 2.4% | — | GIT Project GIT | 17/3/2022 | 17/6/2026 | All versions of package git are vulnerable to Remote Code Execution (RCE) due to missing sanitization in the Git.git method, which allows execution of OS commands rather than just git commands. Steps to Reproduce 1. Create a file named exploit.js with the following content: js var Git = require("git").Git; var repo =… | |
| Modificada | Crítica (9.8) | 3.5% | — | Simple-git Project Simple-git | 11/3/2022 | 17/6/2026 | The package simple-git before 3.3.0 are vulnerable to Command Injection via argument injection. When calling the .fetch(remote, branch, handlerFn) function, both the remote and branch parameters are passed to the git fetch subcommand. By injecting some git options it was possible to get arbitrary command execution. | |
| Modificada | Crítica (9.8) | 2.5% | — | Async-git Project Async-git | 18/2/2021 | 17/6/2026 | The package async-git before 1.13.2 are vulnerable to Command Injection via shell meta-characters (back-ticks). For example: git.reset('atouch HACKEDb') | |
| Modificada | Crítica (9.8) | 5.3% | — | Async-git Project Async-git | 26/1/2021 | 17/6/2026 | The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by git.reset and git.tag. | |
| Modificada | Media (6.1) | 4.0% | — | Viewgit Project Viewgit | 30/1/2020 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ViewGit before 0.0.7 allow remote repository users to inject arbitrary web script or HTML via a (1) tag name to the Shortlog table in templates/shortlog.php or branch name to the (2) Shortlog table in templates/shortlog.php or (3) Heads table in plates/summary.php. |