Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3072▲ 552 respecto a la semana anterior
Críticas / altas1458▲ 273 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
–

5 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.52%—Jenkins GIT Server2/5/202417/6/2026
Jenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git repository over SSH, allowing attackers with a previously configured SSH public key but lacking Overall/Read permission to access these repositories.
ModificadaMedia (6.5)1.3%—Jenkins GIT Server24/1/202417/6/2026
Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing attackers with Overall/Read permission to read content from arbitrary files on the Jenkins controller file…
ModificadaAlta (7.5)2.9%—Adobe Git-server14/8/202017/6/2026
The resolveRepositoryPath function doesn't properly validate user input and a malicious user may traverse to any valid Git repository outside the repoRoot. This issue may lead to unauthorized access of private Git repositories as long as the malicious user knows or brute-forces the location of the repository.
ModificadaAlta (8.8)1.2%—Bonobogitserver Bonobo GIT Server24/4/201917/6/2026
Improper handling of extra parameters in the AccountController (User Profile edit) in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows authenticated users to gain application administrator privileges via additional form parameter submissions.
ModificadaCrítica (9.8)3.8%—Bonobogitserver Bonobo GIT Server24/4/201917/6/2026
The GitController in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows execution of arbitrary commands in the context of the web server via a crafted http request.