Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.72% | — | Kallithea-scm Kallithea | 21/9/2017 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Kallithea before 0.2. | |
| Modificada | Media (5.4) | 0.95% | — | Kallithea-scm Kallithea | 19/9/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the administration pages in Kallithea before 0.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) first name or (2) last name user details, or the (3) repository, (4) repository group, or (5) user group description. | |
| Modificada | Alta (8.8) | 0.59% | — | Kallithea-scm Kallithea | 24/4/2017 | 17/6/2026 | Routes in Kallithea before 0.3.2 allows remote attackers to bypass the CSRF protection by using the GET HTTP request method. | |
| Modificada | Media (6.5) | 0.85% | — | Kallithea | 24/4/2017 | 17/6/2026 | Kallithea before 0.3.2 allows remote authenticated users to edit or delete open pull requests or delete comments by leveraging read access. | |
| Modificada | Media (5) | 6.1% | — | Kallithea-scm Kallithea | 29/10/2015 | 17/6/2026 | CRLF injection vulnerability in Kallithea before 0.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the came_from parameter to _admin/login. | |
| Modificada | Media (4) | 1.8% | — | Kallithea-scm KallitheaRhodecode Enterprise | 16/2/2015 | 17/6/2026 | RhodeCode before 2.2.7 and Kallithea 0.1 allows remote authenticated users to obtain API keys and other sensitive information via the get_repo API method. |