Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.72%—Kallithea-scm Kallithea21/9/201717/6/2026
Cross-site request forgery (CSRF) vulnerability in Kallithea before 0.2.
ModificadaMedia (5.4)0.95%—Kallithea-scm Kallithea19/9/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the administration pages in Kallithea before 0.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) first name or (2) last name user details, or the (3) repository, (4) repository group, or (5) user group description.
ModificadaAlta (8.8)0.59%—Kallithea-scm Kallithea24/4/201717/6/2026
Routes in Kallithea before 0.3.2 allows remote attackers to bypass the CSRF protection by using the GET HTTP request method.
ModificadaMedia (6.5)0.85%—Kallithea24/4/201717/6/2026
Kallithea before 0.3.2 allows remote authenticated users to edit or delete open pull requests or delete comments by leveraging read access.
ModificadaMedia (5)6.1%—Kallithea-scm Kallithea29/10/201517/6/2026
CRLF injection vulnerability in Kallithea before 0.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the came_from parameter to _admin/login.
ModificadaMedia (4)1.8%—Kallithea-scm KallitheaRhodecode Enterprise16/2/201517/6/2026
RhodeCode before 2.2.7 and Kallithea 0.1 allows remote authenticated users to obtain API keys and other sensitive information via the get_repo API method.