Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.74%—Redhat Pagure12/5/202517/6/2026
A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a specially cratfted git repository they could discover secrets on the server.
AnalizadaAlta (7.1)0.41%—Redhat Pagure12/5/202517/6/2026
A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links, the server could unintentionally show incorporate and make visible content from outside the git repo.
AplazadaCrítica (9.8)0.92%—Redhat PagureAI26/3/202517/6/2026
A vulnerability was found in Pagure. An argument injection in Git during retrieval of the repository history leads to remote code execution on the Pagure instance.
AplazadaAlta (8.1)0.55%—Redhat PagureAI24/12/202417/6/2026
A vulnerability was found in Pagure. Support of symbolic links during repository archiving of repositories allows the disclosure of local files. This flaw allows a malicious user to take advantage of the Pagure instance.
ModificadaMedia (6.1)0.97%—Redhat PagureOpensuse Backports SLEOpensuse Leap25/9/202017/6/2026
Pagure before 5.6 allows XSS via the templates/blame.html blame view.
ModificadaMedia (6.1)1.1%—Redhat PagureFedoraproject FedoraRedhat Enterprise Linux6/11/201917/6/2026
Pagure: XSS possible in file attachment endpoint
ModificadaMedia (5.9)0.90%—Redhat Pagure8/2/201917/6/2026
Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validate TLS certificates, so it is easy for man-in-the-middle attackers to read these e-mails and gain access to Pagure on behalf of other users. This issue is found in the API token expiration reminder cron job in files/api_key_expire_mail.py;…
ModificadaAlta (7.5)1.1%—Redhat Pagure14/9/201717/6/2026
Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization
ModificadaMedia (6.1)0.68%—Redhat Pagure7/10/201617/6/2026
Pagure 2.2.1 XSS in raw file endpoint