Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.74% | — | Redhat Pagure | 12/5/2025 | 17/6/2026 | A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a specially cratfted git repository they could discover secrets on the server. | |
| Analizada | Alta (7.1) | 0.41% | — | Redhat Pagure | 12/5/2025 | 17/6/2026 | A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links, the server could unintentionally show incorporate and make visible content from outside the git repo. | |
| Aplazada | Crítica (9.8) | 0.92% | — | Redhat PagureAI | 26/3/2025 | 17/6/2026 | A vulnerability was found in Pagure. An argument injection in Git during retrieval of the repository history leads to remote code execution on the Pagure instance. | |
| Aplazada | Alta (8.1) | 0.55% | — | Redhat PagureAI | 24/12/2024 | 17/6/2026 | A vulnerability was found in Pagure. Support of symbolic links during repository archiving of repositories allows the disclosure of local files. This flaw allows a malicious user to take advantage of the Pagure instance. | |
| Modificada | Media (6.1) | 0.97% | — | Redhat PagureOpensuse Backports SLEOpensuse Leap | 25/9/2020 | 17/6/2026 | Pagure before 5.6 allows XSS via the templates/blame.html blame view. | |
| Modificada | Media (6.1) | 1.1% | — | Redhat PagureFedoraproject FedoraRedhat Enterprise Linux | 6/11/2019 | 17/6/2026 | Pagure: XSS possible in file attachment endpoint | |
| Modificada | Media (5.9) | 0.90% | — | Redhat Pagure | 8/2/2019 | 17/6/2026 | Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validate TLS certificates, so it is easy for man-in-the-middle attackers to read these e-mails and gain access to Pagure on behalf of other users. This issue is found in the API token expiration reminder cron job in files/api_key_expire_mail.py;… | |
| Modificada | Alta (7.5) | 1.1% | — | Redhat Pagure | 14/9/2017 | 17/6/2026 | Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization | |
| Modificada | Media (6.1) | 0.68% | — | Redhat Pagure | 7/10/2016 | 17/6/2026 | Pagure 2.2.1 XSS in raw file endpoint |