Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

7 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9.2)0.41%—RenovateAIMend Renovate CEAIMend Renovate EEAI10/9/202629/9/2026
Renovate is a dependency update automation tool. When listing tags/digests for a container image, Renovate follows pagination links supplied by the remote registry in the HTTP Link header and attaches the registry credentials to the follow-up request without verifying that the pagination URL has the same origin as the…
Pendiente de análisisAlta (8.5)0.23%—RenovateAIMend Renovate CEAIMend Renovate EEAIMend Renovate Enterprise EditionAI10/9/202629/9/2026
Renovate is a dependency update automation tool. In versions before 44.14.7 (and in Mend Renovate CE/EE distributions before 15.4.0, and the mend-renovate-enterprise-edition Helm chart before 10.4.0), the manager/gradle-wrapper module does not escape the distributionUrl value read from a repository's…
Pendiente de análisisMedia (6.9)0.30%—RenovateAIMend Renovate CEAIMend Renovate Enterprise EditionAI10/9/202629/9/2026
Renovate is a dependency update automation tool. In versions before 44.3.1 (and Mend Renovate CE/EE images before 15.4.0, mend-renovate-ce Helm chart before 15.4.0, mend-renovate-enterprise-edition Helm chart before 10.4.0), digest updates are not subject to the internal `minimumReleaseAge` (stability age) checks.…
Pendiente de análisisCrítica (9.2)0.41%—RenovateAIMend Renovate CEAIMend Renovate EEAIMend Renovate Enterprise EditionAI10/9/202629/9/2026
Renovate is a dependency update automation tool. In versions before 44.11.2 (and Mend Renovate CE/EE images and charts before 15.4.0, and mend-renovate-enterprise-edition helm chart before 10.4.0), when listing new package versions from a NuGet registry Renovate follows pagination URLs supplied by the registry in the…
Pendiente de análisisCrítica (9.2)0.41%—RenovateAIMend Renovate CEAIMend Renovate Enterprise EditionAI10/9/202629/9/2026
Renovate, a dependency update tool, follows pagination links supplied by the GitHub server in the HTTP `Link` header when interacting with GitHub.com, GitHub Enterprise Cloud, or GitHub Enterprise Server, and sends the credentials configured for that host to the URL given as the 'next' page. Because the pagination URL…
Pendiente de análisisAlta (8.4)0.96%—RenovateAIMend Renovate-ceAIMend Renovate-eeAI19/8/202629/9/2026
Renovate versions >=32.124.0 and before 42.68.5 (and Mend renovate-ce/renovate-ee before 13.3.0) contain a command injection vulnerability in Gradle Wrapper artifact handling. When Renovate processes Gradle Wrapper updates, it invokes a wrapper update command via a shell (e.g. /bin/sh -c ... ./gradlew :wrapper…
Pendiente de análisisMedia (6.8)0.15%—RenovateAIMend Renovate-ceAIRenovate-ee-serverAIRenovate-ee-workerAI19/8/202629/9/2026
Renovate versions from 42.68.1 before 42.96.3 and from 43.0.0 before 43.4.4, including the renovate/renovate Docker images, and Mend Renovate CE/EE images (renovate-ce, renovate-ee-server, renovate-ee-worker) from 13.3.0 before 13.6.0, fail to restrict environment variables to an allowlist when spawning child…