Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8) | 0.59% | — | Atlassian Sourcetree | 21/7/2026 | 10/8/2026 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows. * Sourcetree for Mac and Sourcetree for Windows 3.4: Upgrade to a release greater than or equal to 3.4.13 | |
| Analizada | Media (5.9) | 0.13% | — | Atlassian Sourcetree | 24/7/2025 | 17/6/2026 | This Medium severity ACE (Arbitrary Code Execution) vulnerability was introduced in version 4.2.8 of Sourcetree for Mac. This ACE (Arbitrary Code Execution) vulnerability, with a CVSS Score of 5.9, allows a locally authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact… | |
| Analizada | Alta (8.8) | 0.74% | — | Atlassian Sourcetree | 19/11/2024 | 17/6/2026 | This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 4.2.8 of Sourcetree for Mac and 3.4.19 for Sourcetree for Windows. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to execute arbitrary code which has high impact to… | |
| Modificada | Alta (7.8) | 0.39% | — | Atlassian Sourcetree | 16/1/2024 | 17/6/2026 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.14 of Sourcetree for Mac and Sourcetree for Windows. Sourcetree for Mac and Sourcetree for Windows 3.4: Upgrade to a release greater than or equal to 3.4.15 | |
| Modificada | Alta (8.8) | 4.9% | — | Atlassian Sourcetree | 14/6/2019 | 17/6/2026 | An argument injection vulnerability in Atlassian Sourcetree for Windows's URI handlers, in all versions prior to 3.1.3, allows remote attackers to gain remote code execution through the use of a crafted URI. | |
| Modificada | Alta (8.8) | 6.4% | — | Atlassian Sourcetree | 8/3/2019 | 17/6/2026 | There was an command injection vulnerability in Sourcetree for Windows from version 0.5a before version 3.0.10 via URI handling. A remote attacker could send a malicious URI to a victim using Sourcetree for Windows to exploit this issue to gain code execution on the system. | |
| Modificada | Alta (8.8) | 6.7% | — | Atlassian Sourcetree | 8/3/2019 | 17/6/2026 | There was an argument injection vulnerability in Atlassian Sourcetree for Windows from version 0.5a before version 3.0.15 via filenames in Mercurial repositories. A remote attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution… | |
| Modificada | Alta (8.8) | 5.9% | — | Atlassian Sourcetree | 8/3/2019 | 17/6/2026 | There was an argument injection vulnerability in Atlassian Sourcetree for macOS from version 1.2 before version 3.1.1 via filenames in Mercurial repositories. A remote attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the… | |
| Modificada | Alta (8.8) | 1.9% | — | Atlassian Sourcetree | 5/11/2018 | 17/6/2026 | There was an argument injection vulnerability in Sourcetree for Windows from version 0.5.1.0 before version 3.0.0 via Git subrepositories in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on… | |
| Modificada | Alta (8.8) | 1.9% | — | Atlassian Sourcetree | 5/11/2018 | 17/6/2026 | There was an argument injection vulnerability in Sourcetree for macOS from version 1.0b2 before version 3.0.0 via Git subrepositories in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the… | |
| Modificada | Alta (8.1) | 1.6% | — | Atlassian Sourcetree | 24/7/2018 | 17/6/2026 | There was an argument injection vulnerability in Sourcetree for Windows via filenames in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system. Versions of Sourcetree for Windows before… | |
| Modificada | Crítica (9.8) | 2.2% | — | Atlassian Sourcetree | 24/7/2018 | 17/6/2026 | There was an argument injection vulnerability in Sourcetree for macOS via filenames in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the system. Versions of Sourcetree for macOS from 1.0b2… | |
| Modificada | Alta (8.8) | 1.4% | — | Atlassian Sourcetree | 25/4/2018 | 17/6/2026 | There was an argument injection vulnerability in Sourcetree for Windows via Mercurial repository tag name that is going to be deleted. An attacker with permission to create a tag on a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system. All versions… | |
| Modificada | Alta (8.8) | 5.5% | — | Atlassian Sourcetree | 26/1/2018 | 17/6/2026 | Sourcetree for Windows had several argument and command injection bugs in Mercurial and Git repository handling. An attacker with permission to commit to a repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system. From version 0.8.4b of Sourcetree for Windows, this… | |
| Modificada | Alta (8.8) | 5.5% | — | Atlassian Sourcetree | 26/1/2018 | 17/6/2026 | Sourcetree for macOS had several argument and command injection bugs in Mercurial and Git repository handling. An attacker with permission to commit to a repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the system. From version 1.4.0 of Sourcetree for macOS, this… | |
| Modificada | Crítica (9.8) | 8.3% | — | Atlassian Sourcetree | 4/5/2017 | 17/6/2026 | Atlassian SourceTree v2.5c and prior are affected by a command injection in the handling of the sourcetree:// scheme. It will lead to arbitrary OS command execution with a URL substring of sourcetree://cloneRepo/ext:: or sourcetree://checkoutRef/ext:: followed by the command. The Atlassian ID number is SRCTREE-4632. | |
| Modificada | Media (4.3) | 2.1% | — | Sourcetreesolutions Mojoportal | 20/8/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Forums/EditPost.aspx in mojoPortal before 2.3.9.8 allows remote attackers to inject arbitrary web script or HTML via the txtSubject parameter. | |
| Modificada | Media (6.8) | 2.5% | — | Sourcetreesolutions Mojoportal | 24/9/2010 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the file manager service (Services/FileService.ashx) in mojoPortal 2.3.4.3 and 2.3.5.1 allows remote attackers to hijack the authentication of administrators for requests that rename arbitrary files, as demonstrated by causing the user.config file to be moved, leading… | |
| Modificada | Media (4.3) | 3.8% | — | Sourcetreesolutions Mojoportal | 24/9/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ProfileView.aspx in mojoPortal 2.3.4.3 and 2.3.5.1 allows remote attackers to inject arbitrary web script or HTML via the User ID parameter. NOTE: some of these details are obtained from third party information. |