Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.55% | — | Gurock Testrail | 3/2/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Gurock TestRail before 7.1.2 allows remote authenticated attackers to run arbitrary code via the reference field in milestones or description fields in reports. | |
| Modificada | Media (5.4) | 0.59% | — | Gurock Testrail | 20/12/2021 | 17/6/2026 | Gurock TestRail before 7.2.4 mishandles HTML escaping. | |
| Modificada | Alta (7.5) | 47% | — | Gurock Testrail | 22/9/2021 | 17/6/2026 | Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat actor can access the /files.md5 file on the client side of a Gurock TestRail application, disclosing a full list of application files and the corresponding file paths. The corresponding file paths can… | |
| Modificada | Media (5.4) | 1.5% | — | Gurock Testrail | 9/8/2021 | 17/6/2026 | A vulnerability in the web UI of Gurock TestRail v5.3.0.3603 could allow an unauthenticated, remote attacker to affect the integrity of a device via a clickjacking attack. The vulnerability is due to insufficient input validation of iFrame data in HTTP requests that are sent to an affected device. An attacker could… | |
| Modificada | Alta (8.8) | 2.7% | — | Gurock Testrail | 25/2/2019 | 17/6/2026 | An issue was discovered in Gurock TestRail 5.6.0.3853. An "Unrestricted Upload of File" vulnerability exists in the image-upload form (available in the description editor), allowing remote authenticated users to execute arbitrary code by uploading an image file with an executable extension but a safe Content-Type… | |
| Modificada | Media (5.3) | 1.1% | — | Gurock Testrail | 7/2/2019 | 17/6/2026 | index.php in Gurock TestRail 5.3.0.3603 returns potentially sensitive information for an invalid request, as demonstrated by full path disclosure and the identification of PHP as the backend technology. | |
| Modificada | Media (6.5) | 1.0% | — | Agiletestware Pangolin Connector FOR Testrail | 1/8/2018 | 17/6/2026 | A data modification vulnerability exists in Jenkins Agiletestware Pangolin Connector for TestRail Plugin 2.1 and earlier in GlobalConfig.java that allows attackers with Overall/Read permission to override this plugin's configuration by sending crafted HTTP requests to an unprotected endpoint. | |
| Modificada | Media (4.3) | 1.7% | — | Gurock Testrail | 26/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Gurock TestRail before 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the Created By field in a project activity. |