Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
76 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 1.8% | — | Tuleap Enterprise EditionAI | 21/9/2026 | 21/9/2026 | An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an attacker to execute arbitrary commands on the server. | |
| Pendiente de análisis | Alta (7.7) | 0.20% | — | Tuleap Enterprise EditionAI | 25/8/2026 | 28/8/2026 | A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to gain access to user accounts created during XML import. | |
| Pendiente de análisis | Alta (7.5) | 0.42% | — | Tuleap Enterprise EditionAI | 13/7/2026 | 13/7/2026 | An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to access data of other users without authorization. | |
| Analizada | Media (4.6) | 0.16% | — | Enalean Tuleap | 2/2/2026 | 17/6/2026 | Tuleap is an Open Source Suite for management of software development and collaboration. Tuleap is missing CSRF protection in the Overview inconsistent items. An attacker could use this vulnerability to trick victims into repairing inconsistent items (creating artifact links from the release). This vulnerability is… | |
| Analizada | Media (4.3) | 0.16% | — | Enalean Tuleap | 9/12/2025 | 17/6/2026 | Tuleap is a free and open source suite for management of software development and collaboration. Versions of Tuleap Community Edition prior to 17.0.99.1763803709 and Tuleap Enterprise Edition versions prior to 17.0-4 and 16.13-9 are mission CSRF protections in its tracker field dependencies, allowing attackers to… | |
| Analizada | Media (4.3) | 0.14% | — | Enalean Tuleap | 8/12/2025 | 17/6/2026 | Tuleap is a free and open source suite for management of software development and collaboration. Versions of Tuleap Community Edition prior to 17.0.99.1763126988 and Tuleap Enterprise Edition prior to 17.0-3 and 16.13-8 have missing CSRF protections which allow attackers to create or remove tracker triggers. This… | |
| Analizada | Media (5.4) | 0.14% | — | Enalean Tuleap | 8/12/2025 | 17/6/2026 | Tuleap is a free and open source suite for management of software development and collaboration. Tuleap Community Editon versions prior to 17.0.99.1762456922 and Tuleap Enterprise Edition versions prior to 17.0-2, 16.13-7 and 16.12-10 are vulnerable to CSRF attacks through planning management API. Attackers have… | |
| Analizada | Media (4.3) | 0.14% | — | Enalean Tuleap | 8/12/2025 | 17/6/2026 | Tuleap is an Open Source Suite for management of software development and collaboration. Tuleap Community Edition versions below 17.0.99.1762444754 and Tuleap Enterprise Edition versions prior to 17.0-2, 16.13-7 and 16.12-10 allow attackers trick victims into changing tracker general settings. This issue is fixed in… | |
| Analizada | Media (6.5) | 0.28% | — | Enalean Tuleap | 8/12/2025 | 17/6/2026 | Tuleap is an Open Source Suite for management of software development and collaboration. Versions below 17.0.99.1762431347 of Tuleap Community Edition and Tuleap Enterprise Edition below 17.0-2, 16.13-7 and 16.12-10 allow attackers to access file release system information in projects they do not have access to. This… | |
| Aplazada | Media (4.6) | 0.14% | — | Enalean TuleapAI | 12/11/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap Community Edition prior to version 16.13.99.1762267347 and Tuleap Enterprise Edition prior to versions 17.01-, 16.13-6, and 16.12-9 don't have cross-site request forgery protections in the file release system. An… | |
| Aplazada | Media (4.6) | 0.14% | — | Enalean TuleapAI | 12/11/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap Community Edition prior to version 16.13.99.1761813675 and Tuleap Enterprise Edition prior to versions 16.13-5 and 16.12-8 don't have cross-site request forgery protection in the management of SVN commit rules and… | |
| Aplazada | Media (4.3) | 0.33% | — | Tuleap Community EditionAITuleap Enterprise EditionAIEnalean TuleapAI | 18/9/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Backlog item representations do not verify the permissions of the child trackers. Users might see tracker names they should not have access to. This vulnerability is fixed in Tuleap Community Edition 16.11.99.1757427600… | |
| Analizada | Media (5.3) | 0.29% | — | Enalean Tuleap | 29/8/2025 | 17/6/2026 | Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition versions before 16.10.99.1754050155 and Tuleap Enterprise Edition versions before 16.9-8 and before 16.10-5, an attacker can access to the content of the special and always there… | |
| Analizada | Media (4.3) | 0.32% | — | Enalean Tuleap | 29/7/2025 | 17/6/2026 | Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1752585665 and Tuleap Enterprise Edition prior to 16.8-6 and 16.9-5, users may potentially access confidential information from artifacts that they are not… | |
| Analizada | Media (5.4) | 0.23% | — | Enalean Tuleap | 29/7/2025 | 17/6/2026 | Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1751892857 and Tuleap Enterprise Edition prior to 16.8-5 and 16.9-3, malicious users with some control over certain artifacts could insert malicious code when… | |
| Analizada | Media (5.3) | 0.30% | — | Enalean Tuleap | 29/7/2025 | 17/6/2026 | Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1750843170 and Tuleap Enterprise Edition prior to 16.8-4 and 16.9-2, the forgot password form allows for user enumeration. This is fixed in Tuleap Community… | |
| Analizada | Media (4.3) | 0.17% | — | Enalean Tuleap | 25/6/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker could use a cross-site request forgery vulnerability in Tuleap Community Edition prior to version 16.8.99.1749830289 and Tuleap Enterprise Edition prior to version 16.9-1 to trick victims into changing the… | |
| Analizada | Media (4.3) | 0.17% | — | Enalean Tuleap | 25/6/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker could use a vulnerability present in Tuleap Community Edition prior to version 16.8.99.1748845907 and Tuleap Enterprise Edition prior to versions 16.8-3 and 16.7-5 to trick victims into changing the canned… | |
| Analizada | Media (5.3) | 0.37% | — | Enalean Tuleap | 31/3/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker can access release notes content or information via the FRS REST endpoints it should not have access to. This vulnerability is fixed in Tuleap Community Edition 16.5.99.1742812323 and Tuleap Enterprise Edition… | |
| Analizada | Media (4.8) | 0.30% | — | Enalean Tuleap | 31/3/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap allows cross-site scripting (XSS) via the content of RSS feeds in the RSS widgets. A project administrator or someone with control over an used RSS feed could use this vulnerability to force victims to execute… | |
| Analizada | Media (4.3) | 0.33% | — | Enalean Tuleap | 31/3/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap does not enforce read permissions on parent trackers in the REST API. This vulnerability is fixed in Tuleap Community Edition 16.5.99.1742392651 and Tuleap Enterprise Edition 16.5-5 and 16.4-8. | |
| Analizada | Media (4.3) | 0.20% | — | Enalean Tuleap | 31/3/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap is missing CSRF protection on tracker hierarchy administration. An attacker could use this vulnerability to trick victims into submitting or editing artifacts or follow-up comments. This vulnerability is fixed in… | |
| Analizada | Media (4.3) | 0.20% | — | Enalean Tuleap | 31/3/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap has missing CSRF protections on artifact submission & edition from the tracker view. An attacker could use this vulnerability to trick victims into submitting or editing artifacts or follow-up comments. The… | |
| Analizada | Media (4.6) | 0.17% | — | Enalean Tuleap | 4/3/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap is missing CSRF protections on tracker fields administrative operations. An attacker could use this vulnerability to trick victims into removing or updating tracker fields. This vulnerability is fixed in Tuleap… | |
| Analizada | Media (4.6) | 0.33% | — | Enalean Tuleap | 4/3/2025 | 17/6/2026 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. In a standard usages of Tuleap, the issue has a limited impact, it will mostly leave dangling data. However, a malicious user could create and delete reports multiple times to cycle through all the filters of all reports… |