Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
52 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.37% | — | WeblateAI | 29/9/2026 | 2/10/2026 | Weblate is a web-based continuous localization platform used to manage software translations. Weblate 4.11.1 through 2026.7.1 contains an argument-injection vulnerability in its Mercurial backend. Repository filenames beginning with - could be interpreted as Mercurial options instead of literal paths. An authenticated… | |
| Pendiente de análisis | Baja (2.3) | 0.08% | — | Weblate WLCAI | 22/9/2026 | 25/9/2026 | wlc is a Weblate command-line client using Weblate's REST API. Prior to 2.0.1, automatically discovered configuration from .weblate, .weblate.ini, or weblate.ini can select the API URL while an unscoped API token is supplied through WLC_KEY or --key without a matching WLC_URL or --url. When wlc runs in an untrusted… | |
| Aplazada | Baja (3.5) | 0.20% | — | WeblateAI | 26/8/2026 | 9/9/2026 | Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, a user permitted to manage component repository URLs can perform server-side request forgery against internal services through DNS rebinding during VCS operations. Weblate validates the hostname's… | |
| Aplazada | Media (5.3) | 0.40% | — | WeblateAI | 26/8/2026 | 9/9/2026 | Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, Weblate's object-scoped RSS feeds do not apply the permission checks used elsewhere, allowing unauthorized users to read change-history metadata from private projects and restricted components. On… | |
| Aplazada | Media (6.5) | 0.44% | — | WeblateAI | 26/8/2026 | 9/9/2026 | Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a user with the built-in "Edit source" role can store a malicious regular expression in a source string's flags that is executed without any timeout, allowing them to stall requests and deny… | |
| Aplazada | Media (4.3) | 0.30% | — | WeblateAI | 26/8/2026 | 9/9/2026 | Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, an authenticated user with access to a project can retrieve the change history of restricted components in that project through nested API change endpoints, even without permission to view those… | |
| Aplazada | Alta (7.7) | 0.59% | — | WeblateAI | 26/8/2026 | 9/9/2026 | Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their repository through the App store metadata download feature, which resolves attacker-influenced paths without adequately confining them to the… | |
| Aplazada | Media (4.4) | 0.40% | — | WeblateAI | 26/8/2026 | 9/9/2026 | Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a team can require its members to configure two-factor authentication before receiving the team's permissions, but this requirement is not enforced for site-wide global permissions. As a result, a… | |
| Aplazada | Alta (8.1) | 0.45% | — | WeblateAI | 26/8/2026 | 9/9/2026 | Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce the scope of project- and workspace-scoped teams, allowing a user to submit invalid team configurations through the API. By assigning projects to a team via… | |
| Aplazada | Media (4.3) | 0.32% | — | WeblateAI | 26/8/2026 | 9/9/2026 | Weblate is a web-based localization tool. In versions prior to 2026.7, several endpoints look up objects in a globally scoped manner rather than restricting the lookup to projects the user can access, so they return HTTP 403 (Forbidden) instead of 404 (Not Found) when a user requests an object they are not authorized… | |
| Aplazada | Baja (3.5) | 0.26% | — | WeblateAI | 26/8/2026 | 9/9/2026 | Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email through PUT or PATCH requests to /api/users/{username}/ without verifying the new address, allowing a later team invitation for that address to be accepted without access to the intended recipient's… | |
| Aplazada | Media (5.9) | 0.47% | — | WeblateAI | 10/6/2026 | 17/6/2026 | Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_RESTRICT_PRIVATE did not properly account for some transitional IPv6 ranges, multicast addresses, or some semi-private IPv4 ranges, which allowed some addresses to bypass private range restrictions. This issue has been… | |
| Aplazada | Media (4.6) | 0.29% | — | WeblateAI | 10/6/2026 | 17/6/2026 | Weblate is a web based localization tool. Prior to version 2026.5, Weblate's live search preview renders unit source and context as HTML without escaping. Any contributor whose content reaches those fields stores HTML and CSS that runs inside the authenticated editor of every user who runs a matching search. This… | |
| Analizada | Media (4.8) | 0.30% | — | Weblate WLC | 8/5/2026 | 17/6/2026 | wlc is a Weblate command-line client using Weblate's REST API. Prior to version 2.0.0, the HTML output format in wlc embeds API response data into HTML without escaping, allowing cross-site scripting when the output is rendered in a browser. This issue has been patched in version 2.0.0. | |
| Analizada | Media (4.3) | 0.37% | — | Weblate | 7/5/2026 | 17/6/2026 | Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. | |
| Analizada | Media (4.3) | 0.38% | — | Weblate | 7/5/2026 | 17/6/2026 | Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. | |
| Analizada | Media (5.3) | 0.50% | — | Weblate | 7/5/2026 | 17/6/2026 | Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/<name>.json contains an attacker-chosen repo URL pointing… | |
| Analizada | Media (5.4) | 0.37% | — | Weblate | 7/5/2026 | 17/6/2026 | Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. | |
| Analizada | Media (5) | 0.37% | — | Weblate | 15/4/2026 | 17/6/2026 | Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path… | |
| Analizada | Media (4.1) | 0.33% | — | Weblate | 15/4/2026 | 17/6/2026 | Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF protections. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can disable the webhook add-on as a workaround. | |
| Analizada | Alta (8.8) | 0.54% | — | Weblate | 15/4/2026 | 17/6/2026 | Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limit the scope of edits. This issue has been fixed in version 5.17. | |
| Analizada | Media (5) | 0.33% | — | Weblate | 15/4/2026 | 17/6/2026 | Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by the per-project "Administration" role) can configure machine translation service URLs pointing to arbitrary internal network addresses. During configuration validation, Weblate makes an HTTP request… | |
| Analizada | Alta (7.7) | 0.53% | — | Weblate | 15/4/2026 | 17/6/2026 | Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following symlinks outside the repository. This issue has been fixed in version 5.17. | |
| Analizada | Media (5) | 0.31% | — | Weblate | 15/4/2026 | 17/6/2026 | Weblate is a web based localization tool. In versions prior to 5.17, the ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. This issue has been fixed in version 5.17. | |
| Analizada | Alta (8) | 0.88% | — | Weblate | 15/4/2026 | 17/6/2026 | Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which could lead to remote code execution under certain circumstances. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can limit… |