Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3064▲ 586 respecto a la semana anterior
Críticas / altas1461▲ 295 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
1224 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Crítica (9.3) | 0.89% | — | Github Enterprise ServerAI | 22/9/2026 | 24/9/2026 | A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated the scheme and host of a user-supplied URL but did not validate the port, allowing requests to be directed to internal services listening on other ports of the same… | |
| En análisis | Alta (7.4) | 0.45% | — | Github Enterprise ServerAI | 22/9/2026 | 24/9/2026 | A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to inject arbitrary HTML attributes into rendered Markdown because the Markdown rendering pipeline rewrote quote characters in already-sanitized HTML without re-sanitizing the result.… | |
| En análisis | Media (6) | 0.45% | — | Github Enterprise ServerAI | 22/9/2026 | 24/9/2026 | An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of the instance to read the raw diff or patch of pull requests in private repositories without authorization. Access tokens for raw pull request diffs and patches were scoped to the repository name and… | |
| Pendiente de análisis | Crítica (10) | 0.56% | — | Altium Enterprise ServerAI | 16/9/2026 | 18/9/2026 | A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unauthenticated network attacker can cause the server to issue outbound HTTP requests to a destination of the attacker's choosing, including internal services that are reachable only from the server… | |
| Analizada | Alta (7.7) | 0.83% | — | Github Enterprise Server | 1/9/2026 | 8/9/2026 | A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execution on the instance. Insufficient network isolation allowed malicious pre-receive hook code to impersonate an internal service and redirect trusted internal requests to a privileged service,… | |
| Analizada | Alta (7.7) | 0.54% | — | Github Enterprise Server | 1/9/2026 | 8/9/2026 | A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution. Exploitation required an authenticated user with write access to a repository and precise timing of concurrent upload requests. This vulnerability affected all versions of GitHub… | |
| Modificada | Alta (8.2) | 0.29% | — | Github Enterprise Server | 1/9/2026 | 22/9/2026 | A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send crafted outbound requests to an attacker-controlled host. An unauthenticated endpoint parsed an attacker-supplied cluster configuration and issued… | |
| Analizada | Media (6.6) | 0.77% | — | Github Enterprise Server | 5/8/2026 | 18/8/2026 | A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause excessive CPU consumption and exhaust the pool of request-handling worker processes by sending a crafted form-encoded HTTP POST request containing deeply nested parameters. Because request… | |
| Analizada | Alta (8.8) | 0.80% | — | Github Enterprise Server | 5/8/2026 | 18/8/2026 | A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and directories on the instance, including the entire user storage directory containing Git LFS objects, release assets, attachments, and avatars. The X-GitHub-Request-Id request… | |
| Aplazada | Media (5.3) | 0.45% | — | Github Enterprise ServerAI | 17/7/2026 | 17/7/2026 | A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with write access to any repository to read metadata from private repositories they did not have access to, including private repository owners and names, branch names, commit SHAs, commit messages, and… | |
| Aplazada | Alta (8.6) | 0.75% | — | Github Enterprise ServerAI | 17/7/2026 | 17/7/2026 | A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write files to arbitrary repository paths, including GitHub Actions workflow files under .github/workflows/ as the path validation did not check the… | |
| Aplazada | Media (5.7) | 0.64% | — | Github Enterprise ServerAI | 17/7/2026 | 17/7/2026 | A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository release notes configuration file containing deeply nested YAML. When release notes were generated, the configuration file was parsed without a nesting… | |
| Aplazada | Crítica (9.4) | 0.71% | — | Altium Enterprise ServerAIAltium 365AI | 1/7/2026 | 20/7/2026 | A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. The service accepts a sequence of post-clone file-manipulation operations that use user-supplied paths without validation, allowing an authenticated user with basic git access to move arbitrary files… | |
| Analizada | Media (5.3) | 0.43% | — | Github Enterprise Server | 1/7/2026 | 6/7/2026 | An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token scoped to a GitHub App installation to perform certain write operations on public repositories outside the token's intended scope. This was possible because the authorization check only verified that… | |
| Analizada | Media (6.3) | 0.32% | — | Github Enterprise Server | 30/6/2026 | 2/7/2026 | A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to execute arbitrary JavaScript in another user's browser by injecting a crafted payload into the title of a Discussion in the Q&A category. The AnsweredQuestionStructuredDataComponent did not… | |
| Analizada | Media (6) | 0.41% | — | Github Enterprise Server | 30/6/2026 | 2/7/2026 | — | |
| Analizada | Media (4.8) | 0.36% | — | Github Enterprise Server | 30/6/2026 | 2/7/2026 | A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner management. An attacker could exploit this by creating an OAuth application requesting the manage_runners:org scope and directing a victim user to… | |
| Pendiente de análisis | Alta (8.3) | 0.52% | — | Altium Enterprise ServerAIAltium 365AI | 5/6/2026 | 23/7/2026 | A path traversal vulnerability exists in the Projects Service download endpoint shared by Altium Enterprise Server and Altium 365. An authenticated user can supply a crafted path parameter that bypasses validation, allowing arbitrary files (including entire directories returned as archives) to be read from the server… | |
| Pendiente de análisis | Crítica (10) | 1.1% | — | Altium Enterprise ServerAIAltium 365AI | 5/6/2026 | 23/7/2026 | Two endpoints in the Vault Service ScriptsController, shared by Altium Enterprise Server and Altium 365, accept file uploads where a user-supplied filename component is used to construct the destination path without validation, allowing arbitrary files to be written to any location writable by the service account.… | |
| Pendiente de análisis | Alta (8.3) | 0.23% | — | Altium Enterprise ServerAIAltium 365AI | 5/6/2026 | 23/7/2026 | A server-side request forgery (SSRF) vulnerability exists in a GraphQL service component shared by Altium Enterprise Server and Altium 365. An authenticated user can submit a request whose input is treated as a URL by the server and used to issue an outbound HTTP GET request without URL validation or destination… | |
| Pendiente de análisis | Crítica (9.4) | 0.32% | — | Altium Enterprise Server Collaboration ServiceAI | 5/6/2026 | 23/7/2026 | A path traversal vulnerability exists in the Altium Enterprise Server Collaboration Service due to improper handling of user-supplied filenames in the MCAD and Simulation file download flows. A regular authenticated user can submit a collaboration message containing a crafted filename, which is later used to construct… | |
| Analizada | Crítica (10) | 0.71% | — | Altium On-prem Enterprise Server | 5/6/2026 | 23/7/2026 | Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an unauthenticated network attacker to write arbitrary files to any writable location on the server filesystem and to read package archive files from the server. No authentication, session, or credentials are… | |
| Analizada | Crítica (9.4) | 0.55% | — | Altium On-prem Enterprise Server | 5/6/2026 | 23/7/2026 | A path traversal vulnerability exists in the Altium Enterprise Server Vault Service UploadController due to improper validation of a user-controlled path component in image upload requests. An authenticated user can supply a crafted absolute path so that the configured storage root is discarded, allowing arbitrary… | |
| Analizada | Crítica (10) | 0.48% | — | Altium On-prem Enterprise Server | 5/6/2026 | 17/6/2026 | A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Because the key is identical across all installations, an unauthenticated network attacker who can reach the server can forge valid download signatures and retrieve files from the Vault storage area… | |
| Aplazada | Media (6.3) | 0.39% | — | Nextcloud ServerAINextcloud Enterprise ServerAI | 1/6/2026 | 22/7/2026 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a malicious user has access to a file share of a user, they could use this share token to also access the chunking upload directly and see temporary part files during… |