Skip to content
Toggle Navigation
Kit ISO 27001
Ingeniería y Consultoría
Recursos
ISO 27001
ISO 27001 – GAP Analysis Tool
Ciberseguridad
Vulnerabilidades CVE
Blog
Contacto
Obtener el Toolkit
Toggle Navigation
Kit ISO 27001
Ingeniería y Consultoría
Recursos
ISO 27001
ISO 27001 – GAP Analysis Tool
Ciberseguridad
Vulnerabilidades CVE
Blog
Contacto
Obtener el Toolkit
Vulnerabilidades CVE
Vulnerabilidades CVE
drmunozcl
2025-06-04T18:44:58-04:00
Vulnerabilidades CVE
A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:
Severidad:
Todas
NONE
LOW
MEDIUM
HIGH
CRITICAL
UNKNOWN
CVE:
Aplicar
Borrar filtros
CVE ID
Publicado
Severidad
CVSS
Descripción
CVE-2019-25765
2026-08-13
HIGH
7.5
ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL by manipulating the id parameter in GET requests to…
CVE-2026-73266
2026-08-13
HIGH
7.1
A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to…
CVE-2026-66256
2026-08-13
HIGH
7.2
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. Users with access to the Shindig REST API…
CVE-2026-59765
2026-08-13
N/A
0.0
SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
CVE-2026-59763
2026-08-13
N/A
0.0
Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
CVE-2026-59109
2026-08-13
HIGH
8.8
SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis concatenates partner-controlled…
CVE-2026-58511
2026-08-13
N/A
0.0
Webhook Authorization Header Returned in Plaintext via API
CVE-2026-58510
2026-08-13
N/A
0.0
GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
CVE-2026-58508
2026-08-13
N/A
0.0
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
CVE-2026-58507
2026-08-13
N/A
0.0
Private Repository Existence Disclosure via go-get Meta Endpoint
CVE-2026-58445
2026-08-13
N/A
0.0
Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
CVE-2026-58444
2026-08-13
N/A
0.0
Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents
CVE-2026-58443
2026-08-13
N/A
0.0
Public-only repository tokens can update private PR head branches
CVE-2026-58442
2026-08-13
N/A
0.0
Repository migration SSRF via multi-answer DNS allow-list bypass
CVE-2026-58441
2026-08-13
N/A
0.0
SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
CVE-2026-58440
2026-08-13
N/A
0.0
Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplete revocation cleanup in `DeleteCollaboration`)
CVE-2026-58439
2026-08-13
N/A
0.0
Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
CVE-2026-58438
2026-08-13
N/A
0.0
Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access
CVE-2026-58437
2026-08-13
N/A
0.0
Repository Visibility Manipulation via Git Push Options
CVE-2026-58436
2026-08-13
N/A
0.0
ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
CVE-2026-58435
2026-08-13
N/A
0.0
Gitea LFS Deploy-Key Privilege Escalation
CVE-2026-58434
2026-08-13
N/A
0.0
Private Repository Metadata Remains Accessible After Access Revocation
CVE-2026-58433
2026-08-13
N/A
0.0
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
CVE-2026-58432
2026-08-13
N/A
0.0
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea
CVE-2026-58431
2026-08-13
N/A
0.0
Public-only API token restriction is not enforced on team API routes
CVE-2026-58429
2026-08-13
N/A
0.0
Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
CVE-2026-58428
2026-08-13
N/A
0.0
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
CVE-2026-58427
2026-08-13
N/A
0.0
Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
CVE-2026-58425
2026-08-13
N/A
0.0
OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
CVE-2026-58420
2026-08-13
N/A
0.0
Local File Inclusion via file:// URI in Migration Restore
CVE-2026-58417
2026-08-13
N/A
0.0
REST API exposes organization membership of private organizations to public
CVE-2026-58416
2026-08-13
N/A
0.0
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
CVE-2026-58314
2026-08-13
N/A
0.0
Two SSRF findings in Gitea 1.26.2
CVE-2026-57897
2026-08-13
N/A
0.0
Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
CVE-2026-57894
2026-08-13
N/A
0.0
Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
CVE-2026-57886
2026-08-13
N/A
0.0
Cross-repository issue/comment attachment re-linking can expose private attachment content
CVE-2026-56755
2026-08-13
N/A
0.0
Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
CVE-2026-56750
2026-08-13
N/A
0.0
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
CVE-2026-56657
2026-08-13
N/A
0.0
Gitea SSH Key Parser Denial of Service
CVE-2026-56654
2026-08-13
N/A
0.0
Privilege Escalation via Access Token Scope Escalation in API
CVE-2026-56443
2026-08-13
N/A
0.0
Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
CVE-2026-55987
2026-08-13
N/A
0.0
OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
CVE-2026-55986
2026-08-13
N/A
0.0
Email Management API Bypasses ManageCredentials Feature Restrictions
CVE-2026-55984
2026-08-13
N/A
0.0
Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
CVE-2026-55982
2026-08-13
N/A
0.0
OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
CVE-2026-55402
2026-08-13
N/A
0.0
CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position can send specially crafted data…
CVE-2026-54481
2026-08-13
N/A
0.0
Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)
CVE-2026-50105
2026-08-13
N/A
0.0
RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
CVE-2026-42931
2026-08-13
N/A
0.0
Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
CVE-2026-24791
2026-08-13
N/A
0.0
Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
« Anterior
Página 2 de 4811
Siguiente »
Page load link
Go to Top