Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

41 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.3)0.21%—Joplinapp JoplinMsiemens One2html18/5/202624/7/2026
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the importer which allows overwriting arbitrary files on disk. The OneNote converter does not sanitize the names of embedded files before writing…
AnalizadaCrítica (9.8)0.45%—Linaro Openamp1/5/202617/6/2026
OpenAMP v2025.10.0 ELF loader contains an integer overflow vulnerability in firmware image parsing. In elf_loader.c, it performs multiplication of two attacker-controlled 16-bit values from the ELF header without overflow checking. On 32-bit embedded systems (STM32MP1, Zynq, i.MX), large values can cause the product…
AnalizadaCrítica (9.8)0.40%—Linagora Twake9/3/202617/6/2026
An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linagora Twake v2023.Q1.1223.
AnalizadaAlta (8.8)0.36%—Linagora Twake9/3/202617/6/2026
An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in linagora Twake v2023.Q1.1223. This allows attackers to execute arbitrary code.
AnalizadaMedia (6.1)0.21%—Linagora Twake9/3/202617/6/2026
An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in linagora Twake v2023.Q1.1223. This allows attackers to obtain sensitive information and execute arbitrary code.
AplazadaAlta (7.1)0.12%—Eduard Pinuaga Linares DID Prestashop DisplayAI27/10/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Eduard Pinuaga Linares Did Prestashop Display did-prestashop-display allows Stored XSS.This issue affects Did Prestashop Display: from n/a through <= 1.0.30.
ModificadaMedia (6.1)0.33%—Bradleybdalina Image TAG Manager31/1/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bradley B. Dalina Image Tag Manager allows Reflected XSS.This issue affects Image Tag Manager: from n/a through 1.5.
ModificadaCrítica (9.8)0.53%—Gmbilisim Multi-disciplinary Design Optimization29/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GM Information Technologies MDO allows SQL Injection. This issue affects MDO: through 20231229. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
ModificadaCrítica (9.8)0.59%—Linagora Twake7/11/202317/6/2026
Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 2023.Q1.1223.
ModificadaAlta (7.8)0.18%—ARM CompilerARM Compiler FOR Embedded FusaARM Compiler FOR Functional SafetyARM Development Studio+727/7/202317/6/2026
When the installation directory does not have sufficiently restrictive file permissions, an attacker can modify files in the installation directory to cause execution of malicious code.
ModificadaAlta (8.8)0.91%—Ai-dev Declinaisons A LA Volee7/7/202317/6/2026
ai-dev aicombinationsonfly before v0.3.1 was discovered to contain a SQL injection vulnerability via the component /includes/ajax.php.
ModificadaMedia (5.4)0.73%—Fit2cloud Lina24/5/202317/6/2026
Jumpserver 2.10.0 <= version <= 2.26.0 contains multiple stored XSS vulnerabilities because of improper filtering of user input, which can execute any javascript under admin's permission.
ModificadaCrítica (9.8)0.62%💥 PoCLinagora Twake27/3/202317/6/2026
Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 0.0.0.
ModificadaAlta (8.8)1.1%—Lfprojects Modelina26/1/202317/6/2026
Modelina is a library for generating data models based on inputs such as AsyncAPI, OpenAPI, or JSON Schema documents. Versions prior to 1.0.0 are vulnerable to Code injection. This issue affects anyone who is using the default presets and/or does not handle the functionality themself. This issue has been partially…
ModificadaMedia (5.4)56%—Linagora Twake1/1/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository linagora/twake prior to 2023.Q1.1200+.
ModificadaCrítica (9.8)2.0%—Linaro Lava18/11/202217/6/2026
In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2 template. The REST API endpoint for validating device configuration files in lava-server loads input as a Jinja2 template in a way that can be used to trigger remote code execution…
ModificadaMedia (6.5)1.0%—Linaro LavaDebian Linux18/11/202217/6/2026
In Linaro Automated Validation Architecture (LAVA) before 2022.11, users with valid credentials can submit crafted XMLRPC requests that cause a recursive XML entity expansion, leading to excessive use of memory on the server and a Denial of Service.
ModificadaAlta (8.8)1.4%—Linaro LavaDebian Linux13/10/202217/6/2026
In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.py. Due to improper input sanitization, an anonymous user can force the lava-server-gunicorn service to execute user-provided code on the server.
ModificadaAlta (7.8)0.54%—Joplinapp Joplin30/9/202217/6/2026
Joplin version 2.8.8 allows an external attacker to execute arbitrary commands remotely on any client that opens a link in a malicious markdown file, via Joplin. This is possible because the application does not properly validate the schema/protocol of existing links in the markdown file before passing them to the…
ModificadaCrítica (9)2.3%💥 PoCJoplinapp Joplin25/7/20229/7/2026
Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.
ModificadaAlta (8.1)2.0%💥 PoCCaphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+666/6/20229/7/2026
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected…
ModificadaAlta (8.8)0.40%—Joplinapp Joplin24/8/202117/6/2026
The package joplin before 2.3.2 are vulnerable to Cross-site Request Forgery (CSRF) due to missing CSRF checks in various forms.
ModificadaCrítica (9.8)1.7%—Rulinalg Project Rulinalg31/12/202017/6/2026
An issue was discovered in the rulinalg crate through 2020-02-11 for Rust. There are incorrect lifetime-boundary definitions for RowMut::raw_slice and RowMut::raw_slice_mut.
ModificadaMedia (4.3)0.73%—Arxes-tolina18/3/202017/6/2026
arxes-tolina 3.0.0 allows User Enumeration.
ModificadaCrítica (9.6)1.3%—Arxes-tolina18/3/202017/6/2026
A CSV injection in arxes-tolina 3.0.0 allows malicious users to gain remote control of other computers. By entering formula code in the following columns: Kundennummer, Firma, Street, PLZ, Ort, Zahlziel, and Bemerkung, an attacker can create a user with a name that contains malicious code. Other users might download…
Orbitaley — Vulnerabilidades