Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1016 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (10) | 22% | — | Hikvision Integrated Security Management PlatformAIAlibaba FastjsonAI | 2/7/2025 | 17/6/2026 | An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger… | |
| Aplazada | Alta (7.1) | 0.26% | — | Regibaer Evangelische TermineAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in regibaer Evangelische Termine evangtermine allows Reflected XSS.This issue affects Evangelische Termine: from n/a through <= 3.3. | |
| Analizada | Media (5.4) | 0.44% | — | Elastic Kibana | 25/6/2025 | 17/6/2026 | URL redirection to an untrusted site ('Open Redirect') in Kibana can lead to sending a user to an arbitrary site and server-side request forgery via a specially crafted URL. | |
| Analizada | Alta (8.8) | 0.44% | — | Elastic Kibana | 10/6/2025 | 17/6/2026 | Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint. | |
| Analizada | Media (6.6) | 0.37% | — | LibarchiveRedhat Openshift Container PlatformRedhat Enterprise Linux | 9/6/2025 | 1/9/2026 | A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a… | |
| Modificada | Media (5) | 0.20% | — | LibarchiveRedhat Openshift Container PlatformRedhat Enterprise Linux | 9/6/2025 | 1/9/2026 | A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior,… | |
| Modificada | Media (5.6) | 0.18% | — | LibarchiveRedhat Openshift Container PlatformRedhat Enterprise Linux | 9/6/2025 | 1/9/2026 | A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading… | |
| Modificada | Media (6.6) | 0.19% | 💥 PoC | LibarchiveRedhat Openshift Container PlatformRedhat Enterprise Linux | 9/6/2025 | 1/9/2026 | A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in… | |
| Modificada | Alta (7.8) | 0.44% | — | LibarchiveRedhat Openshift Container PlatformRedhat Enterprise Linux | 9/6/2025 | 7/10/2026 | A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker… | |
| Aplazada | Media (4.7) | 0.21% | — | Ecovacs HomeAIAlibaba Object Storage ServiceAI | 23/5/2025 | 17/6/2026 | Ecovacs Home Android and iOS Mobile Applications up to version 3.3.0 contained embedded access keys and secrets for Alibaba Object Storage Service (OSS), leading to sensitive data disclosure. | |
| Modificada | Media (6.5) | 0.32% | — | Aomedia Libavif | 16/5/2025 | 17/6/2026 | In libavif before 1.3.0, avifImageRGBToYUV in reformat.c has integer overflows in multiplications involving rgbRowBytes, yRowBytes, uRowBytes, and vRowBytes. | |
| Modificada | Crítica (9.1) | 0.36% | — | Aomedia Libavif | 16/5/2025 | 17/6/2026 | In libavif before 1.3.0, makeRoom in stream.c has an integer overflow and resultant buffer overflow in stream->offset+size. | |
| Analizada | Media (5.3) | 0.36% | — | Pribai Privategpt | 10/5/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Zylon PrivateGPT up to 0.6.2. This affects an unknown part of the file settings.yaml. The manipulation of the argument allow_origins leads to permissive cross-domain policy with untrusted domains. It is possible to initiate the attack remotely. The… | |
| Analizada | Crítica (9.8) | 22% | 💥 PoC | Elastic Kibana | 6/5/2025 | 17/6/2026 | A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints. | |
| Analizada | Media (4.3) | 0.34% | — | Elastic Kibana | 1/5/2025 | 17/6/2026 | Unrestricted file upload in Kibana allows an authenticated attacker to compromise software integrity by uploading a crafted malicious file due to insufficient server-side validation. | |
| Analizada | Media (5.4) | 0.35% | — | Elastic Kibana | 1/5/2025 | 17/6/2026 | Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s browser (XSS) via crafted HTML and JavaScript files. The attacker must have access to the Synthetics app AND/OR have access to write to the synthetics indices. | |
| Aplazada | Media (5.4) | 0.22% | — | Wikimedia Mediawiki Wikibase Media Info ExtensionAI | 11/4/2025 | 17/6/2026 | Improper Input Validation vulnerability in The Wikimedia Foundation Mediawiki - Wikibase Media Info Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Wikibase Media Info Extension: from 1.39 through 1.43. | |
| Analizada | Crítica (9.8) | 0.54% | — | Elastic Kibana | 8/4/2025 | 17/6/2026 | Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined with path traversal. | |
| Analizada | Media (6.5) | 0.40% | — | Elastic Kibana | 8/4/2025 | 17/6/2026 | An issue has been identified where a specially crafted request sent to an Observability API could cause the kibana server to crash. A successful attack requires a malicious user to have read permissions for Observability assigned to them. | |
| Analizada | Alta (7.5) | 0.53% | — | Libarchive | 28/3/2025 | 17/6/2026 | Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pax_extension at rchive_read_support_format_tar.c:1844:8. | |
| Aplazada | Alta (7.1) | 0.18% | — | Mendibass Browser Address BAR ColorAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in mendibass Browser Address Bar Color browser-address-bar-color allows Stored XSS.This issue affects Browser Address Bar Color: from n/a through <= 3.3. | |
| Analizada | Crítica (9.8) | 0.62% | — | Martmbithi Ibanking | 20/3/2025 | 17/6/2026 | An arbitrary file upload vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary code via uploading a crafted PHP file. | |
| Analizada | Media (4.8) | 0.23% | — | Martmbithi Ibanking | 20/3/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter. | |
| Analizada | Media (6.1) | 0.35% | — | Pribai Privategpt | 20/3/2025 | 17/6/2026 | An XSS vulnerability was discovered in the upload file(s) process of imartinez/privategpt v0.5.0. Attackers can upload malicious SVG files, which execute JavaScript when victims click on the file link. This can lead to user data theft, session hijacking, malware distribution, and phishing attacks. | |
| Modificada | Alta (7.5) | 0.62% | — | Pribai Privategpt | 20/3/2025 | 17/6/2026 | A vulnerability in imartinez/privategpt version 0.5.0 allows for a Denial of Service (DOS) attack. When uploading a file, if an attacker appends a large number of characters to the end of a multipart boundary, the system will continuously process these characters, rendering privateGPT inaccessible. This uncontrolled… |