Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
5178 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.25% | — | Atakanau Automatically Hierarchic Categories IN MenuAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atakan Au Automatically Hierarchic Categories in Menu automatically-hierarchic-categories-in-menu allows Stored XSS.This issue affects Automatically Hierarchic Categories in Menu: from n/a through <= 2.0.5. | |
| Aplazada | Alta (7.5) | 0.51% | — | Exthemes WP Timeline Vertical AND Horizontal TimelineAI | 5/10/2024 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Ex-Themes WP Timeline – Vertical and Horizontal timeline plugin wp-timelines.This issue affects WP Timeline – Vertical and Horizontal timeline plugin: from n/a through <= 3.6.7. | |
| Analizada | Alta (8.8) | 0.58% | — | Canonical Authd | 3/10/2024 | 17/6/2026 | Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM operation with it, including authenticating as them. | |
| Analizada | Media (5.5) | 0.21% | — | Canonical Juju | 2/10/2024 | 17/6/2026 | Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available without authentication locally to network namespace users. This enables denial of service attacks. | |
| Analizada | Media (6.5) | 0.19% | — | Canonical Juju | 2/10/2024 | 17/6/2026 | Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the default network namespace may connect to the @/var/lib/juju/agents/unit-xxxx-yyyy/agent.socket and perform actions that are normally reserved to a juju charm. | |
| Analizada | Alta (8) | 0.50% | — | Canonical Juju | 2/10/2024 | 17/6/2026 | JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace can connect to an abstract domain socket and guess the JUJU_CONTEXT_ID value. This gives the unprivileged user access to the same… | |
| Analizada | Baja (3.5) | 0.33% | — | Clinical-genomics Scout | 30/9/2024 | 17/6/2026 | Scout is a web-based visualizer for VCF-files. Due to the lack of sanitization in the filename, it is possible bypass intended file extension and make users download malicious files with any extension. With malicious content injected inside the file data and users unknowingly downloading it and opening may lead to the… | |
| Analizada | Media (6.1) | 0.39% | — | Clinical-genomics Scout | 30/9/2024 | 17/6/2026 | Scout is a web-based visualizer for VCF-files. Open redirect vulnerability allows performing phishing attacks on users by redirecting them to malicious page. /login API endpoint is vulnerable to open redirect attack via next parameter due to absence of sanitization logic. Additionally, due to lack of scheme… | |
| Analizada | Alta (7.5) | 0.18% | — | Canonical Anbox Cloud | 18/9/2024 | 17/6/2026 | Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent. An attacker must be able to machine-in-the-middle the Anbox Stream Agent from within an internal network before they can attempt to take advantage of this. | |
| Modificada | Media (6.5) | 0.27% | — | Eaton Foreseer Electrical Power Monitoring System | 13/9/2024 | 17/6/2026 | The Eaton Foreseer software provides multiple customizable input fields for the users to configure parameters in the tool like alarms, reports, etc. Some of these input fields were not checking the length and bounds of the entered value. The exploit of this security flaw by a bad actor may result in excessive memory… | |
| Modificada | Alta (8.1) | 0.12% | — | Eaton Foreseer Electrical Power Monitoring System | 13/9/2024 | 17/6/2026 | The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, user management, etc. The software uses encryption to store these configurations securely on the host machine. However, the keys used for this encryption were insecurely… | |
| Analizada | Media (6.1) | 0.29% | — | Eaton Foreseer Electrical Power Monitoring System | 13/9/2024 | 17/6/2026 | The Eaton Foreseer software provides users the capability to customize the dashboard in WebView pages. However, the input fields for this feature in the Eaton Foreseer software lacked proper input sanitization on the server-side, which could lead to injection and execution of malicious scripts when abused by bad… | |
| Aplazada | Media (5.4) | 0.35% | — | Swissphone Dical-red 4009AI | 22/8/2024 | 17/6/2026 | Swissphone DiCal-RED 4009 devices allow an unauthenticated attacker use a port-2101 TCP connection to gain access to operation messages that are received by the device. | |
| Aplazada | Crítica (9.8) | 0.98% | — | Swissphone Dical-red 4009AI | 22/8/2024 | 17/6/2026 | Swissphone DiCal-RED 4009 devices allow a remote attacker to gain a root shell via TELNET without authentication. | |
| Aplazada | Alta (8.1) | 0.51% | — | Swissphone Dical-red 4009AI | 22/8/2024 | 17/6/2026 | cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an unauthenticated attacker to gain access to device logs. | |
| Aplazada | Alta (8.8) | 0.74% | — | Swissphone Dical-red 4009AI | 22/8/2024 | 17/6/2026 | cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an authenticated attacker to gain access to arbitrary files on the device's file system. | |
| Aplazada | Media (6.8) | 0.29% | — | Swissphone Dical-red 4009AI | 22/8/2024 | 17/6/2026 | An issue was discovered on Swissphone DiCal-RED 4009 devices. An attacker with access to the file /etc/deviceconfig may recover the administrative device password via password-cracking methods, because unsalted MD5 is used. | |
| Aplazada | Crítica (9.4) | 0.88% | — | Swissphone Dical-red 4009AI | 22/8/2024 | 17/6/2026 | Swissphone DiCal-RED 4009 devices allow a remote attacker to gain access to the administrative web interface via the device password's hash value, without knowing the actual device password. | |
| Aplazada | Alta (7.6) | 0.61% | — | Swissphone Dical-red 4009AI | 22/8/2024 | 17/6/2026 | Swissphone DiCal-RED 4009 devices allow a remote attacker to gain read access to almost the whole file system via anonymous FTP. | |
| Analizada | Alta (7.8) | 0.21% | — | Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+7 | 20/8/2024 | 17/6/2026 | A maliciously crafted DWF file, when parsed in AdDwfPdk.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | |
| Modificada | Baja (3.8) | 0.38% | — | Canonical Juju | 29/7/2024 | 17/6/2026 | An issue was discovered in Juju that resulted in the leak of the sensitive context ID, which allows a local unprivileged attacker to access other sensitive data or relation accessible to the local charm. | |
| Modificada | Alta (7.3) | 0.23% | — | Canonical Snapd | 25/7/2024 | 17/6/2026 | In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap. The snap format is a squashfs file-system image and so can contain symbolic links and other file types. Various file entries within the snap squashfs image (such as icons and desktop files etc) are… | |
| Modificada | Media (6.6) | 0.21% | — | Canonical Snapd | 25/7/2024 | 17/6/2026 | In snapd versions prior to 2.62, snapd failed to properly check the file type when extracting a snap. The snap format is a squashfs file-system image and so can contain files that are non-regular files (such as pipes or sockets etc). Various file entries within the snap squashfs image (such as icons etc) are directly… | |
| Modificada | Alta (8.2) | 0.31% | — | Canonical Snapd | 25/7/2024 | 17/6/2026 | In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict writes to the $HOME/bin path. In Ubuntu, when this path exists, it is automatically added to the users PATH. An attacker who could convince a user to install a malicious snap which used the 'home' plug… | |
| Analizada | Alta (7.8) | 0.26% | — | Canonical Ubuntu Desktop Provision | 23/7/2024 | 17/6/2026 | An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate their privilege. |