Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.26% | — | Elfsight Testimonials SliderAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elfsight Elfsight Testimonials Slider elfsight-testimonials-slider allows Stored XSS.This issue affects Elfsight Testimonials Slider: from n/a through <= 1.0.1. | |
| Aplazada | Media (5.4) | 0.32% | — | Elfsight Testimonials SliderAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in elfsight Elfsight Testimonials Slider elfsight-testimonials-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elfsight Testimonials Slider: from n/a through <= 1.0.1. | |
| Aplazada | Alta (7.5) | 2.3% | 💥 Exploit | Tar-fsAI | 27/3/2025 | 17/6/2026 | An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal"). This vulnerability occurs when extracting a maliciously crafted tar file, which can result in unauthorized file writes or overwrites outside the intended extraction… | |
| Analizada | Alta (8.8) | 0.24% | — | Fs-code Booknetic | 26/3/2025 | 17/6/2026 | The Booknetic WordPress plugin before 4.1.5 does not have CSRF check when creating Staff accounts, which could allow attackers to make logged in admin add arbitrary Staff members via a CSRF attack | |
| Aplazada | Media (5.9) | 0.21% | — | Cifs-utilsAI | 25/3/2025 | 17/6/2026 | A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to the wrong namespace in containerized environments. This issue may lead to disclosing sensitive data from the host's Kerberos credentials cache. | |
| Analizada | Media (5) | 0.87% | — | Apache Commons VFS | 23/3/2025 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS. The FtpFileObject class can throw an exception when a file is not found, revealing the original URI in its message, which may include a password. The fix is to mask the password in the exception message This issue affects… | |
| Modificada | Alta (7.5) | 1.4% | — | Apache Commons VFS | 23/3/2025 | 17/6/2026 | Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0. The FileObject API in Commons VFS has a 'resolveFile' method that takes a 'scope' parameter. Specifying 'NameScope.DESCENDENT' promises that "an exception is thrown if the resolved file is not a descendent of the base file". However, when the… | |
| Aplazada | Media (6.8) | 0.16% | — | Ntfs ToolsAI | 18/3/2025 | 17/6/2026 | Insecure information storage vulnerability in NTFS Tools version 3.5.1. Exploitation of this vulnerability could allow an attacker to know the application password, stored in /Users/user/Library/Application Support/ntfs-tool/config.json. | |
| Aplazada | Alta (8.8) | 0.97% | — | Fujitsu Fs010mAI | 18/3/2025 | 17/6/2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M versions prior to V2.0.1_1101. If this vulnerability is exploited, an arbitrary OS command may be executed by a remote authenticated attacker. | |
| Aplazada | Alta (7.2) | 1.0% | — | Fujifilm Fs010mAI | 18/3/2025 | 17/6/2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M versions prior to V2.0.0_1101. If this vulnerability is exploited, an arbitrary OS command may be executed by a remote authenticated attacker with an administrative privilege. | |
| Aplazada | Alta (7.1) | 0.97% | 💥 PoC | FS INC S3150-8t2fAI | 17/3/2025 | 5/7/2026 | FS Inc S3150-8T2F prior to version S3150-8T2F_2.2.0D_135103 is vulnerable to Cross Site Scripting (XSS) in the Time Range Configuration functionality of the administration interface. An attacker can inject malicious JavaScript into the "Time Range Name" field, which is improperly sanitized. When this input is saved,… | |
| Aplazada | Alta (8.5) | 0.33% | — | Fs-code FS PosterAI | 15/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in fs-code FS Poster fs-poster.This issue affects FS Poster: from n/a through <= 6.5.8. | |
| Analizada | Media (5.4) | 0.24% | — | FS S3150-8t2f Firmware | 13/3/2025 | 17/6/2026 | A stored cross-site scripting vulnerability exists in FS model S3150-8T2F switches running firmware s3150-8t2f-switch-fsos-220d_118101 and web firmware v2.2.2, which allows an authenticated web interface user to bypass input filtering on user names, and stores un-sanitized HTML and Javascript on the device. Pages… | |
| Aplazada | Media (4.3) | 0.24% | — | FS RBDAI | 11/3/2025 | 17/6/2026 | An authenticated user with low privileges can exploit a missing authorization check in an IBS module of FS-RBD, allowing unauthorized access to perform actions beyond their intended permissions. This causes a low impact on integrity with no impact on confidentiality and availability. | |
| Analizada | Alta (7.8) | 0.12% | — | Qualcomm Qcn6224 FirmwareQualcomm Qcn6274 FirmwareQualcomm Qcn6402 FirmwareQualcomm Qcn6412 Firmware+149 | 3/3/2025 | 17/6/2026 | Memory corruption while processing command in Glink linux. | |
| Analizada | Alta (8.1) | 1.5% | — | Zohocorp Manageengine Adselfservice Plus | 3/3/2025 | 17/6/2026 | Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug. | |
| Aplazada | Media (4.3) | 0.16% | — | Fs-code BookneticAI | 25/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in fs-code Booknetic booknetic.This issue affects Booknetic: from n/a through <= 4.0.9. | |
| Aplazada | Media (6.5) | 0.45% | — | LakefsAI | 21/2/2025 | 17/6/2026 | lakeFS is an open-source tool that transforms your object storage into a Git-like repository. In affected versions an authenticated user can crash lakeFS by exhausting server memory. This is an authenticated denial-of-service issue. This problem has been patched in version 1.50.0. Users on versions 1.49.1 and below… | |
| Aplazada | Media (6.4) | 0.33% | — | Coaching StaffsAI | 19/2/2025 | 17/6/2026 | The Coaching Staffs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mstw-cs-table' shortcode in all versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.9) | 0.22% | — | Elfsight Yottie-liteAI | 13/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elfsight Elfsight Yottie Lite yottie-lite allows Stored XSS.This issue affects Elfsight Yottie Lite: from n/a through <= 1.3.3. | |
| Aplazada | Alta (7.8) | 0.19% | — | Nothing Tech Nothing OSAINothing Tech NtbpfserviceAI | 12/2/2025 | 17/6/2026 | An issue in Nothing Tech Nothing OS v.2.6 allows a local attacker to escalate privileges via the NtBpfService component. | |
| Aplazada | Media (6) | 0.43% | — | FreebsdAICd9660AITarfsAIExt2fsAI | 30/1/2025 | 17/6/2026 | On 64-bit systems, the implementation of VOP_VPTOFH() in the cd9660, tarfs and ext2fs filesystems overflows the destination FID buffer by 4 bytes, a stack buffer overflow. A NFS server that exports a cd9660, tarfs, or ext2fs file system can be made to panic by mounting and accessing the export with an NFS client.… | |
| Aplazada | Alta (8.5) | 1.1% | — | GIT LFSAI | 14/1/2025 | 17/6/2026 | Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it passes portions of the host's URL to the `git-credential(1)` command without checking for embedded line-ending control characters, and then sends any credentials it receives back from the Git… | |
| Analizada | Media (6.5) | 0.46% | — | Dell Powerscale Onefs | 8/1/2025 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.2.x through 9.9.0.0 contain an uncontrolled resource consumption vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to denial of service. | |
| Analizada | Media (5.5) | 0.13% | — | Dell Powerscale Onefs | 6/1/2025 | 17/6/2026 | Dell PowerScale OneFS 8.2.2.x through 9.8.0.x contains an incorrect permission assignment for critical resource vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading to denial of service. |