Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.18% | — | Mikeage Hebrew DateAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in mikeage Hebrew Date hebrewdates allows Stored XSS.This issue affects Hebrew Date: from n/a through <= 2.1.0. | |
| Aplazada | Alta (8.3) | 0.65% | — | Homebrew BrewAI | 31/7/2024 | 17/6/2026 | os/linux/elf.rb in Homebrew brew before 4.2.20 uses ldd to load ELF files obtained from untrusted sources, which allows attackers to achieve code execution via an ELF file with a custom .interp section. NOTE: this code execution would occur during an un-sandboxed binary relocation phase, which occurs before a user… | |
| Modificada | Crítica (9.8) | 0.99% | — | Homebrew JAN | 4/6/2024 | 17/6/2026 | An arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file. | |
| Modificada | Crítica (9.8) | 3.0% | — | Homebrew JAN | 4/6/2024 | 17/6/2026 | An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file. | |
| Modificada | Alta (7.5) | 2.1% | — | Homebrew JAN | 4/6/2024 | 17/6/2026 | Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface. | |
| Modificada | Crítica (9.8) | 1.6% | — | Librewireless LS9 Firmware | 3/5/2021 | 17/6/2026 | An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a Authentication Bypass in the Web Interface. This interface does not properly restrict access to internal functionality. Despite presenting a password login page on first access, authentication is not required to access privileged… | |
| Modificada | Crítica (9.8) | 1.8% | — | Librewireless LS9 Firmware | 3/5/2021 | 17/6/2026 | An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is Unauthenticated Root ADB Access Over TCP. The LS9 web interface provides functionality to access ADB over TCP. This is not enabled by default, but can be enabled by sending a crafted request to a web management interface endpoint. Requests… | |
| Modificada | Alta (7.5) | 1.2% | — | Librewireless LS9 Firmware | 3/5/2021 | 17/6/2026 | An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service GETPASS Configuration Password Information Leak. The luci_service daemon running on port 7777 does not require authentication to return the device configuration password in cleartext when using the GETPASS command. As such, any… | |
| Modificada | Alta (7.5) | 1.1% | — | Librewireless LS9 Firmware | 3/5/2021 | 17/6/2026 | An issue was discovered on Libre Wireless LS9 LS1.5/p7040 devices. There is a luci_service Read_ NVRAM Direct Access Information Leak. The luci_service deamon running on port 7777 provides a sub-category of commands for which Read_ is prepended. Commands in this category are able to directly read the contents of the… | |
| Modificada | Media (6.8) | 2.0% | — | Brewblogger | 6/8/2009 | 16/6/2026 | SQL injection vulnerability in the authenticateUser function in includes/authentication.inc.php in BrewBlogger (BB) 2.1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the loginUsername parameter to includes/logincheck.inc.php. NOTE: some of these details are… | |
| Modificada | Alta (7.8) | 1.6% | — | Brew City Software Flexlabel OCX | 11/5/2007 | 16/6/2026 | Unspecified vulnerability in the FlexLabel ActiveX control allows remote attackers to cause a denial of service (unstable behavior) via an improper initialization, as demonstrated by a certain value of the Caption property. | |
| Modificada | Alta (7.5) | 1.3% | — | Brewblogger | 14/11/2006 | 16/6/2026 | SQL injection vulnerability in printLog.php in BrewBlogger (BB) 1.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. |