Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
230 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.82% | 💥 PoC | Archive Tainacan CollectionAI | 16/4/2024 | 17/6/2026 | The archive-tainacan-collection theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in version 2.7.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can… | |
| Aplazada | Media (6.5) | 0.36% | — | SAP Group Reporting Data CollectionAISAP Enter Package Data APPAI | 9/4/2024 | 17/6/2026 | SAP Group Reporting Data Collection does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, specific data can be changed via the Enter Package Data app although the user does not have sufficient authorization causing high impact on… | |
| Analizada | Baja (2.5) | 0.22% | — | Iovisor BPF Compiler Collection | 10/3/2024 | 17/6/2026 | If kernel headers need to be extracted, bcc will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default. | |
| Modificada | Crítica (9.8) | 0.52% | — | Oduyo Online Collection | 9/2/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oduyo Financial Technology Online Collection allows SQL Injection. This issue affects Online Collection: before v.1.0.2. | |
| Modificada | Media (4.4) | 2.6% | — | PostgresqlRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little Endian EUSRedhat Codeready Linux Builder FOR Arm64 EUS+12 | 10/12/2023 | 17/6/2026 | A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific… | |
| Modificada | Alta (8.8) | 4.3% | — | PostgresqlRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little Endian EUSRedhat Codeready Linux Builder FOR Arm64 EUS+17 | 10/12/2023 | 17/6/2026 | A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remote user can trigger the overflow by providing specially crafted data.… | |
| Modificada | Media (4.3) | 2.8% | — | PostgresqlRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little Endian EUSRedhat Codeready Linux Builder FOR Arm64 EUS+12 | 10/12/2023 | 23/6/2026 | A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without type designation can disclose bytes, potentially revealing notable… | |
| Modificada | Alta (7.5) | 0.97% | 💥 PoC | Themeisle Cloud Templates & Patterns Collection | 23/11/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ThemeIsle Cloud Templates & Patterns collection.This issue affects Cloud Templates & Patterns collection: from n/a through 1.2.2. | |
| Modificada | Media (5.5) | 0.37% | — | PHPRedhat Software CollectionsRedhat Enterprise Linux | 2/11/2023 | 17/6/2026 | A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow. | |
| Modificada | Alta (8.8) | 0.21% | — | Profosbox AGP Font Awesome Collection | 16/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Alexey Golubnichenko AGP Font Awesome Collection plugin <= 3.2.4 versions. | |
| Analizada | Alta (7.5) | 0.55% | — | Espeak-ng Espeak NGMcl-collection Mcl-net Firmware | 11/10/2023 | 17/6/2026 | Directory traversal vulnerability in MCL-Net versions prior to 4.6 Update Package (P01) may allow attackers to read arbitrary files. | |
| Modificada | Alta (7.8) | 0.25% | — | Redhat Ansible Automation PlatformRedhat Ansible Collection | 4/10/2023 | 17/6/2026 | A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the log files, compromising the system's confidentiality, integrity, and availability. | |
| Modificada | Alta (8.8) | 1.7% | — | PostgresqlRedhat Software CollectionsRedhat Enterprise LinuxDebian Linux | 11/8/2023 | 30/9/2026 | IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE… | |
| Modificada | Media (6.1) | 0.38% | — | Profosbox AGP Font Awesome Collection | 10/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Alexey Golubnichenko AGP Font Awesome Collection plugin <= 3.2.4 versions. | |
| Modificada | Crítica (9.8) | 0.63% | — | Oduyo Online Collection | 8/8/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oduyo Online Collection Software allows SQL Injection. This issue affects Online Collection Software: before 1.0.1. | |
| Modificada | Crítica (9.8) | 2.3% | 💥 PoC | ONS RAS Collection Instrument | 18/7/2023 | 17/6/2026 | A vulnerability was found in ONS Digital RAS Collection Instrument up to 2.0.27 and classified as critical. Affected by this issue is the function jobs of the file .github/workflows/comment.yml. The manipulation of the argument $COMMENT_BODY leads to os command injection. Upgrading to version 2.0.28 is able to address… | |
| Modificada | Alta (8.8) | 0.94% | — | Zenstruck Collection | 14/7/2023 | 17/6/2026 | zenstruck/collections is a set of helpers for iterating/paginating/filtering collections. Passing _callable strings_ (ie `system`) caused the function to be executed. This would result in a limited subset of specific user input being executed as if it were code. This issue has been addressed in commit `f4b1c48820` and… | |
| Modificada | Crítica (9.8) | 0.63% | — | Vegagroup WEB Collection | 13/7/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VegaGroup Web Collection allows SQL Injection. This issue affects Web Collection: before 31197. | |
| Modificada | Media (5.3) | 4.0% | 💥 Exploit | Mcl-collection Mcl-net Firmware | 29/6/2023 | 17/6/2026 | A Directory Browsing vulnerability in MCL-Net version 4.3.5.8788 webserver running on default port 5080, allows attackers to gain sensitive information about the configured databases via the "/file" endpoint. | |
| Modificada | Media (5.4) | 0.69% | — | PostgresqlRedhat Software CollectionsRedhat Enterprise LinuxFedoraproject Fedora | 9/6/2023 | 17/6/2026 | Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or… | |
| Modificada | Alta (7.2) | 1.2% | — | PostgresqlRedhat Software CollectionsRedhat Enterprise LinuxFedoraproject Fedora | 9/6/2023 | 17/6/2026 | schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated database-level privileges to execute arbitrary code. | |
| Modificada | Media (6.5) | 1.8% | — | HaproxyRedhat Ceph StorageRedhat Software CollectionsRedhat Openshift Container Platform+5 | 23/3/2023 | 17/6/2026 | An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability. | |
| Modificada | Alta (7.5) | 1.2% | — | Collection.js Project Collection.js | 18/3/2023 | 17/6/2026 | Versions of the package collection.js before 6.8.1 are vulnerable to Prototype Pollution via the extend function in Collection.js/dist/node/iterators/extend.js. | |
| Modificada | Alta (8.6) | 1.2% | — | C-ares Project C-aresRedhat Software CollectionsRedhat Enterprise LinuxFedoraproject Fedora | 6/3/2023 | 17/6/2026 | A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity. | |
| Modificada | Media (5.4) | 0.51% | — | Revenue Collection System Project Revenue Collection System | 27/1/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in /index.php?page=help of Revenue Collection System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into sent messages. |