Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
171 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.26% | — | NodejsAIElectronAIWesterndigital WD DiscoveryAI | 2/8/2024 | 17/6/2026 | WD Discovery versions prior to 5.0.589 contain a misconfiguration in the Node.js environment settings that could allow code execution by utilizing the 'ELECTRON_RUN_AS_NODE' environment variable. Any malicious application operating with standard user permissions can exploit this vulnerability, enabling code execution… | |
| Aplazada | Alta (7.4) | 0.31% | — | Projectdiscovery NucleiAI | 17/7/2024 | 17/6/2026 | Nuclei is a fast and customizable vulnerability scanner based on simple YAML based DSL. In affected versions it a way to execute code template without -code option and signature has been discovered. Some web applications inherit from Nuclei and allow users to edit and execute workflow files. In this case, users can… | |
| Aplazada | Media (5.3) | 0.41% | — | Steeltoe Discovery EurekaAI | 17/7/2024 | 17/6/2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build production-grade cloud-native applications using externalized configuration, service discovery, distributed tracing, application management, and more. When utilizing multiple Eureka server service URLs with basic auth and… | |
| Modificada | Crítica (9.3) | 0.63% | — | Projectdiscovery Interactsh | 5/6/2024 | 17/6/2026 | Files or Directories Accessible to External Parties vulnerability in smb server in ProjectDiscovery Interactsh allows remote attackers to read/write any files in the directory and subdirectories of where the victim runs interactsh-server via anonymous login. | |
| Analizada | Alta (7.4) | 0.41% | — | Projectdiscovery Nuclei | 15/3/2024 | 17/6/2026 | projectdiscovery/nuclei is a fast and customisable vulnerability scanner based on simple YAML based DSL. A significant security oversight was identified in Nuclei v3, involving the execution of unsigned code templates through workflows. This vulnerability specifically affects users utilizing custom workflows,… | |
| Analizada | Alta (7.2) | 0.68% | — | Veritas Ediscovery Platform | 22/2/2024 | 17/6/2026 | A vulnerability was discovered in Veritas eDiscovery Platform before 10.2.5. The application administrator can upload potentially malicious files to arbitrary locations on the server on which the application is installed. | |
| Analizada | Alta (7.2) | 0.79% | — | Atlassian Assets Discovery Data Center | 20/2/2024 | 17/6/2026 | This High severity Injection vulnerability was introduced in Assets Discovery 1.0 - 6.2.0 (all versions). Assets Discovery, which can be downloaded via Atlassian Marketplace, is a network scanning tool that can be used with or without an agent with Jira Service Management Cloud, Data Center or Server. It detects… | |
| Modificada | Alta (8.8) | 0.30% | — | IBM Tivoli Application Dependency Discovery Manager | 2/2/2024 | 17/6/2026 | IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 could allow an attacker on the organization's local network to escalate their privileges due to unauthorized API access. IBM X-Force ID: 270267. | |
| Modificada | Media (6.1) | 0.35% | — | IBM Tivoli Application Dependency Discovery Manager | 2/2/2024 | 17/6/2026 | IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM… | |
| Modificada | Crítica (9.8) | 0.78% | — | IBM Tivoli Application Dependency Discovery Manager | 2/2/2024 | 17/6/2026 | IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or… | |
| Modificada | Media (5.3) | 0.49% | — | Consensys Discovery | 19/1/2024 | 14/7/2026 | Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session. which should ideally be unique for every message. The node's private key isn't compromised, only the session key generated for specific peer communication is exposed. | |
| Modificada | Alta (8.8) | 1.2% | 💥 PoC | Knovos Discovery | 16/1/2024 | 17/6/2026 | SQL injection vulnerability in Knovos Discovery v.22.67.0 allows a remote attacker to execute arbitrary code via the /DiscoveryProcess/Service/Admin.svc/getGridColumnStructure component. | |
| Modificada | Media (6.5) | 0.80% | 💥 PoC | Knovos Discovery | 16/1/2024 | 17/6/2026 | An issue in Knovos Discovery v.22.67.0 allows a remote attacker to obtain sensitive information via the /DiscoveryReview/Service/CaseManagement.svc/GetProductSiteName component. | |
| Modificada | Media (5.9) | 94% | 💥 Exploit | Openbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+64 | 18/12/2023 | 17/6/2026 | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some… | |
| Modificada | Alta (8.8) | 11% | — | Atlassian Assets Discovery CloudAtlassian Assets Discovery Data CenterAtlassian Assets Discovery Data Server | 6/12/2023 | 17/6/2026 | This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with the Assets Discovery agent installed. The vulnerability exists between the Assets Discovery application (formerly known as Insight Discovery) and the Assets Discovery agent. | |
| Modificada | Alta (7.5) | 1.0% | — | Projectdiscovery Nuclei | 4/8/2023 | 17/6/2026 | Nuclei is a vulnerability scanner. Prior to version 2.9.9, a security issue in the Nuclei project affected users utilizing Nuclei as Go code (SDK) running custom templates. This issue did not affect CLI users. The problem was related to sanitization issues with payload loading in sandbox mode. There was a potential… | |
| Modificada | Media (6.1) | 0.54% | — | Projectdiscovery Interactsh | 28/6/2023 | 17/6/2026 | Interactsh is an open-source tool for detecting out-of-band interactions. Domains configured with interactsh server prior to version 1.0.0 were vulnerable to subdomain takeover for a specific subdomain, i.e `app.` Interactsh server used to create cname entries for `app` pointing to `projectdiscovery.github.io` as… | |
| Modificada | Alta (7.5) | 0.65% | — | Lightbend Akka ActorLightbend Akka Discovery | 11/5/2023 | 17/6/2026 | In Lightbend Akka before 2.8.1, the async-dns resolver (used by Discovery in DNS mode and transitively by Cluster Bootstrap) uses predictable DNS transaction IDs when resolving DNS records, making DNS resolution subject to poisoning by an attacker. If the application performing discovery does not validate (e.g., via… | |
| Modificada | Media (6.1) | 0.48% | — | Ualberta Neosdiscovery | 5/3/2023 | 17/6/2026 | A vulnerability was found in ualbertalib NEOSDiscovery 1.0.70 and classified as problematic. This issue affects some unknown processing of the file app/views/bookmarks/_refworks.html.erb. The manipulation leads to use of web link to untrusted target with window.opener access. The attack may be initiated remotely.… | |
| Modificada | Crítica (9.8) | 1.9% | — | Force1rc Discovery Wifi U818a HD+ FPV Firmware | 6/12/2022 | 17/6/2026 | Buffer overflow in firmware lewei_cam binary version 2.0.10 in Force 1 Discovery Wifi U818A HD+ FPV Drone allows attacker to gain remote code execution as root user via a specially crafted UDP packet. Please update the Reference section to these links > http://thiscomputer.com/ > https://www.bostoncyber.org/ >… | |
| Modificada | Alta (7.8) | 0.18% | — | Opcfoundation Local Discovery Server | 17/11/2022 | 17/6/2026 | OPC Foundation Local Discovery Server (LDS) through 1.04.403.478 uses a hard-coded file path to a configuration file. This allows a normal user to create a malicious file that is loaded by LDS (running as a high-privilege user). | |
| Modificada | Alta (7.5) | 0.73% | — | Nepxion Discovery | 24/9/2022 | 17/6/2026 | Nepxion Discovery is a solution for Spring Cloud. Discovery is vulnerable to a potential Server-Side Request Forgery (SSRF). RouterResourceImpl uses RestTemplate’s getForEntity to retrieve the contents of a URL containing user-controlled input, potentially resulting in Information Disclosure. There is no patch… | |
| Modificada | Crítica (9.8) | 2.3% | — | Nepxion Discovery | 24/9/2022 | 17/6/2026 | Nepxion Discovery is a solution for Spring Cloud. Discover is vulnerable to SpEL Injection in discovery-commons. DiscoveryExpressionResolver’s eval method is evaluating expression with a StandardEvaluationContext, allowing the expression to reach and interact with Java classes such as java.lang.Runtime, leading to… | |
| Modificada | Media (5.3) | 0.20% | — | Westerndigital WD Discovery | 19/9/2022 | 17/6/2026 | WD Discovery software executable files were signed with an unsafe SHA-1 hashing algorithm. An attacker could use this weakness to create forged certificate signatures due to the use of a hashing algorithm that is not collision-free. This could thereby impact the confidentiality of user content. This issue affects:… | |
| Modificada | Crítica (9.8) | 67% | 💥 PoC | Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+24 | 18/1/2022 | 17/6/2026 | By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or… |