Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
215 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.39% | — | Distribution Project Distribution | 6/4/2026 | 17/6/2026 | Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, in pull-through cache mode, distribution discovers token auth endpoints by parsing WWW-Authenticate challenges returned by the configured upstream registry. The realm URL from a bearer challenge is used without validating… | |
| Analizada | Alta (7.5) | 1.3% | — | Powerdns Dnsdist | 31/3/2026 | 25/7/2026 | An attacker might be able to trigger a use-after-free by sending crafted DNS queries to a DNSdist using the DNSQuestion:getEDNSOptions method in custom Lua code. In some cases DNSQuestion:getEDNSOptions might refer to a version of the DNS packet that has been modified, thus triggering a use-after-free and potentially… | |
| Analizada | Alta (7.5) | 1.5% | — | Powerdns Dnsdist | 31/3/2026 | 25/7/2026 | An attacker might be able to trigger an out-of-bounds write by sending crafted DNS responses to a DNSdist using the DNSQuestion:changeName or DNSResponse:changeName methods in custom Lua code. In some cases the rewritten packet might become larger than the initial response and even exceed 65535 bytes, potentially… | |
| Analizada | Alta (7.5) | 0.54% | — | Powerdns Dnsdist | 31/3/2026 | 25/7/2026 | An attacker might be able to trick DNSdist into allocating too much memory while processing DNS over QUIC or DNS over HTTP/3 payloads, resulting in a denial of service. In setups with a large quantity of memory available this usually results in an exception and the QUIC connection is properly closed, but in some cases… | |
| Analizada | Media (6.5) | 0.15% | — | Powerdns Dnsdist | 31/3/2026 | 25/7/2026 | When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using the nghttp2 provider, the ACL check is skipped, allowing all clients to send DoH queries regardless of the configured ACL. | |
| Analizada | Alta (8.2) | 1.0% | — | Powerdns Dnsdist | 31/3/2026 | 25/7/2026 | An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of-bounds read might trigger a crash, leading to a denial of service, or access unrelated memory, leading to potential information disclosure. | |
| Analizada | Media (4.3) | 0.16% | — | Powerdns Dnsdist | 31/3/2026 | 25/7/2026 | When the internal webserver is enabled (default is disabled), an attacker might be able to trick an administrator logged to the dashboard into visiting a malicious website and extract information about the running configuration from the dashboard. The root cause of the issue is a misconfiguration of the Cross-Origin… | |
| Analizada | Media (4.3) | 0.14% | — | Powerdns Dnsdist | 31/3/2026 | 25/7/2026 | An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNSdist instance where domain-based dynamic rules have been enabled via either DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI. | |
| Aplazada | Alta (7.1) | 0.21% | — | Codisto Omnichannel FOR WoocommerceAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codisto Omnichannel for WooCommerce codistoconnect allows Stored XSS.This issue affects Omnichannel for WooCommerce: from n/a through <= 1.3.65. | |
| Modificada | Crítica (10) | 0.33% | — | Eclipse Cyclone Data Distribution Service | 23/12/2025 | 5/7/2026 | Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute commands with System privileges. | |
| Aplazada | Alta (7.2) | 0.29% | — | Codisto Omnichannel FOR WoocommerceAI | 4/12/2025 | 17/6/2026 | The Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration – Powered by Codisto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sync() function in all versions up to, and including, 1.3.65 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (5.4) | 0.12% | — | Intel Distribution FOR PythonAI | 11/11/2025 | 17/6/2026 | Uncontrolled search path for some Intel(R) Distribution for Python software installers before version 2025.2.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege.… | |
| Aplazada | Baja (3.7) | 0.29% | — | Nghttp2AIPowerdns DnsdistAI | 18/9/2025 | 17/6/2026 | In some circumstances, when DNSdist is configured to use the nghttp2 library to process incoming DNS over HTTPS queries, an attacker might be able to cause a denial of service by crafting a DoH exchange that triggers an unbounded I/O read loop, causing an unexpected consumption of CPU resources. | |
| Aplazada | Media (5.4) | 0.11% | — | Intel Distribution FOR PythonAI | 12/8/2025 | 17/6/2026 | Incorrect default permissions for some Intel(R) Distribution for Python software installers before version 2025.1.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (5.5) | 0.54% | — | Fabian Food Distributor Site | 8/7/2025 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Food Distributor Site 1.0. This affects an unknown part of the file /admin/login.php. The manipulation of the argument Username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and… | |
| Analizada | Baja (1.9) | 0.36% | — | Fabian Food Distributor Site | 27/6/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in code-projects Food Distributor Site 1.0. Affected is an unknown function of the file /admin/save_settings.php. The manipulation of the argument site_phone/site_email/address leads to cross site scripting. It is possible to launch the attack remotely.… | |
| Analizada | Media (5.5) | 0.57% | — | Fabian Food Distributor Site | 27/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Food Distributor Site 1.0. This issue affects some unknown processing of the file /admin/process_login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Aplazada | Alta (8.5) | 0.36% | — | Wpdistillery Navigation Tree ElementorAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdistillery Navigation Tree Elementor navigation-tree-elementor allows Blind SQL Injection.This issue affects Navigation Tree Elementor: from n/a through <= 1.0.1. | |
| Aplazada | Alta (7.5) | 0.61% | — | Powerdns DnsdistAI | 20/5/2025 | 17/6/2026 | In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP connection from a client, an attacker can cause a denial of service by crafting a TCP exchange that triggers an exhaustion of the stack and a crash of DNSdist, causing a denial of service. The remedy is:… | |
| Aplazada | Media (5.4) | 0.33% | — | Ammarahmad786 Calculate Prices Based ON Distance FOR WoocommerceAI | 7/5/2025 | 17/6/2026 | Missing Authorization vulnerability in ammarahmad786 Calculate Prices based on Distance For WooCommerce calculate-prices-based-on-distance-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Calculate Prices based on Distance For WooCommerce: from n/a through <=… | |
| Aplazada | Alta (7.5) | 2.3% | — | Nghttp2AIH2OAIPowerdns DnsdistAI | 29/4/2025 | 17/6/2026 | When DNSdist is configured to provide DoH via the nghttp2 provider, an attacker can cause a denial of service by crafting a DoH exchange that triggers an illegal memory access (double-free) and crash of DNSdist, causing a denial of service. The remedy is: upgrade to the patched 1.9.9 version. A workaround is to… | |
| Analizada | Alta (8.8) | 0.95% | — | Eclipse Cyclone Data Distribution Service | 12/3/2025 | 17/6/2026 | An integer underflow during deserialization may allow any unauthenticated user to read out of bounds heap memory. This may result into secret data or pointers revealing the layout of the address space to be included into a deserialized data structure, which may potentially lead to thread crashes or cause denial of… | |
| Aplazada | Alta (7.5) | 0.37% | — | Maharashtra State Electricity Distribution Company Limited Mahavitran IOS ApplicationAI | 4/3/2025 | 17/6/2026 | Maharashtra State Electricity Distribution Company Limited Mahavitran IOS Application 16.1 application till version 16.1 communicates using the GET method to process requests that contain sensitive information such as user account name and password, which can expose that information through the browser's history,… | |
| Aplazada | Media (6.5) | 0.33% | — | Enituretechnology Distance Based Shipping CalculatorAI | 22/2/2025 | 17/6/2026 | Missing Authorization vulnerability in enituretechnology Distance Based Shipping Calculator distance-based-shipping-calculator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Distance Based Shipping Calculator: from n/a through <= 2.0.22. | |
| Aplazada | Alta (8.5) | 0.37% | — | Techspawn Distance Rate Shipping FOR WoocommerceAI | 18/2/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Techspawn Distance Rate Shipping for WooCommerce distance-rate-shipping-for-woocommerce-pro allows Blind SQL Injection.This issue affects Distance Rate Shipping for WooCommerce: from n/a through <= 1.3.4. |