Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
247 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.24% | — | Leefish File Thingie | 20/3/2026 | 17/6/2026 | File Thingie 2.5.7 is vulnerable to Cross Site Scripting (XSS). A malicious user can leverage the "upload file" functionality to upload a file with a crafted file name used to trigger a Javascript payload. | |
| Analizada | Media (6.5) | 0.24% | — | Leefish File Thingie | 20/3/2026 | 17/6/2026 | File Thinghie 2.5.7 is vulnerable to Cross Site Scripting (XSS). A malicious user can leverage the "dir" parameter of the GET request to invoke arbitrary javascript code. | |
| Analizada | Crítica (9.3) | 0.90% | — | Leefish File Thingie | 11/3/2026 | 17/6/2026 | FileThingie 2.5.7 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files by sending ZIP archives through the ft2.php endpoint. Attackers can upload ZIP files containing PHP shells, use the unzip functionality to extract them into accessible directories, and execute arbitrary… | |
| Aplazada | Alta (8.1) | 0.58% | — | DAN Fisher AlchemistsAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in dan_fisher Alchemists alchemists allows PHP Local File Inclusion.This issue affects Alchemists: from n/a through <= 4.6.0. | |
| Aplazada | Alta (8.8) | 0.34% | — | Starfish Review Generation AND MarketingAI | 13/2/2026 | 17/6/2026 | The Starfish Review Generation & Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'srm_restore_options_defaults' function in all versions up to, and including, 3.1.19. This makes it possible… | |
| Analizada | Baja (1.9) | 0.29% | — | Happyfish100 Libfastcommon | 6/2/2026 | 17/6/2026 | A security vulnerability has been detected in happyfish100 libfastcommon up to 1.0.84. Affected by this vulnerability is the function base64_decode of the file src/base64.c. The manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed publicly… | |
| Aplazada | Alta (7.1) | 0.24% | — | Fishing Reservation SystemAI | 3/2/2026 | 17/6/2026 | Fishing Reservation System 7.5 contains multiple remote SQL injection vulnerabilities in admin.php, cart.php, and calendar.php that allow attackers to inject malicious SQL commands. Attackers can exploit vulnerable parameters like uid, pid, type, m, y, and code to compromise the database management system and web… | |
| Aplazada | Media (5.3) | 0.42% | — | Sheepfish Webp ConversionAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in sheepfish WebP Conversion webp-conversion allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebP Conversion: from n/a through <= 2.2. | |
| Analizada | Crítica (9.4) | 0.58% | — | Leefish File Thingie | 18/12/2025 | 17/6/2026 | File Thingie 2.5.7 contains an authenticated file upload vulnerability that allows remote attackers to upload malicious PHP zip archives to the web server. Attackers can create a custom PHP payload, upload and unzip it, and then execute arbitrary system commands through a crafted PHP script with a command parameter. | |
| Analizada | Alta (8.8) | 0.76% | — | Thermofisher Torrent Suite Software | 4/12/2025 | 17/6/2026 | An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. The /configure/plugins/plugin/upload/zip/ and /configure/newupdates/offline/bundle/upload/ endpoints allow low-privilege users to upload ZIP files to the server. The plupload_file_upload function handles these file uploads and… | |
| Analizada | Alta (7.2) | 0.81% | — | Thermofisher Torrent Suite Software | 4/12/2025 | 17/6/2026 | An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. A remote code execution vulnerability exists in the network configuration functionality, stemming from insufficient input validation when processing network configuration parameters through administrative endpoints. The application… | |
| Analizada | Alta (7.8) | 0.15% | — | Thermofisher Torrent Suite Software | 4/12/2025 | 17/6/2026 | An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. One of the middlewares included in this application, LocalhostAuthMiddleware, authenticates users as ionadmin if the REMOTE_ADDR property in request.META is set to 127.0.0.1, to 127.0.1.1, or to ::1. Any user with local access to the… | |
| Analizada | Crítica (9.8) | 0.50% | — | Thermofisher ION Torrent Onetouch 2 Firmware | 4/12/2025 | 17/6/2026 | An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. When they are powered on, an X11 display server is started. The display server listens on all network interfaces and is accessible over port 6000. The X11 access control list, by default, allows connections from 127.0.0.1 and… | |
| Analizada | Crítica (9.8) | 0.39% | — | Thermofisher Torrent Suite Software | 4/12/2025 | 17/6/2026 | The Thermo Fisher Torrent Suite Django application 5.18.1 has weak default credentials, which are stored as fixtures for the Django ORM API. The ionadmin user account can be used to authenticate to default deployments with the password ionadmin. The user guide recommends changing default credentials; however, a… | |
| Analizada | Crítica (9.8) | 0.46% | — | Thermofisher ION Torrent Onetouch 2 Firmware | 4/12/2025 | 17/6/2026 | An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. They run an SSH server accessible over the default port 22. The root account has a weak default password of ionadmin, and a password change policy for the root account is not enforced. Thus, an attacker with network connectivity can… | |
| Aplazada | Alta (8.7) | 0.92% | — | Rainbowfishsoftware Pacsone ServerAI | 10/11/2025 | 17/6/2026 | PacsOne Server version 6.6.2 (prior versions are likely affected) contains a directory traversal vulnerability within the web-based DICOM viewer component. Successful exploitation allows a remote unauthenticated attacker to read arbitrary files via the 'nocache.php' endpoint with a crafted 'path' parameter.… | |
| Aplazada | Media (5) | 0.27% | — | OpenbmcAIDmtf RedfishAI | 23/9/2025 | 17/6/2026 | Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to use certain special characters in manipulated Redfish® API commands, causing service processes like OpenBMC to crash and reset, potentially resulting in denial of service. | |
| Aplazada | Media (6.5) | 0.21% | — | Codefish Pinterest Pinboard WidgetAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codefish Pinterest Pinboard Widget pinterest-pinboard-widget allows Stored XSS.This issue affects Pinterest Pinboard Widget: from n/a through <= 1.0.7. | |
| Aplazada | Alta (8.5) | 0.22% | — | Thermo Fisher Scientific EportAI | 18/8/2025 | 17/6/2026 | Thermo Fisher Scientific ePort through 3.0.0 has Incorrect Access Control. | |
| Analizada | Alta (8.9) | 0.32% | — | Eclipse Glassfish | 16/7/2025 | 17/6/2026 | In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints. | |
| Analizada | Media (6.1) | 0.24% | — | Eclipse Glassfish | 16/7/2025 | 17/6/2026 | In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console. | |
| Modificada | Media (6.3) | 0.44% | — | Eclipse Glassfish | 16/7/2025 | 18/6/2026 | In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts. GlassFish 8.0.3 adds automatic attack protection documented in https://glassfish.org/docs/latest/security-guide.html#brute-force-attack-protection . | |
| Analizada | Media (6.1) | 0.22% | — | Eclipse Glassfish | 16/7/2025 | 17/6/2026 | In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console. | |
| Analizada | Media (5.8) | 0.17% | — | Eclipse Glassfish | 16/7/2025 | 17/6/2026 | In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site Scripting attacks by modifying the configuration file in the underlying operating system. | |
| Analizada | Media (4.5) | 0.22% | — | Eclipse Glassfish | 16/7/2025 | 17/6/2026 | In Eclipse GlassFish version 7.0.15 is possible to perform Reflected Cross-site scripting attacks in the Administration Console. |