Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.82% | — | Frangoteam Fuxa | 3/2/2026 | 17/6/2026 | FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks authentication mechanisms, allowing unauthenticated remote attackers to upload arbitrary files. This can be exploited to overwrite critical system files (such as the SQLite user database) to gain… | |
| Modificada | Crítica (9.8) | 2.2% | 💥 Exploit | Frangoteam Fuxa | 3/2/2026 | 17/6/2026 | FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-coded secret key to sign and verify JWT Tokens. This allows remote attackers to forge valid admin tokens and bypass authentication to gain full administrative access. | |
| Analizada | Crítica (9.3) | 0.52% | — | Frangoteam Fuxa | 3/2/2026 | 17/6/2026 | FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' flag is commented out by default, causing the application to initialize with authentication disabled. This allows unauthenticated remote attackers to access sensitive API endpoints, modify projects,… | |
| Modificada | Crítica (9.8) | 26% | 💥 PoC | Frangoteam Fuxa | 22/9/2023 | 17/6/2026 | FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin. | |
| Modificada | Alta (7.5) | 1.7% | 💥 PoC | Frangoteam Fuxa | 22/9/2023 | 17/6/2026 | FUXA <= 1.1.12 is vulnerable to Local via Inclusion via /api/download. | |
| Modificada | Alta (7.5) | 1.8% | 💥 PoC | Frangoteam Fuxa | 22/9/2023 | 17/6/2026 | A SQL Injection attack in FUXA <= 1.1.12 allows exfiltration of confidential information from the database. | |
| Modificada | Alta (7.5) | 1.4% | 💥 PoC | Frangoteam Fuxa | 22/9/2023 | 17/6/2026 | FUXA <= 1.1.12 has a Local File Inclusion vulnerability via file=fuxa.log | |
| Modificada | Crítica (9.8) | 26% | 💥 Exploit | Frangoteam Fuxa | 18/9/2023 | 17/6/2026 | A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request. | |
| Modificada | Alta (7.5) | 1.5% | — | Frangoteam Fuxa | 16/3/2022 | 17/6/2026 | A Server-Side Request Forgery (SSRF) attack in FUXA 1.1.3 can be carried out leading to the obtaining of sensitive information from the server's internal environment and services, often potentially leading to the attacker executing commands on the server. |