Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
43 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.37% | — | Hydra BookingAI | 29/7/2025 | 17/6/2026 | The Hydra Booking plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the tfhb_reset_password_callback() function in versions 1.1.0 to 1.1.18. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset the password of an… | |
| Aplazada | Media (4.8) | 0.30% | — | Cardano HydraAI | 19/6/2025 | 17/6/2026 | Hydra is a layer-two scalability solution for Cardano. Prior to version 0.22.0, the process assumes L1 event finality and does not consider failed transactions. Currently, Cardano L1 is monitored for certain events which are necessary for state progression. At the moment, Hydra considers those events as finalized as… | |
| Aplazada | Alta (8.5) | 0.32% | — | Themefic Hydra BookingAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Booking hydra-booking allows SQL Injection.This issue affects Hydra Booking: from n/a through <= 1.1.10. | |
| Analizada | Baja (2.6) | 0.31% | — | Nixos Hydra | 15/4/2025 | 17/6/2026 | Hydra is a Continuous Integration service for Nix based projects. Evaluation of untrusted non-flake nix code could potentially access secrets that are accessible by the hydra user/group. This should not affect the signing keys, that are owned by the hydra-queue-runner and hydra-www users respectively. | |
| Analizada | Alta (7.5) | 0.62% | — | Nixos Hydra | 27/8/2024 | 17/6/2026 | Hydra is a Continuous Integration service for Nix based projects. It is possible to trigger evaluations in Hydra without any authentication. Depending on the size of evaluations, this can impact the availability of systems. The problem can be fixed by applying… | |
| Analizada | Media (5.4) | 0.47% | — | Nixos Hydra | 22/4/2024 | 17/6/2026 | Hydra is a Continuous Integration service for Nix based projects. Attackers can execute arbitrary code in the browser context of Hydra and execute authenticated HTTP requests. The abused feature allows Nix builds to specify files that Hydra serves to clients. One use of this functionality is serving NixOS `.iso`… | |
| Modificada | Alta (8.1) | 1.1% | — | Iohk Hydra | 4/10/2023 | 17/6/2026 | Hydra is the two-layer scalability solution for Cardano. Prior to version 0.13.0, it is possible for a malicious head initializer to extract one or more PTs for the head they are initializing due to incorrect data validation logic in the head token minting policy which then results in an flawed check for burning the… | |
| Modificada | Alta (8.1) | 0.98% | — | Iohk Hydra | 4/10/2023 | 17/6/2026 | Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, the specification states that the contestation period in the datum of the UTxO at the head validator must stay unchanged as the state progresses from Open to Closed (Close transaction), but no such check appears to be performed in the… | |
| Modificada | Crítica (9.1) | 1.1% | — | Iohk Hydra | 4/10/2023 | 17/6/2026 | Hydra is the layer-two scalability solution for Cardano. Users of the Hydra head protocol send the UTxOs they wish to commit into the Hydra head first to the `commit` validator, where they remain until they are either collected into the `head` validator or the protocol initialisation is aborted and the value in the… | |
| Modificada | Media (6.5) | 0.52% | — | Iohk Hydra | 21/9/2023 | 17/6/2026 | Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, not signing and verifying `$\mathsf{cid}$` allows an attacker (which must be a participant of this head) to use a snapshot from an old head instance with the same participants to close the head or contest the state with it. This can lead… | |
| Modificada | Media (5.3) | 1.0% | — | ORY Hydra | 6/4/2020 | 17/6/2026 | In Hydra (an OAuth2 Server and OpenID Certified™ OpenID Connect Provider written in Go), before version 1.4.0+oryOS.17, when using client authentication method 'private_key_jwt' [1], OpenId specification says the following about assertion `jti`: "A unique identifier for the token, which can be used to prevent reuse of… | |
| Modificada | Alta (7.5) | 1.7% | — | Hydra Project Hydra | 12/10/2019 | 17/6/2026 | Hydra through 0.1.8 has a NULL pointer dereference and daemon crash when processing POST requests that lack a Content-Length header. read.c, request.c, and util.c contribute to this. The process_header_end() function calls boa_atoi(), which ultimately calls atoi() on a NULL pointer. | |
| Modificada | Media (6.1) | 1.3% | — | ORY Hydra | 17/2/2019 | 17/6/2026 | ORY Hydra before v1.0.0-rc.3+oryOS.9 has Reflected XSS via the oauth2/fallbacks/error error_hint parameter. | |
| Modificada | Media (5) | 2.7% | — | GE Hydran M2 | 14/3/2015 | 17/6/2026 | The 17046 Ethernet card before 94450214LFMT100SEM-L.R3-CL for the GE Digital Energy Hydran M2 does not properly generate random values for TCP Initial Sequence Numbers (ISNs), which makes it easier for remote attackers to spoof packets by predicting these values. | |
| Modificada | Alta (10) | 62% | — | HP Lefthand P4000 Virtual SAN ApplianceHP Lefthand Virtual SAN Appliance HydraHP Lefthand Virtual SAN Appliance Hydra Software | 2/7/2013 | 16/6/2026 | Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1510. | |
| Modificada | Media (5) | 7.1% | — | Hydrairc | 10/8/2008 | 16/6/2026 | HydraIRC 0.3.164 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a long irc:// URI. | |
| Modificada | Alta (7.8) | 1.6% | — | Hydrairc | 17/7/2007 | 16/6/2026 | Format string vulnerability in HydraIRC 0.3.151 allows remote attackers to cause a denial of service via format string specifiers in certain data related to failed DCC file transfer negotiation. | |
| Modificada | Alta (7.8) | 1.4% | — | Hydrairc | 17/7/2007 | 16/6/2026 | Heap-based buffer overflow in HydraIRC 0.3.151 allows remote IRC servers to cause a denial of service (application crash) via a long CTCP request message containing '%' (percent) characters. |