Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
39 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.3) | 1.1% | — | Katacontainers Runtime | 10/6/2020 | 17/6/2026 | Kata Containers doesn't restrict containers from accessing the guest's root filesystem device. Malicious containers can exploit this to gain code execution on the guest and masquerade as the kata-agent. This issue affects Kata Containers 1.11 versions earlier than 1.11.1; Kata Containers 1.10 versions earlier than… | |
| Modificada | Alta (8.8) | 0.31% | — | Katacontainers Runtime | 19/5/2020 | 17/6/2026 | Kata Containers before 1.11.0 on Cloud Hypervisor persists guest filesystem changes to the underlying image file on the host. A malicious guest can overwrite the image file to gain control of all subsequent guest VMs. Since Kata Containers uses the same VM image file with all VMMs, this issue may also affect QEMU and… | |
| Modificada | Media (6.5) | 0.37% | — | Katacontainers Runtime | 19/5/2020 | 17/6/2026 | An improper link resolution vulnerability affects Kata Containers versions prior to 1.11.0. Upon container teardown, a malicious guest can trick the kata-runtime into unmounting any mount point on the host and all mount points underneath it, potentiality resulting in a host DoS. | |
| Modificada | Baja (3.3) | 0.28% | — | Katadigital M4S Firmware | 14/11/2019 | 17/6/2026 | The Kata M4s Android device with a build fingerprint of alps/full_hct6750_66_n/hct6750_66_n:7.0/NRD90M/1495624556:user/test-keys contains a pre-installed app with a package name of com.mediatek.factorymode app (versionCode=1, versionName=1) that allows unauthorized wireless settings modification via a confused deputy… | |
| Modificada | Alta (7.5) | 1.8% | — | K-takata Onigmo | 9/9/2019 | 17/6/2026 | Onigmo through 6.2.0 has an out-of-bounds read in parse_char_class because of missing codepoint validation in regenc.c. | |
| Modificada | Alta (7.5) | 2.1% | — | K-takata Onigmo | 9/9/2019 | 17/6/2026 | Onigmo through 6.2.0 has a NULL pointer dereference in onig_error_code_to_str because of fetch_token in regparse.c. | |
| Modificada | Alta (8.1) | 1.8% | — | Hakatashi Kindlegen | 1/6/2018 | 17/6/2026 | Kindlegen is a simple Node.js wrapper of the official kindlegen program. Kindlegen versions before 1.1.0 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if… | |
| Modificada | Alta (7.5) | 1.2% | — | Media-products Eros Webkatalog | 16/3/2010 | 16/6/2026 | SQL injection vulnerability in start.php in Eros Webkatalog allows remote attackers to execute arbitrary SQL commands via the id parameter in a rubrik action. | |
| Modificada | Media (6.8) | 1.8% | — | Katalog.hurricane Katalog Stron Hurricane | 22/2/2010 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/moderation.php in Katalog Stron Hurricane 1.3.5, and possibly earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the includes_directory parameter. | |
| Modificada | Alta (7.5) | 0.97% | — | Katalog.hurricane Katalog Stron Hurricane | 22/2/2010 | 16/6/2026 | SQL injection vulnerability in index.php in Katalog Stron Hurricane 1.3.5, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the get parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Katan WEB Server | 10/10/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Kantan WEB Server 1.8 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Alta (7.5) | 1.0% | — | Katalog Plyt Audio | 24/3/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in Katalog Plyt Audio 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fraza and (2) litera parameters, different vectors than CVE-2007-1612. NOTE: the provenance of this information is unknown; the details are obtained solely from… | |
| Modificada | Alta (7.5) | 1.2% | — | Katalog Plyt Audio | 23/3/2007 | 16/6/2026 | SQL injection vulnerability in index.php in Katalog Plyt Audio 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the kolumna parameter. | |
| Modificada | Media (4.3) | 1.0% | — | Nakata AN Httpd | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in AN HTTP 1.41d allows remote attackers to inject arbitrary web script or HTML via a colon (:) in the query string, which is inserted into the resulting error page. |