Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
50 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.54% | — | Wukongopensoource Wukong NocodeAI | 10/7/2024 | 17/6/2026 | A vulnerability was found in WuKongOpenSource Wukong_nocode up to 20230807. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file ExpressionUtil.java of the component AviatorScript Handler. The manipulation leads to deserialization. The attack can be launched… | |
| Aplazada | Media (6.3) | 0.32% | — | Kingkong BoardAI | 14/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Bryan Lee Kingkong Board.This issue affects Kingkong Board: from n/a through 2.1.0.2. | |
| Analizada | Media (5.4) | 0.45% | — | Pantsel Konga | 14/5/2024 | 17/6/2026 | Konga v0.14.9 is vulnerable to Cross Site Scripting (XSS) via the username parameter. | |
| Analizada | Crítica (9.8) | 4.9% | — | 5kcrm Wukong CRM | 29/2/2024 | 14/7/2026 | An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Alta (7.8) | 0.43% | — | Konghq Insomnia | 4/10/2023 | 17/6/2026 | Kong Insomnia 2023.4.0 on macOS allows attackers to execute code and access restricted files, or make requests for TCC permissions, by using the DYLD_INSERT_LIBRARIES environment variable. | |
| Modificada | Crítica (9.8) | 1.1% | — | Pantsel Konga | 16/8/2023 | 17/6/2026 | An issue in Konga v0.14.9 allows attackers to bypass authentication via a crafted JWT token. | |
| Modificada | Media (6.5) | 1.1% | — | Konga Project Konga | 1/5/2023 | 17/6/2026 | An issue discovered in Konga 0.14.9 allows remote attackers to manipulate user accounts regardless of privilege via crafted POST request. | |
| Modificada | Media (5.9) | 0.73% | — | Konghq Kong | 29/4/2023 | 17/6/2026 | A vulnerability was found in Konga 2.8.3 on Kong. It has been classified as problematic. This affects an unknown part of the component Login API. The manipulation leads to insufficiently random values. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been… | |
| Modificada | Alta (7.5) | 0.78% | — | Akindo-sushiro Hong Kong SushiroAkindo-sushiro Singapore SushiroAkindo-sushiro SushiroAkindo-sushiro Taiwan Sushiro+1 | 13/2/2023 | 17/6/2026 | SUSHIRO App for Android outputs sensitive information to the log file, which may result in an attacker obtaining a credential information from the log file. Affected products/versions are as follows: SUSHIRO Ver.4.0.31, Thailand SUSHIRO Ver.1.0.0, Hong Kong SUSHIRO Ver.3.0.2, Singapore SUSHIRO Ver.2.0.0, and Taiwan… | |
| Modificada | Alta (7.5) | 0.92% | — | Konghq Multipart | 12/2/2023 | 17/6/2026 | A vulnerability was found in Kong lua-multipart 0.5.8-1. It has been declared as problematic. This vulnerability affects the function is_header of the file src/multipart.lua. The manipulation leads to inefficient regular expression complexity. Upgrading to version 0.5.9-1 is able to address this issue. The patch is… | |
| Modificada | Alta (8.8) | 18% | — | 72crm Wukong CRM | 10/1/2023 | 17/6/2026 | 72crm v9 was discovered to contain an arbitrary file upload vulnerability via the avatar upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Crítica (9.8) | 1.2% | — | 72crm Wukong CRM | 24/8/2022 | 17/6/2026 | 72crm 9.0 has an Arbitrary file upload vulnerability. | |
| Modificada | Alta (8.8) | 1.1% | — | 72crm Wukong CRM | 24/8/2022 | 17/6/2026 | An issue was discovered in 72crm 9.0. There is a SQL Injection vulnerability in View the task calendar. | |
| Modificada | Alta (8.8) | 10% | 💥 Exploit | Konga Project Konga | 4/5/2022 | 17/6/2026 | Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation. | |
| Modificada | Crítica (9.8) | 1.4% | — | Kongchuanhujiao Project Kongchuanhujiao | 26/3/2021 | 17/6/2026 | In github.com/kongchuanhujiao/server before version 1.3.21 there is an authentication Bypass by Primary Weakness vulnerability. All users are impacted. This is fixed in version 1.3.21. | |
| Modificada | Alta (7.5) | 1.8% | — | Konghq Kong Gateway | 18/3/2021 | 17/6/2026 | An improper access control vulnerability in the JWT plugin in Kong Gateway prior to 2.3.2.0 allows unauthenticated users access to authenticated routes without a valid token JWT. | |
| Modificada | Crítica (9.8) | 2.2% | — | Kong Alpine Docker Image | 17/12/2020 | 17/6/2026 | The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System using the kong docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 33% | 💥 Exploit | Konghq Docker-kong | 12/4/2020 | 17/6/2026 | An issue was discovered in docker-kong (for Kong) through 2.0.3. The admin API port may be accessible on interfaces other than 127.0.0.1. NOTE: The vendor argue that this CVE is not a vulnerability because it has an inaccurate bug scope and patch links. “1) Inaccurate Bug Scope - The issue scope was on Kong's… | |
| Modificada | Crítica (9.8) | 1.8% | — | Kongtop D303 FirmwareKongtop D305 FirmwareKongtop D403 FirmwareKongtop A303 Firmware+1 | 8/5/2018 | 17/6/2026 | KONGTOP DVR devices A303, A403, D303, D305, and D403 contain a backdoor that prints the login password via a Print_Password function call in certain circumstances. | |
| Modificada | Media (5.4) | 0.29% | — | Magzter Hong Kong Tatler Society | 19/10/2014 | 17/6/2026 | The Hong Kong Tatler Society (aka com.magzter.hongkongtatlersociety) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.3% | — | Kong Inf08 | 21/6/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the phptemplate_preprocess_node function in template.php in the Inf08 theme 6.x-1.x before 6.x-1.10 for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via a taxonomy vocabulary name. | |
| Modificada | Media (5) | 52% | 💥 Exploit | Wangkongbao Cns-1000Wangkongbao Cns-1100 | 17/7/2012 | 16/6/2026 | Multiple directory traversal vulnerabilities in src/acloglogin.php in Wangkongbao CNS-1000 and 1100 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) lang or (2) langid cookie to port 85. | |
| Modificada | Media (4.3) | 1.1% | — | Tskynet Kongreg8 | 19/3/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Kongreg8 1.7.3 allow remote attackers to inject arbitrary web script or HTML via the (1) surname or (2) firstname parameters to modules/members/addmember.php; or (3) groupdescription or (4) groupname parameters to modules/groups/addgroupform.php. | |
| Modificada | Alta (10) | 4.5% | 💥 Exploit | Zakongroup Openconf | 8/2/2012 | 16/6/2026 | SQL injection vulnerability in author/edit.php in OpenConf 4.x before 4.12 allows remote attackers to execute arbitrary SQL commands via the pid parameter. |