Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

50 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.54%—Wukongopensoource Wukong NocodeAI10/7/202417/6/2026
A vulnerability was found in WuKongOpenSource Wukong_nocode up to 20230807. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file ExpressionUtil.java of the component AviatorScript Handler. The manipulation leads to deserialization. The attack can be launched…
AplazadaMedia (6.3)0.32%—Kingkong BoardAI14/6/202417/6/2026
Missing Authorization vulnerability in Bryan Lee Kingkong Board.This issue affects Kingkong Board: from n/a through 2.1.0.2.
AnalizadaMedia (5.4)0.45%—Pantsel Konga14/5/202417/6/2026
Konga v0.14.9 is vulnerable to Cross Site Scripting (XSS) via the username parameter.
AnalizadaCrítica (9.8)4.9%—5kcrm Wukong CRM29/2/202414/7/2026
An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component.
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModificadaAlta (7.8)0.43%—Konghq Insomnia4/10/202317/6/2026
Kong Insomnia 2023.4.0 on macOS allows attackers to execute code and access restricted files, or make requests for TCC permissions, by using the DYLD_INSERT_LIBRARIES environment variable.
ModificadaCrítica (9.8)1.1%—Pantsel Konga16/8/202317/6/2026
An issue in Konga v0.14.9 allows attackers to bypass authentication via a crafted JWT token.
ModificadaMedia (6.5)1.1%—Konga Project Konga1/5/202317/6/2026
An issue discovered in Konga 0.14.9 allows remote attackers to manipulate user accounts regardless of privilege via crafted POST request.
ModificadaMedia (5.9)0.73%—Konghq Kong29/4/202317/6/2026
A vulnerability was found in Konga 2.8.3 on Kong. It has been classified as problematic. This affects an unknown part of the component Login API. The manipulation leads to insufficiently random values. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been…
ModificadaAlta (7.5)0.78%—Akindo-sushiro Hong Kong SushiroAkindo-sushiro Singapore SushiroAkindo-sushiro SushiroAkindo-sushiro Taiwan Sushiro+113/2/202317/6/2026
SUSHIRO App for Android outputs sensitive information to the log file, which may result in an attacker obtaining a credential information from the log file. Affected products/versions are as follows: SUSHIRO Ver.4.0.31, Thailand SUSHIRO Ver.1.0.0, Hong Kong SUSHIRO Ver.3.0.2, Singapore SUSHIRO Ver.2.0.0, and Taiwan…
ModificadaAlta (7.5)0.92%—Konghq Multipart12/2/202317/6/2026
A vulnerability was found in Kong lua-multipart 0.5.8-1. It has been declared as problematic. This vulnerability affects the function is_header of the file src/multipart.lua. The manipulation leads to inefficient regular expression complexity. Upgrading to version 0.5.9-1 is able to address this issue. The patch is…
ModificadaAlta (8.8)18%—72crm Wukong CRM10/1/202317/6/2026
72crm v9 was discovered to contain an arbitrary file upload vulnerability via the avatar upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaCrítica (9.8)1.2%—72crm Wukong CRM24/8/202217/6/2026
72crm 9.0 has an Arbitrary file upload vulnerability.
ModificadaAlta (8.8)1.1%—72crm Wukong CRM24/8/202217/6/2026
An issue was discovered in 72crm 9.0. There is a SQL Injection vulnerability in View the task calendar.
ModificadaAlta (8.8)10%💥 ExploitKonga Project Konga4/5/202217/6/2026
Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation.
ModificadaCrítica (9.8)1.4%—Kongchuanhujiao Project Kongchuanhujiao26/3/202117/6/2026
In github.com/kongchuanhujiao/server before version 1.3.21 there is an authentication Bypass by Primary Weakness vulnerability. All users are impacted. This is fixed in version 1.3.21.
ModificadaAlta (7.5)1.8%—Konghq Kong Gateway18/3/202117/6/2026
An improper access control vulnerability in the JWT plugin in Kong Gateway prior to 2.3.2.0 allows unauthenticated users access to authenticated routes without a valid token JWT.
ModificadaCrítica (9.8)2.2%—Kong Alpine Docker Image17/12/202017/6/2026
The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System using the kong docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
ModificadaCrítica (9.8)33%💥 ExploitKonghq Docker-kong12/4/202017/6/2026
An issue was discovered in docker-kong (for Kong) through 2.0.3. The admin API port may be accessible on interfaces other than 127.0.0.1. NOTE: The vendor argue that this CVE is not a vulnerability because it has an inaccurate bug scope and patch links. “1) Inaccurate Bug Scope - The issue scope was on Kong's…
ModificadaCrítica (9.8)1.8%—Kongtop D303 FirmwareKongtop D305 FirmwareKongtop D403 FirmwareKongtop A303 Firmware+18/5/201817/6/2026
KONGTOP DVR devices A303, A403, D303, D305, and D403 contain a backdoor that prints the login password via a Print_Password function call in certain circumstances.
ModificadaMedia (5.4)0.29%—Magzter Hong Kong Tatler Society19/10/201417/6/2026
The Hong Kong Tatler Society (aka com.magzter.hongkongtatlersociety) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.3)1.3%—Kong Inf0821/6/201316/6/2026
Cross-site scripting (XSS) vulnerability in the phptemplate_preprocess_node function in template.php in the Inf08 theme 6.x-1.x before 6.x-1.10 for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via a taxonomy vocabulary name.
ModificadaMedia (5)52%💥 ExploitWangkongbao Cns-1000Wangkongbao Cns-110017/7/201216/6/2026
Multiple directory traversal vulnerabilities in src/acloglogin.php in Wangkongbao CNS-1000 and 1100 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) lang or (2) langid cookie to port 85.
ModificadaMedia (4.3)1.1%—Tskynet Kongreg819/3/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Kongreg8 1.7.3 allow remote attackers to inject arbitrary web script or HTML via the (1) surname or (2) firstname parameters to modules/members/addmember.php; or (3) groupdescription or (4) groupname parameters to modules/groups/addgroupform.php.
ModificadaAlta (10)4.5%💥 ExploitZakongroup Openconf8/2/201216/6/2026
SQL injection vulnerability in author/edit.php in OpenConf 4.x before 4.12 allows remote attackers to execute arbitrary SQL commands via the pid parameter.
Orbitaley — Vulnerabilidades