Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

41 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.8%—Linagora Hublin23/7/201917/6/2026
LINAGORA hublin latest (commit 72ead897082403126bf8df9264e70f0a9de247ff) is affected by: Directory Traversal. The impact is: The vulnerability allows an attacker to access any file (with a fixed extension) on the server. The component is: A web-view renderer; details here:…
ModificadaAlta (7.5)6.0%—Shellinabox Project Shellinabox21/3/201917/6/2026
libhttp/url.c in shellinabox through 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a crafted multipart/form-data HTTP request, an attacker could exploit this to force shellinaboxd into an infinite loop, exhausting available CPU resources and taking the service down.
ModificadaMedia (5.5)0.66%—Huawei Agassi-l09 FirmwareHuawei Agassi-w09 FirmwareHuawei Baggio2-u01a FirmwareHuawei Bond-al00c Firmware+1526/9/201817/6/2026
Some Huawei products Agassi-L09 AGS-L09C100B257CUSTC100D001, AGS-L09C170B253CUSTC170D001, AGS-L09C199B251CUSTC199D001, AGS-L09C229B003CUSTC229D001, Agassi-W09 AGS-W09C100B257CUSTC100D001, AGS-W09C128B252CUSTC128D001, AGS-W09C170B252CUSTC170D001, AGS-W09C229B251CUSTC229D001, AGS-W09C331B003CUSTC331D001,…
ModificadaAlta (8.8)2.5%—Linaro LavaDebian Linux19/6/201817/6/2026
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of yaml.safe_load() when parsing user data, remote code execution can occur.
ModificadaMedia (6.5)1.5%—Linaro LavaDebian Linux19/6/201817/6/2026
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that will force lava-server-gunicorn to return any file on the server that is readable by lavaserver and valid yaml.
ModificadaMedia (6.5)0.89%—Linaro Lava19/6/201817/6/2026
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for file: URLs, a user can force lava-server-gunicorn to download any file from the filesystem if it's readable by lavaserver and valid yaml.
ModificadaMedia (5.9)1.6%—Linaro Op-tee2/1/201817/6/2026
Linaro's open source TEE solution called OP-TEE, version 2.4.0 (and older) is vulnerable a timing attack in the Montgomery parts of libMPA in OP-TEE resulting in a compromised private RSA key.
ModificadaAlta (7.5)1.9%—Linaro Op-tee2/1/201817/6/2026
Linaro's open source TEE solution called OP-TEE, version 2.4.0 (and older) is vulnerable to the bellcore attack in the LibTomCrypt code resulting in compromised private RSA key.
ModificadaMedia (5.9)0.49%—Meafinancial Oculina Mobile Banking16/6/201717/6/2026
The "Oculina Mobile Banking" by Oculina Bank app 3.0.0 -- aka oculina-mobile-banking/id867025690 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.4)2.0%—Fedoraproject FedoraShellinabox Project Shellinabox12/1/201617/6/2026
The HTTPS fallback implementation in Shell In A Box (aka shellinabox) before 2.19 makes it easier for remote attackers to conduct DNS rebinding attacks via the "/plain" URL.
ModificadaAlta (7.5)1.2%—Lina Wolf SEO Pack FOR TT News27/6/201316/6/2026
SQL injection vulnerability in the SEO Pack for tt_news extension before 1.3.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (6.8)2.0%💥 ExploitCelina Jorge Facil CMS8/9/200916/6/2026
Multiple directory traversal vulnerabilities in Facil CMS 0.1RC allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) change_lang parameter to index.php or (2) modload parameter to modules.php.
ModificadaMedia (5)8.1%💥 ExploitSmolinari Mini WEB Calendar13/11/200816/6/2026
Directory traversal vulnerability in php/cal_pdf.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers to read arbitrary files via directory traversal sequences in the thefile parameter.
ModificadaMedia (4.3)3.5%💥 ExploitSmolinari Mini WEB Calendar13/11/200816/6/2026
Cross-site scripting (XSS) vulnerability in php/cal_default.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers to inject arbitrary web script or HTML via the URL.
ModificadaAlta (7.2)1.6%💥 ExploitJacques Gelinas Linuxconf2/4/200316/6/2026
Buffer overflow in Linuxconf before 1.28r4 allows local users to execute arbitrary code via a long LINUXCONF_LANG environment variable, which overflows an error string that is generated.
ModificadaAlta (7.5)2.5%—Jacques Gelinas Linuxconf12/11/200216/6/2026
The mailconf module in Linuxconf 1.24, and other versions before 1.28, on Conectiva Linux 6.0 through 8, and possibly other distributions, generates the Sendmail configuration file (sendmail.cf) in a way that configures Sendmail to run as an open mail relay, which allows remote attackers to send Spam email.
Orbitaley — Vulnerabilidades