Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

728 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.32%—Zhiyuan Yuedu Shuqi NovelAI27/1/202517/6/2026
An issue in Zhiyuan Yuedu (Guangzhou) Literature Information Technology Co., Ltd Shuqi Novel iOS 5.3.8 allows attackers to access sensitive user information via supplying a crafted link.
ModificadaCrítica (9.8)72%💥 PoCSamba RsyncAlmalinuxArchlinux Arch LinuxGentoo Linux+415/1/202529/6/2026
A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.
ModificadaAlta (7.5)4.7%—Samba RsyncRedhat DiscoveryRedhat Openshift Container PlatformRedhat Enterprise Linux+1614/1/202530/6/2026
A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory.
AplazadaCrítica (10)1.5%💥 PoCJoshua Wolfe THE Novel Design Store DirectoryAI11/11/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Joshua Wolfe The Novel Design Store Directory noveldesign-store-directory allows Upload a Web Shell to a Web Server.This issue affects The Novel Design Store Directory: from n/a through <= 4.3.0.
AnalizadaAlta (7.5)0.67%—Xxyopen Novel-plus30/4/202417/6/2026
Arbitrary File Read vulnerability in novel-plus 4.3.0 and before allows a remote attacker to obtain sensitive information via a crafted GET request using the filePath parameter.
AplazadaMedia (5.4)0.21%—Nosegraze NovelistAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Nose Graze Novelist.This issue affects Novelist: from n/a through 1.2.2.
AnalizadaCrítica (9.8)0.78%—Xxyopen Novel-plus20/2/202417/6/2026
An arbitrary file upload vulnerability in the component /sysFile/upload of Novel-Plus v4.3.0-RC1 allows attackers to execute arbitrary code via uploading a crafted file.
ModificadaCrítica (9.8)0.62%—Xxyopen Novel-plus8/2/202417/6/2026
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/userFeedback/list.
ModificadaCrítica (9.8)0.63%—Xxyopen Novel-plus8/2/202417/6/2026
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /common/dict/list
ModificadaCrítica (9.8)0.62%—Xxyopen Novel-plus8/2/202417/6/2026
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /novel/author/list
ModificadaCrítica (9.8)0.69%—Xxyopen Novel-plus8/2/202417/6/2026
An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions at com.java2nb.system.controller.SysUserController: uploadImg(). An attacker can pass in specially crafted filename parameter to perform arbitrary File download.
ModificadaCrítica (9.8)0.65%—Xxyopen Novel-plus8/2/202417/6/2026
An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: upload(). An attacker can pass in specially crafted filename parameter to perform arbitrary File download.
ModificadaCrítica (9.8)0.65%—Xxyopen Novel-plus8/2/202417/6/2026
An arbitrary File download vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: fileDownload(). An attacker can pass in specially crafted filePath and fieName parameters to perform arbitrary File download.
ModificadaCrítica (9.8)0.62%—Xxyopen Novel-plus8/2/202417/6/2026
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/bookContent/list.
ModificadaCrítica (9.8)0.61%—Xxyopen Novel-plus8/2/202417/6/2026
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL injection via /system/dataPerm/list
ModificadaCrítica (9.8)0.59%—Xxyopen Novel-plus7/2/202417/6/2026
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL injection via /system/roleDataPerm/list
ModificadaCrítica (9.8)0.61%—Xxyopen Novel-plus6/2/202417/6/2026
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL via /sys/user/exit
ModificadaCrítica (9.8)0.59%—Xxyopen Novel-plus6/2/202417/6/2026
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /novel/pay/list
ModificadaMedia (6.8)0.73%💥 PoCAlpha-innotec Heat Pumps FirmwareNovelan Heat Pumps Firmware30/1/202417/6/2026
An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execute arbitrary code via the password component in the shadow file.
ModificadaCrítica (9.8)0.68%—Xxyopen Novel-plus26/1/202417/6/2026
A vulnerability was found in Novel-Plus 4.3.0-RC1 and classified as critical. This issue affects some unknown processing of the file /novel/bookComment/list. The manipulation of the argument sort leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-252185 was…
ModificadaCrítica (9.8)0.71%—Xxyopen Novel-plus18/1/202417/6/2026
A vulnerability has been found in Novel-Plus 4.3.0-RC1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /novel/bookSetting/list. The manipulation of the argument sort leads to sql injection. The exploit has been disclosed to the public and may be used. The associated…
ModificadaMedia (4.8)0.53%—Xxyopen Novel-plus29/12/202317/6/2026
A vulnerability was found in Novel-Plus up to 4.2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file novel-admin/src/main/java/com/java2nb/novel/controller/FriendLinkController.java of the component Friendly Link Handler. The manipulation leads to cross site…
ModificadaMedia (5.4)0.55%—Xxyopen Novel-plus29/12/202317/6/2026
A vulnerability classified as problematic has been found in Novel-Plus up to 4.2.0. This affects an unknown part of the file /user/updateUserInfo of the component HTTP POST Request Handler. The manipulation of the argument nickName leads to cross site scripting. It is possible to initiate the attack remotely. The…
ModificadaMedia (5.4)0.43%—Porternovelli Widget Settings Importer/exporter23/12/202317/6/2026
The Widget Settings Importer/Exporter Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wp_ajax_import_widget_dataparameter AJAX action in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with…
ModificadaCrítica (9.8)1.1%—Xxyopen Novel-plus5/11/202317/6/2026
SQL injection vulnerability in Novel-Plus v.4.2.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /common/log/list.
Orbitaley — Vulnerabilidades