Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
728 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.32% | — | Zhiyuan Yuedu Shuqi NovelAI | 27/1/2025 | 17/6/2026 | An issue in Zhiyuan Yuedu (Guangzhou) Literature Information Technology Co., Ltd Shuqi Novel iOS 5.3.8 allows attackers to access sensitive user information via supplying a crafted link. | |
| Modificada | Crítica (9.8) | 72% | 💥 PoC | Samba RsyncAlmalinuxArchlinux Arch LinuxGentoo Linux+4 | 15/1/2025 | 29/6/2026 | A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer. | |
| Modificada | Alta (7.5) | 4.7% | — | Samba RsyncRedhat DiscoveryRedhat Openshift Container PlatformRedhat Enterprise Linux+16 | 14/1/2025 | 30/6/2026 | A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory. | |
| Aplazada | Crítica (10) | 1.5% | 💥 PoC | Joshua Wolfe THE Novel Design Store DirectoryAI | 11/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Joshua Wolfe The Novel Design Store Directory noveldesign-store-directory allows Upload a Web Shell to a Web Server.This issue affects The Novel Design Store Directory: from n/a through <= 4.3.0. | |
| Analizada | Alta (7.5) | 0.67% | — | Xxyopen Novel-plus | 30/4/2024 | 17/6/2026 | Arbitrary File Read vulnerability in novel-plus 4.3.0 and before allows a remote attacker to obtain sensitive information via a crafted GET request using the filePath parameter. | |
| Aplazada | Media (5.4) | 0.21% | — | Nosegraze NovelistAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Nose Graze Novelist.This issue affects Novelist: from n/a through 1.2.2. | |
| Analizada | Crítica (9.8) | 0.78% | — | Xxyopen Novel-plus | 20/2/2024 | 17/6/2026 | An arbitrary file upload vulnerability in the component /sysFile/upload of Novel-Plus v4.3.0-RC1 allows attackers to execute arbitrary code via uploading a crafted file. | |
| Modificada | Crítica (9.8) | 0.62% | — | Xxyopen Novel-plus | 8/2/2024 | 17/6/2026 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/userFeedback/list. | |
| Modificada | Crítica (9.8) | 0.63% | — | Xxyopen Novel-plus | 8/2/2024 | 17/6/2026 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /common/dict/list | |
| Modificada | Crítica (9.8) | 0.62% | — | Xxyopen Novel-plus | 8/2/2024 | 17/6/2026 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /novel/author/list | |
| Modificada | Crítica (9.8) | 0.69% | — | Xxyopen Novel-plus | 8/2/2024 | 17/6/2026 | An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions at com.java2nb.system.controller.SysUserController: uploadImg(). An attacker can pass in specially crafted filename parameter to perform arbitrary File download. | |
| Modificada | Crítica (9.8) | 0.65% | — | Xxyopen Novel-plus | 8/2/2024 | 17/6/2026 | An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: upload(). An attacker can pass in specially crafted filename parameter to perform arbitrary File download. | |
| Modificada | Crítica (9.8) | 0.65% | — | Xxyopen Novel-plus | 8/2/2024 | 17/6/2026 | An arbitrary File download vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: fileDownload(). An attacker can pass in specially crafted filePath and fieName parameters to perform arbitrary File download. | |
| Modificada | Crítica (9.8) | 0.62% | — | Xxyopen Novel-plus | 8/2/2024 | 17/6/2026 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/bookContent/list. | |
| Modificada | Crítica (9.8) | 0.61% | — | Xxyopen Novel-plus | 8/2/2024 | 17/6/2026 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL injection via /system/dataPerm/list | |
| Modificada | Crítica (9.8) | 0.59% | — | Xxyopen Novel-plus | 7/2/2024 | 17/6/2026 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL injection via /system/roleDataPerm/list | |
| Modificada | Crítica (9.8) | 0.61% | — | Xxyopen Novel-plus | 6/2/2024 | 17/6/2026 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL via /sys/user/exit | |
| Modificada | Crítica (9.8) | 0.59% | — | Xxyopen Novel-plus | 6/2/2024 | 17/6/2026 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /novel/pay/list | |
| Modificada | Media (6.8) | 0.73% | 💥 PoC | Alpha-innotec Heat Pumps FirmwareNovelan Heat Pumps Firmware | 30/1/2024 | 17/6/2026 | An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execute arbitrary code via the password component in the shadow file. | |
| Modificada | Crítica (9.8) | 0.68% | — | Xxyopen Novel-plus | 26/1/2024 | 17/6/2026 | A vulnerability was found in Novel-Plus 4.3.0-RC1 and classified as critical. This issue affects some unknown processing of the file /novel/bookComment/list. The manipulation of the argument sort leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-252185 was… | |
| Modificada | Crítica (9.8) | 0.71% | — | Xxyopen Novel-plus | 18/1/2024 | 17/6/2026 | A vulnerability has been found in Novel-Plus 4.3.0-RC1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /novel/bookSetting/list. The manipulation of the argument sort leads to sql injection. The exploit has been disclosed to the public and may be used. The associated… | |
| Modificada | Media (4.8) | 0.53% | — | Xxyopen Novel-plus | 29/12/2023 | 17/6/2026 | A vulnerability was found in Novel-Plus up to 4.2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file novel-admin/src/main/java/com/java2nb/novel/controller/FriendLinkController.java of the component Friendly Link Handler. The manipulation leads to cross site… | |
| Modificada | Media (5.4) | 0.55% | — | Xxyopen Novel-plus | 29/12/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in Novel-Plus up to 4.2.0. This affects an unknown part of the file /user/updateUserInfo of the component HTTP POST Request Handler. The manipulation of the argument nickName leads to cross site scripting. It is possible to initiate the attack remotely. The… | |
| Modificada | Media (5.4) | 0.43% | — | Porternovelli Widget Settings Importer/exporter | 23/12/2023 | 17/6/2026 | The Widget Settings Importer/Exporter Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wp_ajax_import_widget_dataparameter AJAX action in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with… | |
| Modificada | Crítica (9.8) | 1.1% | — | Xxyopen Novel-plus | 5/11/2023 | 17/6/2026 | SQL injection vulnerability in Novel-Plus v.4.2.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /common/log/list. |