Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
52 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.38% | — | Akbim Panon | 3/4/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Akbim Computer Panon allows Reflected XSS. This issue affects Panon: before 1.0.2. | |
| Modificada | Crítica (9.8) | 0.70% | — | Akbim Panon | 3/4/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Akbim Computer Panon allows SQL Injection. This issue affects Panon: before 1.0.2. | |
| Modificada | Media (5.4) | 0.36% | — | Wepanow Print Away | 3/2/2023 | 17/6/2026 | WEPA Print Away does not verify that a user has authorization to access documents before generating print orders and associated release codes. This could allow an attacker to generate print orders and release codes for documents they don´t own and print hem without authorization. In order to exploit this… | |
| Modificada | Media (5.4) | 0.37% | — | Wepanow Print Away | 3/2/2023 | 17/6/2026 | WEPA Print Away is vulnerable to a stored XSS. It does not properly sanitize uploaded filenames, allowing an attacker to deceive a user into uploading a document with a malicious filename, which will be included in subsequent HTTP responses, allowing a stored XSS to occur. This attack is persistent across victim… | |
| Modificada | Media (5.4) | 0.47% | — | Ipanorama 360 Wordpress Virtual Tour Builder Project Ipanorama 360 Wordpress Virtual Tour Builder | 9/1/2023 | 17/6/2026 | The iPanorama 360 WordPress Virtual Tour Builder plugin through 1.6.29 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Crítica (9.8) | 2.2% | — | Kopano Groupware Core | 1/4/2022 | 17/6/2026 | An issue in provider/libserver/ECKrbAuth.cpp of Kopano Core <= v11.0.2.51 contains an issue which allows attackers to authenticate even if the user account or password is expired. It also exists in the predecessor Zarafa Collaboration Platform (ZCP) in provider/libserver/ECPamAuth.cpp of Zarafa >= 6.30 (introduced… | |
| Modificada | Alta (7.2) | 1.6% | — | Bosch Autodome IP 4000i FirmwareBosch Autodome IP 5000i FirmwareBosch Autodome IP Starlight 5000i FirmwareBosch Autodome IP Starlight 7000i Firmware+64 | 30/3/2022 | 17/6/2026 | A specially crafted TCP/IP packet may cause the camera recovery image web interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with administrative rights or with physical access to the camera and allows the upload of a new firmware in… | |
| Modificada | Alta (7.2) | 1.6% | — | Bosch Autodome IP 4000i FirmwareBosch Autodome IP 5000i FirmwareBosch Autodome IP Starlight 5000i FirmwareBosch Autodome IP Starlight 7000i Firmware+64 | 30/3/2022 | 17/6/2026 | A specially crafted TCP/IP packet may cause a camera recovery image telnet interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with administrative rights or with physical access to the camera and allows the upload of a new firmware in… | |
| Modificada | Crítica (9.1) | 2.1% | — | Libpano13 Project Libpano13Debian Linux | 10/3/2022 | 17/6/2026 | Panorama Tools libpano13 v2.9.20 was discovered to contain an out-of-bounds read in the function panoParserFindOLine() in parser.c. | |
| Modificada | Crítica (9.8) | 1.9% | — | Libpano13 Project Libpano13Fedoraproject FedoraDebian Linux | 5/4/2021 | 17/6/2026 | Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~rc2+dfsg-3 and earlier can lead to read and write arbitrary memory values. | |
| Modificada | Alta (7.5) | 2.0% | — | Kopano Groupware CoreZarafa | 31/3/2021 | 17/6/2026 | kopano-ical (formerly zarafa-ical) in Kopano Groupware Core through 8.7.16, 9.x through 9.1.0, 10.x through 10.0.7, and 11.x through 11.0.1 and Zarafa 6.30.x through 7.2.x allows memory exhaustion via long HTTP headers. | |
| Modificada | Media (6.1) | 4.1% | — | Krpano | 7/1/2021 | 17/6/2026 | The default installation of Krpano Panorama Viewer version <=1.20.8 is vulnerable to Reflected XSS due to insecure remote js load in file viewer/krpano.html, parameter plugin[test].url. | |
| Modificada | Media (6.1) | 0.87% | — | Krpano | 7/1/2021 | 17/6/2026 | The default installation of Krpano Panorama Viewer version <=1.20.8 is prone to Reflected XSS due to insecure XML load in file /viewer/krpano.html, parameter xml. | |
| Modificada | Alta (7.4) | 0.97% | — | Panorama Project Nhiservisignadapter | 31/12/2020 | 17/6/2026 | The digest generation function of NHIServiSignAdapter has not been verified for source file path, which leads to the SMB request being redirected to a malicious host, resulting in the leakage of user's credential. | |
| Modificada | Alta (7.4) | 0.97% | — | Panorama Project Nhiservisignadapter | 31/12/2020 | 17/6/2026 | Multiple functions of NHIServiSignAdapter failed to verify the users’ file path, which leads to the SMB request being redirected to a malicious host, resulting in the leakage of user's credential. | |
| Modificada | Crítica (9.8) | 2.0% | — | Panorama Nhiservisignadapter | 31/12/2020 | 17/6/2026 | The digest generation function of NHIServiSignAdapter has not been verified for parameter’s length, which leads to a stack overflow loophole. Remote attackers can use the leak to execute code without privilege. | |
| Modificada | Crítica (9.8) | 2.0% | — | Panorama Nhiservisignadapter | 31/12/2020 | 17/6/2026 | NHIServiSignAdapter fails to verify the length of digital credential files’ path which leads to a heap overflow loophole. Remote attackers can use the leak to execute code without privilege. | |
| Modificada | Alta (7.5) | 0.51% | — | Panorama Nhiservisignadapter | 31/12/2020 | 17/6/2026 | The encryption function of NHIServiSignAdapter fail to verify the file path input by users. Remote attacker can access arbitrary files through the flaw without privilege. | |
| Modificada | Alta (7.8) | 0.50% | — | Opensuse LeapOpensuse Tumbleweed Kopano-spamd | 29/6/2020 | 17/6/2026 | A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of kopano-spamd of openSUSE Leap 15.1, openSUSE Tumbleweed allowed local attackers with the privileges of the kopano user to escalate to root. This issue affects: openSUSE Leap 15.1 kopano-spamd versions prior to 10.0.5-lp151.4.1. openSUSE… | |
| Modificada | Crítica (9.8) | 2.2% | — | Kopano Groupware Core | 19/12/2019 | 17/6/2026 | HrAddFBBlock in libfreebusy/freebusyutil.cpp in Kopano Groupware Core before 8.7.7 allows out-of-bounds access, as demonstrated by mishandling of an array copy during parsing of ICal data. | |
| Modificada | Crítica (9.8) | 2.3% | — | Cylan Clever DOG Smart Camera Panorama Dog-2w FirmwareCylan Clever DOG Smart Camera Plus Dog-2w-v4 Firmware | 20/6/2019 | 17/6/2026 | On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the network can login remotely to the camera and gain root access. The device ships with a hardcoded 12345678 password for the root account, accessible from a TELNET login prompt. | |
| Modificada | Media (5.5) | 0.35% | — | Cylan Clever DOG Smart Camera Panorama Dog-2w FirmwareCylan Clever DOG Smart Camera Plus Dog-2w-v4 Firmware | 20/6/2019 | 17/6/2026 | On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the local network has unauthenticated access to the internal SD card via the HTTP service on port 8000. The HTTP web server on the camera allows anyone to view or download the video archive recorded and saved on the external memory… | |
| Modificada | Crítica (9.8) | 5.2% | — | Polycom Group SeriesPolycom HDXPolycom Pano | 13/5/2019 | 17/6/2026 | An issue was discovered in Polycom Group Series 6.1.6.1 and earlier, HDX 3.1.12 and earlier, and Pano 1.1.1 and earlier. A remote code execution vulnerability exists in the content sharing functionality because of a Buffer Overflow via crafted packets. | |
| Modificada | Media (6.1) | 0.75% | — | Kopano Webapp | 26/7/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in js/ViewerPanel.js in the file previewer plugin in Kopano WebApp versions 3.3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a specially crafted previewable file. | |
| Modificada | Baja (3.5) | 0.94% | — | Panopoly Magic Project Panopoly Magic | 26/2/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the live preview in the Panopoly Magic module before 7.x-1.17 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a pane title. |