Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
66 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.47% | — | 9001 Copyparty | 25/2/2025 | 17/6/2026 | copyparty, a portable file server, has a DOM-based cross-site scripting vulnerability in versions prior to 1.16.15. The vulnerability is considered low-risk. By handing someone a maliciously-named file, and then tricking them into dragging the file into copyparty's Web-UI, an attacker could execute arbitrary… | |
| Aplazada | Alta (7.1) | 0.15% | — | Andrea Pernici Third Party Cookie EraserAI | 2/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Andrea Pernici Third Party Cookie Eraser third-party-cookie-eraser allows Stored XSS.This issue affects Third Party Cookie Eraser: from n/a through <= 1.0.2. | |
| Analizada | Media (6.5) | 0.33% | — | Cisco IP Conference Phone 7832 FirmwareCisco IP Conference Phone 7832 With Multiplatform FirmwareCisco IP Conference Phone 8832 FirmwareCisco IP Conference Phone 8832 With Multiplatform Firmware+30 | 18/11/2024 | 17/6/2026 | Multiple vulnerabilities in the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) implementations for Cisco IP Phone Series 68xx/78xx/88xx could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP phone. These vulnerabilities are due to… | |
| Aplazada | Alta (7.1) | 0.27% | — | Zaus Forms 3RD Party Post AgainAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zaus Forms: 3rd-Party Post Again forms-3rdparty-post-again allows Reflected XSS.This issue affects Forms: 3rd-Party Post Again: from n/a through <= 0.3. | |
| Analizada | Media (5.3) | 1.3% | — | Debian LinuxFedoraproject FedoraJnunemaker Httparty | 4/1/2024 | 14/7/2026 | httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written. | |
| Modificada | Alta (7.2) | 0.53% | — | Samperrow PRE Party Resource Hints | 28/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sam Perrow Pre* Party Resource Hints.This issue affects Pre* Party Resource Hints: from n/a through 1.8.18. | |
| Modificada | Alta (7.5) | 0.80% | — | Johannschopplich Nuxt API Party | 9/12/2023 | 17/6/2026 | `nuxt-api-party` is an open source module to proxy API requests. The library allows the user to send many options directly to `ofetch`. There is no filter on which options are available. We can abuse the retry logic to cause the server to crash from a stack overflow. fetchOptions are obtained directly from the request… | |
| Modificada | Alta (7.5) | 0.82% | — | Johannschopplich Nuxt API Party | 9/12/2023 | 17/6/2026 | `nuxt-api-party` is an open source module to proxy API requests. nuxt-api-party attempts to check if the user has passed an absolute URL to prevent the aforementioned attack. This has been recently changed to use the regular expression `^https?://`, however this regular expression can be bypassed by an absolute URL… | |
| Modificada | Media (6.1) | 9.2% | 💥 Exploit | 9001 Copyparty | 25/7/2023 | 17/6/2026 | copyparty is file server software. Prior to version 1.8.7, the application contains a reflected cross-site scripting via URL-parameter `?k304=...` and `?setck=...`. The worst-case outcome of this is being able to move or delete existing files on the server, or upload new files, using the account of the person who… | |
| Modificada | Alta (7.5) | 45% | 💥 Exploit | 9001 Copyparty | 14/7/2023 | 17/6/2026 | Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder. The Path Traversal attack technique allows an attacker access to files, directories, and commands that reside outside the web document root directory. This issue has been… | |
| Modificada | Alta (7.8) | 1.4% | — | Connect-multiparty Project Connect-multiparty | 16/5/2022 | 17/6/2026 | An arbitrary file upload vulnerability in the file upload module of Express Connect-Multiparty 2.2.0 allows attackers to execute arbitrary code via a crafted PDF file. NOTE: the Supplier has not verified this vulnerability report. | |
| Modificada | Media (6.5) | 12% | — | Apache Xerces-jOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Banking Deposits AND Lines OF Credit Servicing+25 | 24/1/2022 | 25/8/2026 | There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version… | |
| Modificada | Media (4.6) | 0.35% | — | Cisco IP Conference Phone 7832 FirmwareCisco IP Conference Phone 8832 FirmwareCisco IP Phone 7811 FirmwareCisco IP Phone 7821 Firmware+16 | 14/1/2022 | 17/6/2026 | A vulnerability in the information storage architecture of several Cisco IP Phone models could allow an unauthenticated, physical attacker to obtain confidential information from an affected device. This vulnerability is due to unencrypted storage of confidential information on an affected device. An attacker could… | |
| Modificada | Media (5.9) | 100% | 💥 PoC | Apache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+112 | 18/12/2021 | 25/8/2026 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j… | |
| Modificada | Media (6.5) | 2.9% | — | NettyQuarkusNetapp Oncommand Workflow AutomationNetapp Snapcenter+14 | 9/12/2021 | 17/6/2026 | Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control chars when they are present at the beginning / end of the header name. It should instead fail fast as these are not… | |
| Modificada | Alta (7.1) | 0.26% | — | Hitachienergy Counterparty Settlements AND BillingHitachienergy Retail Operations | 17/11/2021 | 17/6/2026 | Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Operations, Counterparty Settlement and Billing (CSB) allows an attacker to execute a modified signed Java Applet JAR file. A successful exploitation may lead to data extraction or modification of data… | |
| Modificada | Alta (7.2) | 1.3% | — | Hitachienergy Counterparty Settlement AND BillingHitachienergy Retail Operations | 20/8/2021 | 17/6/2026 | Insufficiently Protected Credentials vulnerability in client environment of Hitachi ABB Power Grids Retail Operations and Counterparty Settlement Billing (CSB) allows an attacker or unauthorized user to access database credentials, shut down the product and access or alter. This issue affects: Hitachi ABB Power Grids… | |
| Modificada | Media (5.4) | 1.3% | — | CkeditorDebian LinuxFedoraproject FedoraOracle Application Express+8 | 13/8/2021 | 17/6/2026 | ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. It… | |
| Modificada | Media (5.4) | 1.2% | — | CkeditorFedoraproject FedoraOracle Application ExpressOracle Banking Party Management+6 | 12/8/2021 | 17/6/2026 | ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML, which could result in injecting arbitrary… | |
| Modificada | Media (5.4) | 1.2% | — | CkeditorFedoraproject FedoraOracle Application ExpressOracle Banking Party Management+9 | 12/8/2021 | 17/6/2026 | ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It… | |
| Modificada | Media (6.1) | 1.5% | — | Antisamy Project AntisamyOracle Retail Back OfficeOracle Retail Central OfficeOracle Retail Returns Management+7 | 19/7/2021 | 17/6/2026 | OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character. | |
| Modificada | Alta (7.5) | 13% | — | Apache Commons CompressOracle Banking ApisOracle Banking Digital ExperienceOracle Banking Enterprise Default Management+30 | 13/7/2021 | 17/6/2026 | When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package. | |
| Modificada | Alta (7.5) | 11% | — | Apache Commons CompressNetapp Active IQ Unified ManagerNetapp Oncommand InsightOracle Banking Apis+23 | 13/7/2021 | 17/6/2026 | When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package. | |
| Modificada | Alta (7.5) | 12% | — | Apache Commons CompressNetapp Active IQ Unified ManagerNetapp Oncommand InsightOracle Banking Digital Experience+20 | 13/7/2021 | 17/6/2026 | When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' sevenz package. | |
| Modificada | Alta (7.5) | 12% | — | Apache Commons CompressNetapp Active IQ Unified ManagerNetapp Oncommand InsightOracle Banking Digital Experience+22 | 13/7/2021 | 17/6/2026 | When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package. |