Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
113 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.68% | — | Picotronica E-clinic Healthcare System EchsAI | 6/5/2026 | 17/6/2026 | A vulnerability was detected in PicoTronica e-Clinic Healthcare System ECHS 5.7. The affected element is an unknown function of the file /cdemos/echs/api/v2/patient-records of the component API Endpoint. The manipulation results in missing authentication. The attack can be executed remotely. The exploit is now public… | |
| Analizada | Media (5.5) | 4.7% | — | Sipeed Picoclaw | 25/4/2026 | 17/6/2026 | A vulnerability was detected in PicoClaw up to 0.2.4. Impacted is an unknown function of the file /api/gateway/restart of the component Web Launcher Management Plane. Performing a manipulation results in command injection. It is possible to initiate the attack remotely. The project was informed of the problem early… | |
| Analizada | Media (5.3) | 0.51% | — | Jonschlinkert Picomatch | 26/3/2026 | 17/6/2026 | Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` object. Because the object inherits from `Object.prototype`, specially crafted POSIX bracket expressions (e.g., `[[:constructor:]]`) can… | |
| Analizada | Alta (7.5) | 0.49% | 💥 PoC | Jonschlinkert Picomatch | 26/3/2026 | 17/6/2026 | Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob quantifiers such as `+()` and `*()`, especially when combined with overlapping alternatives… | |
| Aplazada | Alta (8.8) | 0.34% | — | Thememount ApiconaAI | 25/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in thememount Apicona apicona allows Object Injection.This issue affects Apicona: from n/a through <= 24.1.0. | |
| Aplazada | Alta (8.5) | 0.17% | — | KmspicoAI | 25/1/2026 | 17/6/2026 | KMSpico 17.1.0.0 contains an unquoted service path vulnerability in the Service KMSELDI configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path in C:\Program Files\KMSpico\Service_KMS.exe to inject malicious executables and escalate privileges. | |
| Aplazada | Media (5.4) | 0.13% | — | Alessandro Piconi Simple Keyword TO LinkAI | 24/12/2025 | 5/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi Simple Keyword to Link simple-keyword-to-link allows Cross Site Request Forgery.This issue affects Simple Keyword to Link: from n/a through <= 1.5. | |
| Aplazada | Media (4.3) | 0.16% | — | Alessandro Piconi Simple Keyword TO LinkAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi Simple Keyword to Link simple-keyword-to-link allows Cross Site Request Forgery.This issue affects Simple Keyword to Link: from n/a through <= 1.5. | |
| Aplazada | Media (5.3) | 0.62% | — | MultiscanAIPicoscanAI | 28/4/2025 | 17/6/2026 | The multiScan and picoScan are vulnerable to a denial-of-service (DoS) attack. A remote attacker can exploit this vulnerability by conducting a Slowloris-type attack, causing the web page to become unresponsive. | |
| Modificada | Crítica (9.8) | 1.8% | 💥 PoC | Epicor Human Capital Management | 28/3/2025 | 17/6/2026 | A SQL injection vulnerability exists in Epicor HCM 2021 1.9, with patches available: 5.16.0.1033/HCM2022, 5.17.0.1146/HCM2023, and 5.18.0.573/HCM2024. The injection is specifically in the filter parameter of the JsonFetcher.svc endpoint. An attacker can exploit this vulnerability by injecting malicious SQL payloads… | |
| Aplazada | Alta (8.1) | 0.43% | — | Epicor Prophet 21AI | 6/3/2025 | 17/6/2026 | A SQL Injection vulnerability has been identified in EPICOR Prophet 21 (P21) up to 23.2.5232. This vulnerability allows authenticated remote attackers to execute arbitrary SQL commands through unsanitized user input fields to obtain unauthorized information | |
| Aplazada | Media (5.3) | 0.55% | — | Privateoctopus PicoquicAI | 20/2/2025 | 17/6/2026 | The hash table used to manage connections in picoquic before b80fd3f uses a weak hash function, allowing remote attackers to cause a considerable CPU load on the server (a Hash DoS attack) by initiating connections with colliding Source Connection IDs (SCIDs). | |
| Aplazada | Alta (7.1) | 0.15% | — | Alessandro Piconi Internal Link BuilderAI | 31/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi Internal Link Builder internal-link-builder allows Cross Site Request Forgery.This issue affects Internal Link Builder: from n/a through <= 1.0. | |
| Analizada | Crítica (9.8) | 0.48% | — | Dena Picotls | 11/10/2024 | 17/6/2026 | Picotls is a TLS protocol library that allows users select different crypto backends based on their use case. When parsing a spoofed TLS handshake message, picotls (specifically, bindings within picotls that call the crypto libraries) may attempt to free the same memory twice. This double free occurs during the… | |
| Modificada | Crítica (9.8) | 1.6% | — | Alekseykurepin Pico Http Server IN C | 5/1/2024 | 17/6/2026 | route in main.c in Pico HTTP Server in C through f3b69a6 has an sprintf stack-based buffer overflow via a long URI, leading to remote code execution. | |
| Modificada | Crítica (9.1) | 0.87% | — | Capgemini Picotcp | 10/10/2023 | 17/6/2026 | In PicoTCP 1.7.0, TCP ISNs are improperly random. | |
| Modificada | Alta (7.5) | 1.8% | — | FrroutingPica8 PicosDebian LinuxFedoraproject Fedora | 29/8/2023 | 17/6/2026 | FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation). | |
| Modificada | Media (6.8) | 0.22% | — | Espressif Esp32-d0wd-v3 FirmwareEspressif Esp32-d0wdr2-v3 FirmwareEspressif Esp32-u4wdh FirmwareEspressif Esp32-pico-v3 Firmware+18 | 17/7/2023 | 17/6/2026 | An issue was discovered on Espressif ESP32 3.0 (ESP32_rev300 ROM) devices. An EMFI attack on ECO3 provides the attacker with a capability to influence the PC value at the CPU context level, regardless of Secure Boot and Flash Encryption status. By using this capability, the attacker can exploit another behavior in the… | |
| Modificada | Alta (7.5) | 0.64% | — | Virtualsquare Picotcp | 19/6/2023 | 17/6/2026 | VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 does not properly check whether header sizes would result in accessing data outside of a packet. | |
| Modificada | Alta (7.5) | 0.70% | — | Virtualsquare Picotcp | 19/6/2023 | 17/6/2026 | VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 lacks certain size calculations before attempting to set a value of an mss structure member. | |
| Modificada | Alta (7.5) | 0.70% | — | Virtualsquare Picotcp | 19/6/2023 | 17/6/2026 | VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 does not have an MSS lower bound (e.g., it could be zero). | |
| Modificada | Alta (7.5) | 0.70% | — | Virtualsquare Picotcp | 19/6/2023 | 17/6/2026 | VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 does not check the transport layer length in a frame before performing port filtering. | |
| Modificada | Alta (7.5) | 0.87% | — | Altran Picotcp | 19/4/2023 | 17/6/2026 | Altran picoTCP through 1.7.0 allows memory corruption (and subsequent denial of service) because of an integer overflow in pico_ipv6_alloc when processing large ICMPv6 packets. This affects installations with Ethernet support in which a packet size greater than 65495 may occur. | |
| Modificada | Media (6.1) | 0.47% | — | Mapicoin Project Mapicoin | 21/3/2023 | 17/6/2026 | A vulnerability has been found in Ydalb mapicoin up to 1.9.0 and classified as problematic. This vulnerability affects unknown code of the file webroot/stats.php. The manipulation of the argument link/search leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 1.10.0 is able to… | |
| Modificada | Crítica (9.8) | 0.84% | — | Altran PicotcpAltran Picotcp-ng | 15/2/2023 | 17/6/2026 | Double Free vulnerability in virtualsquare picoTCP v1.7.0 and picoTCP-NG v2.1 in modules/pico_fragments.c in function pico_fragments_reassemble, allows attackers to execute arbitrary code. |