Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

113 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.68%—Picotronica E-clinic Healthcare System EchsAI6/5/202617/6/2026
A vulnerability was detected in PicoTronica e-Clinic Healthcare System ECHS 5.7. The affected element is an unknown function of the file /cdemos/echs/api/v2/patient-records of the component API Endpoint. The manipulation results in missing authentication. The attack can be executed remotely. The exploit is now public…
AnalizadaMedia (5.5)4.7%—Sipeed Picoclaw25/4/202617/6/2026
A vulnerability was detected in PicoClaw up to 0.2.4. Impacted is an unknown function of the file /api/gateway/restart of the component Web Launcher Management Plane. Performing a manipulation results in command injection. It is possible to initiate the attack remotely. The project was informed of the problem early…
AnalizadaMedia (5.3)0.51%—Jonschlinkert Picomatch26/3/202617/6/2026
Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` object. Because the object inherits from `Object.prototype`, specially crafted POSIX bracket expressions (e.g., `[[:constructor:]]`) can…
AnalizadaAlta (7.5)0.49%💥 PoCJonschlinkert Picomatch26/3/202617/6/2026
Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob quantifiers such as `+()` and `*()`, especially when combined with overlapping alternatives…
AplazadaAlta (8.8)0.34%—Thememount ApiconaAI25/3/202617/6/2026
Deserialization of Untrusted Data vulnerability in thememount Apicona apicona allows Object Injection.This issue affects Apicona: from n/a through <= 24.1.0.
AplazadaAlta (8.5)0.17%—KmspicoAI25/1/202617/6/2026
KMSpico 17.1.0.0 contains an unquoted service path vulnerability in the Service KMSELDI configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path in C:\Program Files\KMSpico\Service_KMS.exe to inject malicious executables and escalate privileges.
AplazadaMedia (5.4)0.13%—Alessandro Piconi Simple Keyword TO LinkAI24/12/20255/10/2026
Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi Simple Keyword to Link simple-keyword-to-link allows Cross Site Request Forgery.This issue affects Simple Keyword to Link: from n/a through <= 1.5.
AplazadaMedia (4.3)0.16%—Alessandro Piconi Simple Keyword TO LinkAI6/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi Simple Keyword to Link simple-keyword-to-link allows Cross Site Request Forgery.This issue affects Simple Keyword to Link: from n/a through <= 1.5.
AplazadaMedia (5.3)0.62%—MultiscanAIPicoscanAI28/4/202517/6/2026
The multiScan and picoScan are vulnerable to a denial-of-service (DoS) attack. A remote attacker can exploit this vulnerability by conducting a Slowloris-type attack, causing the web page to become unresponsive.
ModificadaCrítica (9.8)1.8%💥 PoCEpicor Human Capital Management28/3/202517/6/2026
A SQL injection vulnerability exists in Epicor HCM 2021 1.9, with patches available: 5.16.0.1033/HCM2022, 5.17.0.1146/HCM2023, and 5.18.0.573/HCM2024. The injection is specifically in the filter parameter of the JsonFetcher.svc endpoint. An attacker can exploit this vulnerability by injecting malicious SQL payloads…
AplazadaAlta (8.1)0.43%—Epicor Prophet 21AI6/3/202517/6/2026
A SQL Injection vulnerability has been identified in EPICOR Prophet 21 (P21) up to 23.2.5232. This vulnerability allows authenticated remote attackers to execute arbitrary SQL commands through unsanitized user input fields to obtain unauthorized information
AplazadaMedia (5.3)0.55%—Privateoctopus PicoquicAI20/2/202517/6/2026
The hash table used to manage connections in picoquic before b80fd3f uses a weak hash function, allowing remote attackers to cause a considerable CPU load on the server (a Hash DoS attack) by initiating connections with colliding Source Connection IDs (SCIDs).
AplazadaAlta (7.1)0.15%—Alessandro Piconi Internal Link BuilderAI31/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi Internal Link Builder internal-link-builder allows Cross Site Request Forgery.This issue affects Internal Link Builder: from n/a through <= 1.0.
AnalizadaCrítica (9.8)0.48%—Dena Picotls11/10/202417/6/2026
Picotls is a TLS protocol library that allows users select different crypto backends based on their use case. When parsing a spoofed TLS handshake message, picotls (specifically, bindings within picotls that call the crypto libraries) may attempt to free the same memory twice. This double free occurs during the…
ModificadaCrítica (9.8)1.6%—Alekseykurepin Pico Http Server IN C5/1/202417/6/2026
route in main.c in Pico HTTP Server in C through f3b69a6 has an sprintf stack-based buffer overflow via a long URI, leading to remote code execution.
ModificadaCrítica (9.1)0.87%—Capgemini Picotcp10/10/202317/6/2026
In PicoTCP 1.7.0, TCP ISNs are improperly random.
ModificadaAlta (7.5)1.8%—FrroutingPica8 PicosDebian LinuxFedoraproject Fedora29/8/202317/6/2026
FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).
ModificadaMedia (6.8)0.22%—Espressif Esp32-d0wd-v3 FirmwareEspressif Esp32-d0wdr2-v3 FirmwareEspressif Esp32-u4wdh FirmwareEspressif Esp32-pico-v3 Firmware+1817/7/202317/6/2026
An issue was discovered on Espressif ESP32 3.0 (ESP32_rev300 ROM) devices. An EMFI attack on ECO3 provides the attacker with a capability to influence the PC value at the CPU context level, regardless of Secure Boot and Flash Encryption status. By using this capability, the attacker can exploit another behavior in the…
ModificadaAlta (7.5)0.64%—Virtualsquare Picotcp19/6/202317/6/2026
VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 does not properly check whether header sizes would result in accessing data outside of a packet.
ModificadaAlta (7.5)0.70%—Virtualsquare Picotcp19/6/202317/6/2026
VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 lacks certain size calculations before attempting to set a value of an mss structure member.
ModificadaAlta (7.5)0.70%—Virtualsquare Picotcp19/6/202317/6/2026
VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 does not have an MSS lower bound (e.g., it could be zero).
ModificadaAlta (7.5)0.70%—Virtualsquare Picotcp19/6/202317/6/2026
VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 does not check the transport layer length in a frame before performing port filtering.
ModificadaAlta (7.5)0.87%—Altran Picotcp19/4/202317/6/2026
Altran picoTCP through 1.7.0 allows memory corruption (and subsequent denial of service) because of an integer overflow in pico_ipv6_alloc when processing large ICMPv6 packets. This affects installations with Ethernet support in which a packet size greater than 65495 may occur.
ModificadaMedia (6.1)0.47%—Mapicoin Project Mapicoin21/3/202317/6/2026
A vulnerability has been found in Ydalb mapicoin up to 1.9.0 and classified as problematic. This vulnerability affects unknown code of the file webroot/stats.php. The manipulation of the argument link/search leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 1.10.0 is able to…
ModificadaCrítica (9.8)0.84%—Altran PicotcpAltran Picotcp-ng15/2/202317/6/2026
Double Free vulnerability in virtualsquare picoTCP v1.7.0 and picoTCP-NG v2.1 in modules/pico_fragments.c in function pico_fragments_reassemble, allows attackers to execute arbitrary code.
Orbitaley — Vulnerabilidades