Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
–

102 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.1)0.24%—Pinecone SimulatorAI4/3/202517/6/2026
Pinecone is an experimental overlay routing protocol suite which is the foundation of the current P2P Matrix demos. The Pinecone Simulator (pineconesim) included in Pinecone up to commit ea4c337 is vulnerable to stored cross-site scripting. The payload storage is not permanent and will be wiped when restarting…
AnalizadaAlta (8)0.46%—Alpsalpine Ilx-f509 Firmware31/1/202517/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The specific flaw exists within the…
AnalizadaMedia (5.3)0.68%—Alpsalpine Ilx-f509 Firmware31/1/202517/6/2026
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DLT interface, which listens on TCP port 3490 by default. The issue results from the lack of…
AplazadaAlta (7.1)0.27%—Tevya Happiness-reports-for-help-scoutAI9/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tevya Satisfaction Reports from Help Scout happiness-reports-for-help-scout allows Reflected XSS.This issue affects Satisfaction Reports from Help Scout: from n/a through <= 2.0.3.
AplazadaMedia (5.9)0.27%—Walterpinem WP MylinksAI5/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Walter Pinem WP MyLinks wp-mylinks allows Stored XSS.This issue affects WP MyLinks: from n/a through <= 1.0.6.
AnalizadaMedia (6.8)1.0%—Alpsalpine Ilx-f509 Firmware28/9/202417/6/2026
Alpine Halo9 UPDM_wemCmdUpdFSpeDecomp Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within…
AnalizadaMedia (4.6)0.26%—Alpsalpine Ilx-f509 Firmware28/9/202417/6/2026
Alpine Halo9 Improper Verification of Cryptographic Signature Vulnerability. This vulnerability allows physically present attackers to bypass signature validation mechanism on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within…
AnalizadaAlta (7.5)0.50%—Alpsalpine Ilx-f509 Firmware28/9/202417/6/2026
Alpine Halo9 DecodeUTF7 Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target…
AnalizadaMedia (6.8)1.0%—Alpsalpine Ilx-f509 Firmware28/9/202417/6/2026
Alpine Halo9 UPDM_wemCmdCreatSHA256Hash Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists…
AnalizadaAlta (8.8)0.79%—Alpsalpine Ilx-f509 Firmware28/9/202417/6/2026
Alpine Halo9 prh_l2_sar_data_ind Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…
AplazadaMedia (6.5)0.36%—Walterpinem Oneclick Chat TO OrderAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Walter Pinem OneClick Chat to Order allows Stored XSS.This issue affects OneClick Chat to Order: from n/a through 1.0.5.
ModificadaMedia (4.8)0.40%—Walterpinem Oneclick Chat TO Order14/11/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Walter Pinem OneClick Chat to Order plugin <= 1.0.4.2 versions.
ModificadaMedia (6.1)0.38%—Cybonet Pineapp Mail Secure8/5/202317/6/2026
Cybonet PineApp Mail Secure A reflected cross-site scripting (XSS) vulnerability was identified in the product, using an unspecified endpoint.
ModificadaMedia (5.4)0.66%—Alpine Project Alpine28/12/202217/6/2026
Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows Authentication Filter bypass. The AuthenticationFilter relies on the request URI to evaluate if the user is accessing the swagger endpoint. By accessing a URL with a path such as /api/foo;%2fapi%2fswagger the contains condition will hold…
ModificadaAlta (7.5)0.84%—Alpine Project Alpine28/12/202217/6/2026
Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows URL access filter bypass. This issue has been fixed in version 1.10.4. There are no known workarounds.
ModificadaMedia (5.9)0.91%—Alpine Project Alpine3/11/202217/6/2026
Alpine before 2.25 allows remote attackers to cause a denial of service (application crash) when LIST or LSUB is sent before STARTTLS.
ModificadaMedia (5.4)0.63%—Thealpinepress Alpine Phototile FOR Pinterest23/8/202217/6/2026
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alpine Press Alpine PhotoTile for Pinterest plugin <= 1.3.1 at WordPress.
ModificadaMedia (6.1)0.73%—Thealpinepress Alpine-photo-tile-for-instagram23/6/202217/6/2026
A vulnerability, which was classified as problematic, has been found in Alpine PhotoTile for Instagram Plugin 1.2.7.7. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched remotely.
ModificadaMedia (4.6)0.51%—Lepin Ep-kp001 Project Lepinep-kp001 Firmware10/6/202217/6/2026
Due to an insecure design, the Lepin EP-KP001 flash drive through KP001_V19 is vulnerable to an authentication bypass attack that enables an attacker to gain access to the stored encrypted data. Normally, the encrypted disk partition with this data is unlocked by entering the correct passcode (6 to 14 digits) via the…
ModificadaCrítica (9.8)1.0%—Cybonet Pineapp Mail Secure24/2/202217/6/2026
Cybonet - PineApp Mail Relay Unauthenticated Sql Injection. Attacker can send a request to: /manage/emailrichment/userlist.php?CUSTOMER_ID_INNER=1 /admin/emailrichment/userlist.php?CUSTOMER_ID_INNER=1 /manage/emailrichment/usersunlist.php?CUSTOMER_ID_INNER=1 /admin/emailrichment/usersunlist.php?CUSTOMER_ID_INNER=1 and…
ModificadaAlta (7.5)0.69%—Cybonet Pineapp Mail Secure24/2/202217/6/2026
Cybonet - PineApp Mail Relay Local File Inclusion. Attacker can send a request to : /manage/mailpolicymtm/log/eml_viewer/email.content.body.php?filesystem_path=ENCDODED PATH and by doing that, the attacker can read Local Files inside the server.
ModificadaAlta (7.8)0.40%—Alpsalpine Touchpad Driver31/1/202217/6/2026
Alps Alpine Touchpad Driver 10.3201.101.215 is vulnerable to DLL Injection.
ModificadaMedia (6.1)0.58%—Pineapp Mail Secure8/12/202117/6/2026
PineApp - Mail Secure - Attacker sending a request to :/blocking.php?url=<script>alert(1)</script> and stealing cookies .
ModificadaMedia (5.9)1.6%—Alpine Project Alpine10/8/202117/6/2026
In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS.
ModificadaMedia (5.9)0.35%—Alpinelinux Aports5/7/202117/6/2026
In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attacks because pre-generated RSA certificates and private keys are used.