Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
102 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.24% | — | Pinecone SimulatorAI | 4/3/2025 | 17/6/2026 | Pinecone is an experimental overlay routing protocol suite which is the foundation of the current P2P Matrix demos. The Pinecone Simulator (pineconesim) included in Pinecone up to commit ea4c337 is vulnerable to stored cross-site scripting. The payload storage is not permanent and will be wiped when restarting… | |
| Analizada | Alta (8) | 0.46% | — | Alpsalpine Ilx-f509 Firmware | 31/1/2025 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Media (5.3) | 0.68% | — | Alpsalpine Ilx-f509 Firmware | 31/1/2025 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DLT interface, which listens on TCP port 3490 by default. The issue results from the lack of… | |
| Aplazada | Alta (7.1) | 0.27% | — | Tevya Happiness-reports-for-help-scoutAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tevya Satisfaction Reports from Help Scout happiness-reports-for-help-scout allows Reflected XSS.This issue affects Satisfaction Reports from Help Scout: from n/a through <= 2.0.3. | |
| Aplazada | Media (5.9) | 0.27% | — | Walterpinem WP MylinksAI | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Walter Pinem WP MyLinks wp-mylinks allows Stored XSS.This issue affects WP MyLinks: from n/a through <= 1.0.6. | |
| Analizada | Media (6.8) | 1.0% | — | Alpsalpine Ilx-f509 Firmware | 28/9/2024 | 17/6/2026 | Alpine Halo9 UPDM_wemCmdUpdFSpeDecomp Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within… | |
| Analizada | Media (4.6) | 0.26% | — | Alpsalpine Ilx-f509 Firmware | 28/9/2024 | 17/6/2026 | Alpine Halo9 Improper Verification of Cryptographic Signature Vulnerability. This vulnerability allows physically present attackers to bypass signature validation mechanism on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within… | |
| Analizada | Alta (7.5) | 0.50% | — | Alpsalpine Ilx-f509 Firmware | 28/9/2024 | 17/6/2026 | Alpine Halo9 DecodeUTF7 Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target… | |
| Analizada | Media (6.8) | 1.0% | — | Alpsalpine Ilx-f509 Firmware | 28/9/2024 | 17/6/2026 | Alpine Halo9 UPDM_wemCmdCreatSHA256Hash Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists… | |
| Analizada | Alta (8.8) | 0.79% | — | Alpsalpine Ilx-f509 Firmware | 28/9/2024 | 17/6/2026 | Alpine Halo9 prh_l2_sar_data_ind Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Aplazada | Media (6.5) | 0.36% | — | Walterpinem Oneclick Chat TO OrderAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Walter Pinem OneClick Chat to Order allows Stored XSS.This issue affects OneClick Chat to Order: from n/a through 1.0.5. | |
| Modificada | Media (4.8) | 0.40% | — | Walterpinem Oneclick Chat TO Order | 14/11/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Walter Pinem OneClick Chat to Order plugin <= 1.0.4.2 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Cybonet Pineapp Mail Secure | 8/5/2023 | 17/6/2026 | Cybonet PineApp Mail Secure A reflected cross-site scripting (XSS) vulnerability was identified in the product, using an unspecified endpoint. | |
| Modificada | Media (5.4) | 0.66% | — | Alpine Project Alpine | 28/12/2022 | 17/6/2026 | Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows Authentication Filter bypass. The AuthenticationFilter relies on the request URI to evaluate if the user is accessing the swagger endpoint. By accessing a URL with a path such as /api/foo;%2fapi%2fswagger the contains condition will hold… | |
| Modificada | Alta (7.5) | 0.84% | — | Alpine Project Alpine | 28/12/2022 | 17/6/2026 | Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows URL access filter bypass. This issue has been fixed in version 1.10.4. There are no known workarounds. | |
| Modificada | Media (5.9) | 0.91% | — | Alpine Project Alpine | 3/11/2022 | 17/6/2026 | Alpine before 2.25 allows remote attackers to cause a denial of service (application crash) when LIST or LSUB is sent before STARTTLS. | |
| Modificada | Media (5.4) | 0.63% | — | Thealpinepress Alpine Phototile FOR Pinterest | 23/8/2022 | 17/6/2026 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alpine Press Alpine PhotoTile for Pinterest plugin <= 1.3.1 at WordPress. | |
| Modificada | Media (6.1) | 0.73% | — | Thealpinepress Alpine-photo-tile-for-instagram | 23/6/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Alpine PhotoTile for Instagram Plugin 1.2.7.7. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched remotely. | |
| Modificada | Media (4.6) | 0.51% | — | Lepin Ep-kp001 Project Lepinep-kp001 Firmware | 10/6/2022 | 17/6/2026 | Due to an insecure design, the Lepin EP-KP001 flash drive through KP001_V19 is vulnerable to an authentication bypass attack that enables an attacker to gain access to the stored encrypted data. Normally, the encrypted disk partition with this data is unlocked by entering the correct passcode (6 to 14 digits) via the… | |
| Modificada | Crítica (9.8) | 1.0% | — | Cybonet Pineapp Mail Secure | 24/2/2022 | 17/6/2026 | Cybonet - PineApp Mail Relay Unauthenticated Sql Injection. Attacker can send a request to: /manage/emailrichment/userlist.php?CUSTOMER_ID_INNER=1 /admin/emailrichment/userlist.php?CUSTOMER_ID_INNER=1 /manage/emailrichment/usersunlist.php?CUSTOMER_ID_INNER=1 /admin/emailrichment/usersunlist.php?CUSTOMER_ID_INNER=1 and… | |
| Modificada | Alta (7.5) | 0.69% | — | Cybonet Pineapp Mail Secure | 24/2/2022 | 17/6/2026 | Cybonet - PineApp Mail Relay Local File Inclusion. Attacker can send a request to : /manage/mailpolicymtm/log/eml_viewer/email.content.body.php?filesystem_path=ENCDODED PATH and by doing that, the attacker can read Local Files inside the server. | |
| Modificada | Alta (7.8) | 0.40% | — | Alpsalpine Touchpad Driver | 31/1/2022 | 17/6/2026 | Alps Alpine Touchpad Driver 10.3201.101.215 is vulnerable to DLL Injection. | |
| Modificada | Media (6.1) | 0.58% | — | Pineapp Mail Secure | 8/12/2021 | 17/6/2026 | PineApp - Mail Secure - Attacker sending a request to :/blocking.php?url=<script>alert(1)</script> and stealing cookies . | |
| Modificada | Media (5.9) | 1.6% | — | Alpine Project Alpine | 10/8/2021 | 17/6/2026 | In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS. | |
| Modificada | Media (5.9) | 0.35% | — | Alpinelinux Aports | 5/7/2021 | 17/6/2026 | In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attacks because pre-generated RSA certificates and private keys are used. |