Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
105 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.20% | — | Linickx Root CookieAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in linickx root Cookie allows Cross Site Request Forgery. This issue affects root Cookie: from n/a through 1.6. | |
| Analizada | Crítica (9.8) | 0.36% | — | Webroot Secureanywhere WEB Shield | 3/10/2024 | 17/6/2026 | Improper Check for Unusual or Exceptional Conditions vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrURL.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3. | |
| Analizada | Crítica (9.8) | 0.36% | — | Webroot Secureanywhere WEB Shield | 3/10/2024 | 17/6/2026 | Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3. | |
| Analizada | Crítica (9.8) | 0.42% | — | Webroot Secureanywhere WEB Shield | 3/10/2024 | 17/6/2026 | Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3. | |
| Modificada | Media (6.9) | 0.43% | — | Denkgroot Spina | 25/7/2024 | 17/6/2026 | A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Media (6.9) | 0.36% | — | Denkgroot Spina | 24/7/2024 | 17/6/2026 | A vulnerability was found in Spina CMS up to 2.18.0. It has been classified as problematic. Affected is an unknown function of the file /admin/pages/. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.… | |
| Analizada | Crítica (9.6) | 0.21% | — | Denkgroot Spina | 19/7/2024 | 17/6/2026 | Spina CMS v2.18.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the URI /admin/layout. | |
| Analizada | Alta (8.8) | 0.26% | — | Denkgroot Spina | 19/7/2024 | 17/6/2026 | Cross Site Request Forgery vulnerability in Spina CMS v.2.18.0 and before allows a remote attacker to escalate privileges via a crafted URL | |
| Aplazada | Crítica (9.1) | 0.49% | — | Spinroot SpinAI | 8/5/2024 | 17/6/2026 | Spin is the developer tool for building and running serverless applications powered by WebAssembly. Prior to 2.4.3, some specifically configured Spin applications that use `self` requests without a specified URL authority can be induced to make requests to arbitrary hosts via the `Host` HTTP header. The following… | |
| Analizada | Crítica (9.8) | 0.50% | — | Roothub | 7/5/2024 | 17/6/2026 | Roothub v2.6 was discovered to contain a SQL injection vulnerability via the nodeTitle parameter in the parentNode() function.. | |
| Analizada | Media (6.3) | 0.34% | — | Roothub | 7/5/2024 | 17/6/2026 | Roothub v2.6 was discovered to contain a SQL injection vulnerability via the topic parameter in the list() function. | |
| Modificada | Crítica (9.8) | 0.78% | — | Roothub | 7/5/2024 | 9/7/2026 | Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. This vulnerability allows attackers to execute arbitrary code via a crafted JSP file. | |
| Analizada | Media (6.3) | 0.33% | — | Roothub | 6/5/2024 | 17/6/2026 | Roothub v2.6 was discovered to contain a SQL injection vulnerability via the 's' parameter in the search() function. | |
| Aplazada | Alta (7.5) | 0.66% | — | BuildrootAI | 3/5/2024 | 17/6/2026 | Buildroot before 0b2967e lacks the sticky bit for the /dev/shm directory. A fix was released in 2024.02.2. | |
| Aplazada | Alta (7.9) | 0.19% | — | Webroot AntivirusAI | 1/5/2024 | 17/6/2026 | Privilege Escalation in WRSA.EXE in Webroot Antivirus 8.0.1X- 9.0.35.12 on Windows64 bit and 32 bit allows malicious software to abuse WRSA.EXE to delete arbitrary and protected files. | |
| Modificada | Media (6.5) | 1.1% | — | Malaterre Grassroots DicomFedoraproject Fedora | 25/4/2024 | 17/6/2026 | An out-of-bounds read vulnerability exists in the RAWCodec::DecodeBytes functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to an out-of-bounds read. An attacker can provide a malicious file to trigger this vulnerability. | |
| Analizada | Crítica (9.8) | 1.4% | — | Malaterre Grassroots DicomFedoraproject Fedora | 25/4/2024 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in the LookupTable::SetLUT functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 1.7% | — | Malaterre Grassroots DicomFedoraproject Fedora | 25/4/2024 | 10/9/2026 | An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability. | |
| Analizada | Alta (7.3) | 0.32% | — | Root3 Support APP | 14/3/2024 | 17/6/2026 | Support App is an opensource application specialized in managing Apple devices. It's possible to abuse a vulnerability inside the postinstall installer script to make the installer execute arbitrary code as root. The cause of the vulnerability is the fact that the shebang `#!/bin/zsh` is being used. When the installer… | |
| Modificada | Alta (7.5) | 0.77% | — | Eyuepcanyilmaz Root Quick Reboot | 5/2/2024 | 17/6/2026 | The com.eypcnnapps.quickreboot (aka Eyuep Can Yilmaz {ROOT] Quick Reboot) application 1.0.8 for Android has exposed broadcast receivers for PowerOff, Reboot, and Recovery (e.g., com.eypcnnapps.quickreboot.widget.PowerOff) that are susceptible to unauthorized broadcasts because of missing input validation. | |
| Modificada | Alta (8.1) | 0.81% | — | Buildroot | 5/12/2023 | 17/6/2026 | Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `mxsldr` package. | |
| Modificada | Alta (8.1) | 0.81% | — | Buildroot | 5/12/2023 | 17/6/2026 | Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `versal-firmware` package. | |
| Modificada | Alta (8.1) | 0.81% | — | Buildroot | 5/12/2023 | 17/6/2026 | Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `riscv64-elf-toolchain` package. | |
| Modificada | Alta (8.1) | 0.81% | — | Buildroot | 5/12/2023 | 17/6/2026 | Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `aufs-util` package. | |
| Modificada | Alta (8.1) | 0.82% | — | Buildroot | 5/12/2023 | 17/6/2026 | Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `aufs` package. |