Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

105 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.20%—Linickx Root CookieAI16/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in linickx root Cookie allows Cross Site Request Forgery. This issue affects root Cookie: from n/a through 1.6.
AnalizadaCrítica (9.8)0.36%—Webroot Secureanywhere WEB Shield3/10/202417/6/2026
Improper Check for Unusual or Exceptional Conditions vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrURL.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3.
AnalizadaCrítica (9.8)0.36%—Webroot Secureanywhere WEB Shield3/10/202417/6/2026
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3.
AnalizadaCrítica (9.8)0.42%—Webroot Secureanywhere WEB Shield3/10/202417/6/2026
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3.
ModificadaMedia (6.9)0.43%—Denkgroot Spina25/7/202417/6/2026
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown functionality of the file /admin/media_folders. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.…
ModificadaMedia (6.9)0.36%—Denkgroot Spina24/7/202417/6/2026
A vulnerability was found in Spina CMS up to 2.18.0. It has been classified as problematic. Affected is an unknown function of the file /admin/pages/. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.…
AnalizadaCrítica (9.6)0.21%—Denkgroot Spina19/7/202417/6/2026
Spina CMS v2.18.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the URI /admin/layout.
AnalizadaAlta (8.8)0.26%—Denkgroot Spina19/7/202417/6/2026
Cross Site Request Forgery vulnerability in Spina CMS v.2.18.0 and before allows a remote attacker to escalate privileges via a crafted URL
AplazadaCrítica (9.1)0.49%—Spinroot SpinAI8/5/202417/6/2026
Spin is the developer tool for building and running serverless applications powered by WebAssembly. Prior to 2.4.3, some specifically configured Spin applications that use `self` requests without a specified URL authority can be induced to make requests to arbitrary hosts via the `Host` HTTP header. The following…
AnalizadaCrítica (9.8)0.50%—Roothub7/5/202417/6/2026
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the nodeTitle parameter in the parentNode() function..
AnalizadaMedia (6.3)0.34%—Roothub7/5/202417/6/2026
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the topic parameter in the list() function.
ModificadaCrítica (9.8)0.78%—Roothub7/5/20249/7/2026
Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. This vulnerability allows attackers to execute arbitrary code via a crafted JSP file.
AnalizadaMedia (6.3)0.33%—Roothub6/5/202417/6/2026
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the 's' parameter in the search() function.
AplazadaAlta (7.5)0.66%—BuildrootAI3/5/202417/6/2026
Buildroot before 0b2967e lacks the sticky bit for the /dev/shm directory. A fix was released in 2024.02.2.
AplazadaAlta (7.9)0.19%—Webroot AntivirusAI1/5/202417/6/2026
Privilege Escalation in WRSA.EXE in Webroot Antivirus 8.0.1X- 9.0.35.12 on Windows64 bit and 32 bit allows malicious software to abuse WRSA.EXE to delete arbitrary and protected files.
ModificadaMedia (6.5)1.1%—Malaterre Grassroots DicomFedoraproject Fedora25/4/202417/6/2026
An out-of-bounds read vulnerability exists in the RAWCodec::DecodeBytes functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to an out-of-bounds read. An attacker can provide a malicious file to trigger this vulnerability.
AnalizadaCrítica (9.8)1.4%—Malaterre Grassroots DicomFedoraproject Fedora25/4/202417/6/2026
A heap-based buffer overflow vulnerability exists in the LookupTable::SetLUT functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
ModificadaCrítica (9.8)1.7%—Malaterre Grassroots DicomFedoraproject Fedora25/4/202410/9/2026
An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
AnalizadaAlta (7.3)0.32%—Root3 Support APP14/3/202417/6/2026
Support App is an opensource application specialized in managing Apple devices. It's possible to abuse a vulnerability inside the postinstall installer script to make the installer execute arbitrary code as root. The cause of the vulnerability is the fact that the shebang `#!/bin/zsh` is being used. When the installer…
ModificadaAlta (7.5)0.77%—Eyuepcanyilmaz Root Quick Reboot5/2/202417/6/2026
The com.eypcnnapps.quickreboot (aka Eyuep Can Yilmaz {ROOT] Quick Reboot) application 1.0.8 for Android has exposed broadcast receivers for PowerOff, Reboot, and Recovery (e.g., com.eypcnnapps.quickreboot.widget.PowerOff) that are susceptible to unauthorized broadcasts because of missing input validation.
ModificadaAlta (8.1)0.81%—Buildroot5/12/202317/6/2026
Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `mxsldr` package.
ModificadaAlta (8.1)0.81%—Buildroot5/12/202317/6/2026
Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `versal-firmware` package.
ModificadaAlta (8.1)0.81%—Buildroot5/12/202317/6/2026
Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `riscv64-elf-toolchain` package.
ModificadaAlta (8.1)0.81%—Buildroot5/12/202317/6/2026
Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `aufs-util` package.
ModificadaAlta (8.1)0.82%—Buildroot5/12/202317/6/2026
Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `aufs` package.