Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.83% | — | Audiobookshelf | 27/5/2024 | 17/6/2026 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.10.0, opening an ebook with malicious scripts inside leads to code execution inside the browsing context. Attacking a user with high privileges (upload, creation of libraries) can lead to remote code execution (RCE) in the worst case.… | |
| Analizada | Media (4.2) | 0.28% | — | Kirillmakarov Musicshelf | 11/3/2024 | 17/6/2026 | A vulnerability classified as problematic was found in Musicshelf 1.0/1.1 on Android. Affected by this vulnerability is an unknown functionality of the file io\fabric\sdk\android\services\network\PinningTrustManager.java of the component SHA-1 Handler. The manipulation leads to password hash with insufficient… | |
| Analizada | Media (4.6) | 0.33% | — | Kirillmakarov Musicshelf | 10/3/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in Musicshelf 1.0/1.1 on Android. Affected is an unknown function of the file androidmanifest.xml of the component Backup Handler. The manipulation leads to exposure of backup file to an unauthorized control sphere. It is possible to launch the attack on the… | |
| Modificada | Alta (7.5) | 0.35% | — | Audiobookshelf | 27/12/2023 | 17/6/2026 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenticated blind server-side request (SSRF) vulnerability in `podcastUtils.js`. This vulnerability has been addressed in version 2.7.0. There are no known workarounds for this vulnerability. | |
| Modificada | Alta (7.5) | 0.35% | — | Audiobookshelf | 27/12/2023 | 17/6/2026 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenticated blind server-side request (SSRF) vulnerability in Auth.js. This vulnerability has been addressed in version 2.7.0. There are no known workarounds for this vulnerability. | |
| Modificada | Media (6.5) | 0.83% | — | Audiobookshelf | 13/12/2023 | 17/6/2026 | Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, any user (regardless of their permissions) may be able to read files from the local file system due to a path traversal in the `/hls` endpoint. This issue may lead to Information Disclosure. As of time of publication, no patches… | |
| Modificada | Media (6.5) | 0.61% | — | Audiobookshelf | 13/12/2023 | 17/6/2026 | Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, users with the update permission are able to read arbitrary files, delete arbitrary files and send a GET request to arbitrary URLs and read the response. This issue may lead to Information Disclosure. As of time of publication,… | |
| Modificada | Media (6.5) | 0.73% | — | Electronic Shelf Label Protocol Project Electronic Shelf Label Protocol | 27/11/2022 | 17/6/2026 | The ESL (Electronic Shelf Label) protocol, as implemented by (for example) the OV80e934802 RF transceiver on the ETAG-2130-V4.3 20190629 board, does not use authentication, which allows attackers to change label values via 433 MHz RF signals, as demonstrated by disrupting the organization of a hospital storage unit,… | |
| Modificada | Media (5.4) | 0.62% | — | Bookshelf Project Bookshelf | 2/8/2021 | 17/6/2026 | The Bookshelf WordPress plugin through 2.0.4 does not sanitise or escape its "Paypal email address" setting before outputting it in the page, leading to an authenticated Stored Cross-Site Scripting issue | |
| Modificada | Media (6.7) | 0.45% | — | Cisco Remote PHY 120 FirmwareCisco Remote PHY 220 FirmwareCisco Remote PHY Shelf 7200 Firmware | 4/3/2020 | 17/6/2026 | A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability exists because the affected software does not properly sanitize user-supplied input. An attacker who has valid… | |
| Modificada | Media (6.7) | 0.44% | — | Cisco Remote PHY 120 FirmwareCisco Remote PHY 220 FirmwareCisco Remote PHY Shelf 7200 FirmwareCisco Cbr-8 Firmware | 21/8/2019 | 17/6/2026 | A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability occurs because the affected software improperly sanitizes user-supplied input. An attacker who has valid… |