Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
84 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.26% | — | Denkgroot Spina | 19/7/2024 | 17/6/2026 | Cross Site Request Forgery vulnerability in Spina CMS v.2.18.0 and before allows a remote attacker to escalate privileges via a crafted URL | |
| Aplazada | Crítica (9.1) | 0.49% | — | Spinroot SpinAI | 8/5/2024 | 17/6/2026 | Spin is the developer tool for building and running serverless applications powered by WebAssembly. Prior to 2.4.3, some specifically configured Spin applications that use `self` requests without a specified URL authority can be induced to make requests to arbitrary hosts via the `Host` HTTP header. The following… | |
| Aplazada | Media (6.5) | 0.34% | — | Maurice Spin 360 DEG AND 3D Model ViewerAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maurice Spin 360 deg and 3D Model Viewer allows Stored XSS.This issue affects Spin 360 deg and 3D Model Viewer: from n/a through 1.2.7. | |
| Aplazada | Crítica (9.8) | 0.83% | — | Knowband SpinwheelAI | 19/3/2024 | 17/6/2026 | SQL injection vulnerability in KnowBand spinwheel v.3.0.3 and before allows a remote attacker to gain escalated privileges and obtain sensitive information via the SpinWheelFrameSpinWheelModuleFrontController::sendEmail() method. | |
| Modificada | Media (5.3) | 0.38% | — | Linuxfoundation Spinnaker | 28/8/2023 | 17/6/2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. Log output when updating GitHub status is improperly set to FULL always. It's recommended to apply the patch and rotate the GitHub token used for github status notifications. Given that this would output github tokens to a log system, the risk is… | |
| Modificada | Media (4.8) | 0.56% | — | Denkgroot Spina | 28/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. | |
| Modificada | Alta (7.5) | 0.88% | — | Mel-spintax Project Mel-spintax | 18/1/2023 | 17/6/2026 | A vulnerability was found in melnaron mel-spintax. It has been rated as problematic. Affected by this issue is some unknown functionality of the file lib/spintax.js. The manipulation of the argument text leads to inefficient regular expression complexity. The name of the patch is… | |
| Modificada | Alta (7.5) | 0.54% | — | Linuxfoundation Spinnaker | 3/1/2023 | 17/6/2026 | Spinnaker is an open source, multi-cloud continuous delivery platform for releasing software changes, and Spinnaker's Rosco microservice produces machine images. Rosco prior to versions 1.29.2, 1.28.4, and 1.27.3 does not property mask secrets generated via packer builds. This can lead to exposure of sensitive AWS… | |
| Modificada | Media (5.5) | 0.64% | — | Spinroot Spin | 14/1/2022 | 17/6/2026 | Spin v6.5.1 was discovered to contain an out-of-bounds write in lex() at spinlex.c. | |
| Modificada | Crítica (9.8) | 2.6% | — | Linuxfoundation Spinnaker | 4/1/2022 | 17/6/2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. Spinnaker has improper permissions allowing pipeline creation & execution. This lets an arbitrary user with access to the gate endpoint to create a pipeline and execute it without authentication. If users haven't setup Role-based access control… | |
| Modificada | Alta (7.1) | 0.34% | — | Linuxfoundation Spinnaker | 4/1/2022 | 17/6/2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. A path traversal vulnerability was discovered in uses of TAR files by AppEngine for deployments. This uses a utility to extract files locally for deployment without validating the paths in that deployment don't override system files. This would… | |
| Modificada | Media (6.5) | 0.94% | — | Spinetix DsosSpinetix Hmp350 FirmwareSpinetix Hmp300 FirmwareSpinetix Diva Firmware+2 | 24/3/2021 | 17/6/2026 | spxmanage on certain SpinetiX devices allows requests that access unintended resources because of SSRF and Path Traversal. This affects HMP350, HMP300, and DiVA through 4.5.2-1.0.36229; HMP400 and HMP400W through 4.5.2-1.0.2-1eb2ffbd; and DSOS through 4.5.2-1.0.2-1eb2ffbd. | |
| Modificada | Alta (8.8) | 1.5% | — | Linuxfoundation Spinnaker | 11/12/2020 | 17/6/2026 | Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnerability exists within the handling of SpEL expressions that allows an attacker to read and write arbitrary files within the orca container via authenticated HTTP… | |
| Modificada | Alta (7.5) | 1.3% | — | Spinnaker Orca | 28/8/2020 | 17/6/2026 | The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an attacker to send requests on behalf of Spinnaker potentially leading to sensitive data disclosure. | |
| Modificada | Alta (7.5) | 1.4% | — | Spin-rs Project Spin-rs | 9/9/2019 | 17/6/2026 | An issue was discovered in the spin crate before 0.5.2 for Rust, when RwLock is used. Because memory ordering is mishandled, two writers can acquire the lock at the same time, violating mutual exclusion. | |
| Modificada | Media (5.9) | 2.0% | — | Fedoraproject Spin-kickstarts | 16/10/2017 | 17/6/2026 | fedora-cloud-atomic.ks in spin-kickstarts allows remote attackers to conduct man-in-the-middle attacks by leveraging use of HTTP to download Fedora Atomic updates. | |
| Modificada | Alta (8.8) | 0.90% | — | Denkgroot Spina | 7/9/2017 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Spina before commit bfe44f289e336f80b6593032679300c493735e75. | |
| Modificada | Media (5.4) | 0.27% | — | Narr8 Spin - Motion Comic | 19/10/2014 | 17/6/2026 | The SPIN - Motion Comic (aka me.narr8.android.serial.spin) application 2.1.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 0.90% | — | Aspindir Xweblog | 5/10/2011 | 16/6/2026 | SQL injection vulnerability in arsiv.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the tarih parameter. | |
| Modificada | Alta (7.5) | 0.99% | — | Aspindir Xweblog | 5/10/2011 | 16/6/2026 | SQL injection vulnerability in oku.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the makale_id parameter. | |
| Modificada | Media (5) | 2.5% | — | Aspindir Kisisel Radyo Script | 2/11/2010 | 16/6/2026 | Kisisel Radyo Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for sevvo/eco23.mdb. | |
| Modificada | Alta (7.5) | 1.0% | — | Aspindir Kisisel Radyo Script | 2/11/2010 | 16/6/2026 | SQL injection vulnerability in radyo.asp in Kisisel Radyo Script allows remote attackers to execute arbitrary SQL commands via the Id parameter. | |
| Modificada | Media (5) | 1.3% | — | Aspindir KRM Haber | 6/5/2010 | 16/6/2026 | KrM Haber 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for d_atabase/Krmdb.mdb. | |
| Modificada | Media (5) | 2.5% | — | Aspindir Angelo-emlak | 27/4/2010 | 16/6/2026 | Angelo-Emlak 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for veribaze/angelo.mdb. | |
| Modificada | Media (5) | 1.3% | — | Aspindir Lookmer Muzik Portal | 25/3/2010 | 16/6/2026 | LookMer Music Portal stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for dbmdb/LookMerSarkiMDB.mdb. |