Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
86 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.3) | 2.2% | — | Ucdok TomatoAI | 4/6/2026 | 22/7/2026 | A flaw has been found in Shibby Tomato 1.28.0000. This affects the function start_dhcpc of the file /sbin/rc of the component Web UI. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. This project is superseded by FreshTomato. | |
| Aplazada | Alta (7.4) | 0.47% | — | Ucdok TomatoAIFreshtomatoAI | 30/5/2026 | 22/7/2026 | A vulnerability was determined in Shibby Tomato up to 1.28. Affected is the function rip_zebra_read_ipv4 of the file /usr/sbin/ripd of the component Zserv Handler. Executing a manipulation can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and… | |
| Aplazada | Alta (8.7) | 0.44% | — | FreshtomatoAIUcdok TomatoAI | 29/5/2026 | 21/7/2026 | A vulnerability has been found in Shibby Tomato 1.28. The impacted element is an unknown function of the file usr/sbin/miniupnpd. Such manipulation leads to resource consumption. The attack may be launched remotely. This project is superseded by FreshTomato. This vulnerability only affects products that are no longer… | |
| Aplazada | Media (6.9) | 0.28% | — | FreshtomatoAIUcdok TomatoAI | 29/5/2026 | 21/7/2026 | A flaw has been found in Shibby Tomato 1.28. The affected element is the function send of the file usr/sbin/miniupnpd of the component SUBSCRIBE Call Handler. This manipulation causes server-side request forgery. The attack may be initiated remotely. This project is superseded by FreshTomato. This vulnerability only… | |
| Aplazada | Alta (8.7) | 0.44% | — | Ucdok TomatoAI | 29/5/2026 | 21/7/2026 | A vulnerability was detected in Shibby Tomato 1.28. Impacted is the function sub_90F0 of the file multimon.cgi. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. This project is superseded by FreshTomato. This vulnerability only affects products that are no longer supported… | |
| Aplazada | Alta (8.7) | 0.44% | — | Ucdok TomatoAI | 29/5/2026 | 21/7/2026 | A security vulnerability has been detected in Shibby Tomato up to 1.28. This issue affects the function sub_9068 of the file tomatoups.cgi of the component UPS Service. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. This project is superseded by FreshTomato. This… | |
| Aplazada | Alta (8.7) | 0.44% | — | Ucdok TomatoAI | 29/5/2026 | 21/7/2026 | A weakness has been identified in Shibby Tomato 1.28. This vulnerability affects the function get_ups_field of the file tomatodata.cgi. Executing a manipulation of the argument Date can lead to stack-based buffer overflow. It is possible to launch the attack remotely. This project is superseded by FreshTomato. This… | |
| Analizada | Media (4.8) | 0.14% | — | Cryptomator | 16/4/2026 | 17/6/2026 | Cryptomator is an open-source client-side encryption application for cloud storage. Version 1.19.1 contains a logic flaw in CheckHostTrustController.getAuthority() that allows an attacker to bypass the security fix for CVE-2026-32303. The method hardcodes the URI scheme based on port number, causing HTTPS URLs with… | |
| En análisis | Media (5.9) | 0.11% | — | Cryptomator | 20/3/2026 | 17/6/2026 | Cryptomator for IOS offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 2.8.3, an integrity check vulnerability allows an attacker tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub key loading mechanism. Before this fix, the… | |
| Analizada | Media (5.9) | 0.08% | — | Cryptomator | 20/3/2026 | 17/6/2026 | Cryptomator for Android offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 1.12.3, an integrity check vulnerability allows an attacker tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub key loading mechanism. Before this fix, the… | |
| Analizada | Media (5.3) | 0.36% | — | Cryptomator | 20/3/2026 | 17/6/2026 | Cryptomator encrypts data being stored on cloud infrastructure. From version 1.6.0 to before version 1.19.1, vault configuration is parsed before its integrity is verified, and the masterkeyfile loader uses the unverified keyId as a filesystem path. The loader resolves keyId.getSchemeSpecificPart() directly against… | |
| Modificada | Alta (8.7) | 0.27% | — | Cryptomator | 20/3/2026 | 17/6/2026 | Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, the Hub-based unlock flow explicitly supports hub+http and consumes Hub endpoints from vault metadata without enforcing HTTPS. As a result, a vault configuration can drive OAuth and key-loading traffic over plaintext HTTP or other… | |
| Analizada | Media (5.9) | 0.16% | — | Cryptomator | 20/3/2026 | 17/6/2026 | Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, an integrity check vulnerability allows an attacker to tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub key loading mechanism. Before this fix, the client trusted endpoints from the… | |
| Analizada | Media (5.3) | 0.21% | — | Cryptomator | 6/3/2026 | 17/6/2026 | Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.0, in non-debug mode Cryptomator might leak cleartext paths into the log file. This can reveal meta information about the files stored inside a vault at a time, where the actual vault is closed. Not every cleartext path is logged.… | |
| Aplazada | Alta (7.2) | 0.67% | — | Uncannyowl Uncanny AutomatorAI | 3/3/2026 | 17/6/2026 | The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.0.0.3 via the download_url() function. This makes it possible for authenticated attackers, with Administrator-level access… | |
| Aplazada | Media (6.4) | 0.29% | — | Uncannyowl Uncanny AutomatorAI | 23/1/2026 | 17/6/2026 | The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the automator_discord_user_mapping shortcode in all versions up to, and including, 6.10.0.2 due to insufficient input sanitization and output escaping on the… | |
| Aplazada | Alta (7.6) | 0.27% | — | AutomatorwpAI | 23/12/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia AutomatorWP automatorwp allows SQL Injection.This issue affects AutomatorWP: from n/a through <= 5.2.4. | |
| Aplazada | Media (4.3) | 0.26% | — | Uncannyowl Uncanny AutomatorAI | 21/11/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Uncanny Owl Uncanny Automator uncanny-automator allows Retrieve Embedded Sensitive Data.This issue affects Uncanny Automator: from n/a through < 6.10.0. | |
| Aplazada | Media (5.4) | 0.20% | — | Automaticwp AutomatormwpAI | 9/9/2025 | 17/6/2026 | The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on multiple plugin's functions in all versions up to, and including, 5.3.7. This makes it possible… | |
| Aplazada | Alta (8) | 0.46% | — | AutomatorwpAI | 9/9/2025 | 17/6/2026 | The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the automatorwp_ajax_import_automation_from_url function in all versions up to, and including, 5.3.6. This… | |
| Aplazada | Media (4.3) | 0.20% | — | Uncannyowl Uncanny AutomatorAI | 27/8/2025 | 17/6/2026 | Missing Authorization vulnerability in Uncanny Owl Uncanny Automator uncanny-automator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uncanny Automator: from n/a through <= 6.7.0.1. | |
| Aplazada | Alta (7.2) | 0.40% | — | AutomatorwpAI | 14/6/2025 | 17/6/2026 | The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the field_conditions parameter in all versions up to, and including, 5.2.3 due to insufficient escaping on the user supplied parameter and lack of… | |
| Modificada | Crítica (9.8) | 0.31% | — | Uncannyowl Uncanny Automator | 5/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Uncanny Owl Uncanny Automator uncanny-automator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uncanny Automator: from n/a through <= 6.4.0.2. | |
| Aplazada | Alta (7.6) | 0.34% | — | AutomatorwpAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia AutomatorWP automatorwp allows Blind SQL Injection.This issue affects AutomatorWP: from n/a through <= 5.2.1.3. | |
| Analizada | Media (4.3) | 0.28% | — | Uncannyowl Uncanny Automator | 14/5/2025 | 17/6/2026 | The Uncanny Automator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in versions up to, and including, 6.4.0.2. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update plugin settings. |