Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

38 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.71%—BentomlAI20/3/202517/6/2026
BentoML version v1.3.4post1 is vulnerable to a Denial of Service (DoS) attack. The vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request. This causes the server to continuously process each character, leading to excessive resource consumption…
AplazadaMedia (6.2)0.78%—Bentoml OpenllmAI20/3/202517/6/2026
A Local File Inclusion (LFI) vulnerability in OpenLLM version 0.6.10 allows attackers to include files from the local server through the web application. This flaw could expose internal server files and potentially sensitive information such as configuration files, passwords, and other critical data. Unauthorized…
AplazadaMedia (4.7)0.33%—Tomlister Payflex Payment GatewayAI5/10/202417/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in tomlister Payflex Payment Gateway payflex-payment-gateway.This issue affects Payflex Payment Gateway: from n/a through <= 2.6.1.
ModificadaCrítica (9.8)0.41%—Prestashop PK Customlinks19/6/202417/6/2026
In the module "Custom links" (pk_customlinks) <= 2.3 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The script ajax.php have a sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection.
AplazadaMedia (5.9)0.26%—Kharim Tomlinson WP Next Post NaviAI3/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kharim Tomlinson WP Next Post Navi allows Stored XSS.This issue affects WP Next Post Navi: from n/a through 1.8.3.
AplazadaCrítica (10)1.5%—BentomlAI16/4/202417/6/2026
An insecure deserialization vulnerability exists in the BentoML framework, allowing remote code execution (RCE) by sending a specially crafted POST request. By exploiting this vulnerability, attackers can execute arbitrary commands on the server hosting the BentoML application. The vulnerability is triggered when a…
ModificadaAlta (8.8)0.22%—SFU Customlocale1/11/202317/6/2026
Cross-Site Request Forgery (CSRF) in GitHub repository pkp/customLocale prior to 1.2.0-1.
ModificadaMedia (6.5)0.81%—Tinytoml Project Tinytoml26/5/202217/6/2026
There is a stack-overflow vulnerability in tinytoml v0.4 that can cause a crash or DoS.
ModificadaCrítica (9.8)3.3%—Nconf-toml Project Nconf-toml25/5/202117/6/2026
Prototype pollution vulnerability in `nconf-toml` versions 0.0.1 through 0.0.2 allows an attacker to cause a denial of service and may lead to remote code execution.
ModificadaMedia (4.3)2.0%—Bottomline Transform Foundation Server5/6/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Transform Content Center in Bottomline Technologies Transform Foundation Server before 4.3.1 Patch 8 and 5.x before 5.2 Patch 7 allow remote attackers to inject arbitrary web script or HTML via the (1) pn parameter to index.fsp/document.pdf, (2) db or (3)…
ModificadaMedia (4.6)1.4%—Bottomline Webseries Payment Application2/5/200516/6/2026
Webseries Payment Application does not properly restrict privileged operations, which allows remote authenticated users to gain privileges by directly accessing certain URLs.
ModificadaBaja (3.6)0.69%—Bottomline Webseries Payment Application11/1/200516/6/2026
The change password functionality in Bottomline Webseries Payment Application does not require the old password when users enter a new password, which could allow remote authenticated users to change other users' passwords.
ModificadaMedia (5)1.4%—Bottomline Webseries Payment Application10/1/200516/6/2026
Bottomline Webseries Payment Application allows remote attackers to read arbitrary files on the network via a report template with modified ReportPath or ReportName values.