Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
33 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.53% | — | Wallosapp Wallos | 7/3/2026 | 17/6/2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, the url parameter can be used to retrieve local system files. This issue has been patched in version 4.6.2. | |
| Analizada | Alta (7.7) | 0.43% | — | Wallosapp Wallos | 21/2/2026 | 17/6/2026 | Wallos is an open-source, self-hostable personal subscription tracker. Versions 4.6.0 and below contain a Server-Side Request Forgery (SSRF) vulnerability in the subscription and payment logo/icon upload functionality. The application validates the IP address of the provided URL before making the request, but allows… | |
| Aplazada | Alta (7.3) | 0.15% | — | Wallosapp WallosAI | 14/10/2025 | 5/7/2026 | A Cross-Site Request Forgery (CSRF) in the component /endpoints/currency/currency of Wallos v4.1.1 allows attackers to execute arbitrary operations via a crafted GET request. | |
| Analizada | Crítica (9.8) | 0.64% | — | Wallosapp Wallos | 16/4/2025 | 17/6/2026 | Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to restore database by uploading a ZIP file. The contents of the ZIP file are extracted on the server. This functionality enables an unauthenticated attacker to upload malicious files to the server.… | |
| Analizada | Crítica (9.8) | 0.62% | — | Wallosapp Wallos | 16/4/2025 | 17/6/2026 | Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to restore backups by uploading a ZIP file. The contents of the ZIP file are extracted on the server. This functionality enables an authenticated attacker (being an administrator is not required) to upload… | |
| Analizada | Media (6.1) | 0.45% | — | Wallosapp Wallos | 23/1/2025 | 17/6/2026 | Cross Site Scripting vulnerability in Wallos v.2.41.0 allows a remote attacker to execute arbitrary code via the profile picture function. | |
| Analizada | Alta (8.1) | 0.67% | — | Wallosapp Wallos | 30/4/2024 | 17/6/2026 | Wallos before 1.15.3 is vulnerable to SQL Injection via the category and payment parameters to /subscriptions/get.php. | |
| Analizada | Media (4.7) | 0.47% | — | Wallosapp Wallos | 23/2/2024 | 17/6/2026 | Wallos 0.9 is vulnerable to Cross Site Scripting (XSS) in all text-based input fields without proper validation, excluding those requiring specific formats like date fields. |