Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

58 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.25%—Flowdee Clickwhale29/1/202517/6/2026
The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via link titles in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (6.5)0.32%—Cloud Whale Interactive Technology LLC Polybuzz IOSAI27/1/202517/6/2026
An issue in Cloud Whale Interactive Technology LLC. PolyBuzz iOS 2.0.20 allows attackers to access sensitive user information via supplying a crafted link.
AnalizadaMedia (6.1)0.35%—Flowdee Clickwhale11/1/202517/6/2026
The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.4.1. This makes it…
ModificadaAlta (8.5)0.38%—Flowdee Clickwhale7/1/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickWhale ClickWhale clickwhale allows Blind SQL Injection.This issue affects ClickWhale: from n/a through <= 2.4.1.
AplazadaMedia (6.3)0.28%—Naver Whale Browser InstallerAI25/10/202417/6/2026
Whale browser Installer before 3.1.0.0 allows an attacker to execute a malicious DLL in the user environment due to improper permission settings.
AplazadaCrítica (9.6)0.37%—Naver Whale BrowserAI11/7/202417/6/2026
Whale browser before 3.26.244.21 allows an attacker to execute malicious JavaScript due to improper sanitization when processing a built-in extension.
AnalizadaAlta (7.5)0.62%—Icewhale Casaos-userservice1/4/202417/6/2026
Go package IceWhaleTech/CasaOS-UserService provides user management functionalities to CasaOS. The Casa OS Login page has disclosed the username enumeration vulnerability in the login page which was patched in version 0.4.7. This issue in CVE-2024-28232 has been patched in version 0.4.8 but that version has not yet…
AnalizadaAlta (7.5)0.76%—Icewhale Casaos-userservice6/3/202417/6/2026
CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, the Casa OS Login page disclosed the username enumeration vulnerability in the login page. An attacker can enumerate the CasaOS username using the application response. If the username is…
AnalizadaCrítica (9.8)0.98%—Icewhale Casaos6/3/202417/6/2026
CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, CasaOS doesn't defend against password brute force attacks, which leads to having full access to the server. The web application lacks control over the login attempts. This vulnerability…
AnalizadaCrítica (9.8)0.97%—Icewhale Casaos6/3/202417/6/2026
CasaOS-UserService provides user management functionalities to CasaOS. Prior to version 0.4.7, path filtering of the URL for user avatar image files was not strict, making it possible to get any file on the system. This could allow an unauthorized actor to access, for example, the CasaOS user database, and possibly…
ModificadaMedia (6.5)0.43%—Meiyou BIG Whale11/1/202417/6/2026
A vulnerability was found in meetyoucrop big-whale 1.1 and classified as critical. Affected by this issue is some unknown functionality of the file /auth/user/all.api of the component Admin Module. The manipulation of the argument id leads to improper ownership management. The attack may be launched remotely. The…
ModificadaMedia (5.5)0.23%—Naver Whale Browser27/11/202317/6/2026
The Android Mobile Whale browser app before 3.0.1.2 allows the attacker to bypass its browser unlock function via 'Open in Whale' feature.
ModificadaAlta (8.8)1.6%—Icewhale Casaos24/8/202317/6/2026
CasaOS is an open-source personal cloud system. Prior to version 0.4.4, if an authenticated user using CasaOS is able to successfully connect to a controlled SMB server, they are able to execute arbitrary commands. Version 0.4.4 contains a patch for the issue.
AnalizadaCrítica (9.8)6.8%💥 ExploitIcewhale Casaos17/7/202317/6/2026
CasaOS is an open-source Personal Cloud system. Unauthenticated attackers can craft arbitrary JWTs and access features that usually require authentication and execute arbitrary commands as `root` on CasaOS instances. This problem was addressed by improving the validation of JWTs in commit `705bf1f`. This patch is part…
AnalizadaCrítica (9.8)7.4%💥 ExploitIcewhale CasaosIcewhale Casaos-gateway17/7/202317/6/2026
CasaOS is an open-source Personal Cloud system. Due to a lack of IP address verification an unauthenticated attackers can execute arbitrary commands as `root` on CasaOS instances. The problem was addressed by improving the detection of client IP addresses in `391dd7f`. This patch is part of CasaOS 0.4.4. Users should…
ModificadaAlta (8.8)1.1%—Whaleal Icefrog18/6/202317/6/2026
A vulnerability classified as problematic has been found in whaleal IceFrog 1.1.8. Affected is an unknown function of the component Aviator Template Engine. The manipulation leads to deserialization. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-231804.
ModificadaMedia (5.3)0.50%—Funkwhale9/12/202217/6/2026
User invites for Funkwhale v1.2.8 do not permanently expire after being used for signup and can be used again after an account has been deleted.
ModificadaMedia (5.3)0.73%—Navercorp Whale27/6/202217/6/2026
NAVER Whale browser mobile app before 1.10.6.2 allows the attacker to bypass its browser unlock function via incognito mode.
ModificadaMedia (6.5)0.88%—Navercorp Whale17/3/202217/6/2026
Whale browser before 3.12.129.18 allowed extensions to replace JavaScript files of the HWP viewer website which could access to local HWP files. When the HWP files were opened, the replaced script could read the files.
ModificadaCrítica (9.8)1.1%—Navercorp Whale17/3/202217/6/2026
Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itself that could lead to controlling Whale Bridge if the rendering process compromises.
ModificadaAlta (7.1)0.58%—Navercorp Whale17/3/202217/6/2026
The Web Request API in Whale browser before 3.12.129.18 allowed to deny access to the extension store or redirect to any URL when users access the store.
ModificadaMedia (6.1)0.58%—Navercorp Whale17/3/202217/6/2026
The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into the extension store web page via devtools.inspectedWindow, leading to extensions downloading and uploading when users open the developer tool.
ModificadaCrítica (9.8)5.5%—Icewhale Casaos10/3/202217/6/2026
CasaOS before v0.2.7 was discovered to contain a command injection vulnerability.
ModificadaMedia (4.3)0.65%—Navercorp Whale28/1/202217/6/2026
A Built-in extension in Whale browser before 3.12.129.46 allows attackers to compromise the rendering process which could lead to controlling browser internal APIs.
ModificadaMedia (5.3)0.71%—Navercorp Whale2/11/202117/6/2026
Whale browser for iOS before 1.14.0 has an inconsistent user interface issue that allows an attacker to obfuscate the address bar which may lead to address bar spoofing.
Orbitaley — Vulnerabilidades