Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
58 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.25% | — | Flowdee Clickwhale | 29/1/2025 | 17/6/2026 | The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via link titles in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.32% | — | Cloud Whale Interactive Technology LLC Polybuzz IOSAI | 27/1/2025 | 17/6/2026 | An issue in Cloud Whale Interactive Technology LLC. PolyBuzz iOS 2.0.20 allows attackers to access sensitive user information via supplying a crafted link. | |
| Analizada | Media (6.1) | 0.35% | — | Flowdee Clickwhale | 11/1/2025 | 17/6/2026 | The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.4.1. This makes it… | |
| Modificada | Alta (8.5) | 0.38% | — | Flowdee Clickwhale | 7/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickWhale ClickWhale clickwhale allows Blind SQL Injection.This issue affects ClickWhale: from n/a through <= 2.4.1. | |
| Aplazada | Media (6.3) | 0.28% | — | Naver Whale Browser InstallerAI | 25/10/2024 | 17/6/2026 | Whale browser Installer before 3.1.0.0 allows an attacker to execute a malicious DLL in the user environment due to improper permission settings. | |
| Aplazada | Crítica (9.6) | 0.37% | — | Naver Whale BrowserAI | 11/7/2024 | 17/6/2026 | Whale browser before 3.26.244.21 allows an attacker to execute malicious JavaScript due to improper sanitization when processing a built-in extension. | |
| Analizada | Alta (7.5) | 0.62% | — | Icewhale Casaos-userservice | 1/4/2024 | 17/6/2026 | Go package IceWhaleTech/CasaOS-UserService provides user management functionalities to CasaOS. The Casa OS Login page has disclosed the username enumeration vulnerability in the login page which was patched in version 0.4.7. This issue in CVE-2024-28232 has been patched in version 0.4.8 but that version has not yet… | |
| Analizada | Alta (7.5) | 0.76% | — | Icewhale Casaos-userservice | 6/3/2024 | 17/6/2026 | CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, the Casa OS Login page disclosed the username enumeration vulnerability in the login page. An attacker can enumerate the CasaOS username using the application response. If the username is… | |
| Analizada | Crítica (9.8) | 0.98% | — | Icewhale Casaos | 6/3/2024 | 17/6/2026 | CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, CasaOS doesn't defend against password brute force attacks, which leads to having full access to the server. The web application lacks control over the login attempts. This vulnerability… | |
| Analizada | Crítica (9.8) | 0.97% | — | Icewhale Casaos | 6/3/2024 | 17/6/2026 | CasaOS-UserService provides user management functionalities to CasaOS. Prior to version 0.4.7, path filtering of the URL for user avatar image files was not strict, making it possible to get any file on the system. This could allow an unauthorized actor to access, for example, the CasaOS user database, and possibly… | |
| Modificada | Media (6.5) | 0.43% | — | Meiyou BIG Whale | 11/1/2024 | 17/6/2026 | A vulnerability was found in meetyoucrop big-whale 1.1 and classified as critical. Affected by this issue is some unknown functionality of the file /auth/user/all.api of the component Admin Module. The manipulation of the argument id leads to improper ownership management. The attack may be launched remotely. The… | |
| Modificada | Media (5.5) | 0.23% | — | Naver Whale Browser | 27/11/2023 | 17/6/2026 | The Android Mobile Whale browser app before 3.0.1.2 allows the attacker to bypass its browser unlock function via 'Open in Whale' feature. | |
| Modificada | Alta (8.8) | 1.6% | — | Icewhale Casaos | 24/8/2023 | 17/6/2026 | CasaOS is an open-source personal cloud system. Prior to version 0.4.4, if an authenticated user using CasaOS is able to successfully connect to a controlled SMB server, they are able to execute arbitrary commands. Version 0.4.4 contains a patch for the issue. | |
| Analizada | Crítica (9.8) | 6.8% | 💥 Exploit | Icewhale Casaos | 17/7/2023 | 17/6/2026 | CasaOS is an open-source Personal Cloud system. Unauthenticated attackers can craft arbitrary JWTs and access features that usually require authentication and execute arbitrary commands as `root` on CasaOS instances. This problem was addressed by improving the validation of JWTs in commit `705bf1f`. This patch is part… | |
| Analizada | Crítica (9.8) | 7.4% | 💥 Exploit | Icewhale CasaosIcewhale Casaos-gateway | 17/7/2023 | 17/6/2026 | CasaOS is an open-source Personal Cloud system. Due to a lack of IP address verification an unauthenticated attackers can execute arbitrary commands as `root` on CasaOS instances. The problem was addressed by improving the detection of client IP addresses in `391dd7f`. This patch is part of CasaOS 0.4.4. Users should… | |
| Modificada | Alta (8.8) | 1.1% | — | Whaleal Icefrog | 18/6/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in whaleal IceFrog 1.1.8. Affected is an unknown function of the component Aviator Template Engine. The manipulation leads to deserialization. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-231804. | |
| Modificada | Media (5.3) | 0.50% | — | Funkwhale | 9/12/2022 | 17/6/2026 | User invites for Funkwhale v1.2.8 do not permanently expire after being used for signup and can be used again after an account has been deleted. | |
| Modificada | Media (5.3) | 0.73% | — | Navercorp Whale | 27/6/2022 | 17/6/2026 | NAVER Whale browser mobile app before 1.10.6.2 allows the attacker to bypass its browser unlock function via incognito mode. | |
| Modificada | Media (6.5) | 0.88% | — | Navercorp Whale | 17/3/2022 | 17/6/2026 | Whale browser before 3.12.129.18 allowed extensions to replace JavaScript files of the HWP viewer website which could access to local HWP files. When the HWP files were opened, the replaced script could read the files. | |
| Modificada | Crítica (9.8) | 1.1% | — | Navercorp Whale | 17/3/2022 | 17/6/2026 | Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itself that could lead to controlling Whale Bridge if the rendering process compromises. | |
| Modificada | Alta (7.1) | 0.58% | — | Navercorp Whale | 17/3/2022 | 17/6/2026 | The Web Request API in Whale browser before 3.12.129.18 allowed to deny access to the extension store or redirect to any URL when users access the store. | |
| Modificada | Media (6.1) | 0.58% | — | Navercorp Whale | 17/3/2022 | 17/6/2026 | The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into the extension store web page via devtools.inspectedWindow, leading to extensions downloading and uploading when users open the developer tool. | |
| Modificada | Crítica (9.8) | 5.5% | — | Icewhale Casaos | 10/3/2022 | 17/6/2026 | CasaOS before v0.2.7 was discovered to contain a command injection vulnerability. | |
| Modificada | Media (4.3) | 0.65% | — | Navercorp Whale | 28/1/2022 | 17/6/2026 | A Built-in extension in Whale browser before 3.12.129.46 allows attackers to compromise the rendering process which could lead to controlling browser internal APIs. | |
| Modificada | Media (5.3) | 0.71% | — | Navercorp Whale | 2/11/2021 | 17/6/2026 | Whale browser for iOS before 1.14.0 has an inconsistent user interface issue that allows an attacker to obfuscate the address bar which may lead to address bar spoofing. |