Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

67 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.58%—Fastrack Reflex 2.0 Firmware26/12/202217/6/2026
fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows a Remote attacker to change the time, date, and month via Bluetooth LE Characteristics on handle 0x0017.
ModificadaAlta (7.5)0.92%—Fastrack Reflex 2.0 Firmware26/12/202217/6/2026
fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows an Unauthenticated Remote attacker to send a malicious firmware update via BLE and brick the device.
ModificadaAlta (7.5)0.63%—Finastra Nestjs-proxyNestjs-proxy Project Nestjs-proxy15/6/202217/6/2026
NestJS Proxy is a NestJS module to decorate and proxy calls. Prior to version 0.7.0, the nestjs-proxy library did not have a way to block sensitive cookies (e.g. session cookies) from being forwarded to backend services configured by the application developer. This could have led to sensitive cookies being…
ModificadaAlta (7.5)0.63%—Finastra Nestjs-proxyNestjs-proxy Project Nestjs-proxy15/6/202217/6/2026
NestJS Proxy is a NestJS module to decorate and proxy calls. Prior to version 0.7.0, the nestjs-proxy library did not have a way to control when Authorization headers should should be forwarded for specific backend services configured by the application developer. This could have resulted in sensitive information such…
ModificadaAlta (7.5)4.0%—Yaml Project YamlNetapp Astra Trident19/5/202217/6/2026
An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input.
ModificadaAlta (7.5)3.2%—Golang GONetapp Astra TridentDebian Linux5/3/202217/6/2026
regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression.
ModificadaMedia (6.5)1.1%—Finastra Ssr-pages1/3/202217/6/2026
ssr-pages is an HTML page builder for the purpose of server-side rendering (SSR). In versions prior to 0.1.4, a path traversal issue can occur when providing untrusted input to the `svg` property as an argument to the `build(MessagePageOptions)` function. While there is no known workaround at this time, there is a…
ModificadaMedia (6.1)0.87%—Finastra Ssr-pages1/3/202217/6/2026
ssr-pages is an HTML page builder for the purpose of server-side rendering (SSR). In versions prior to 0.1.5, a cross site scripting (XSS) issue can occur when providing untrusted input to the `redirect.link` property as an argument to the `build(MessagePageOptions)` function. While there is no known workaround at…
ModificadaCrítica (9.8)11%💥 PoCBrainstormforce Astra9/8/202117/6/2026
The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infinite AJAX action (available to both unauthenticated and authenticated user) before using them in SQL statement, leading to an SQL Injection…
ModificadaMedia (6.1)0.83%—Getastra WP Hardening21/6/202117/6/2026
The WP Hardening – Fix Your WordPress Security WordPress plugin before 1.2.2 did not sanitise or escape the historyvalue GET parameter before outputting it in a Javascript block, leading to a reflected Cross-Site Scripting issue.
ModificadaMedia (6.1)0.83%—Getastra WP Hardening21/6/202117/6/2026
The WP Hardening – Fix Your WordPress Security WordPress plugin before 1.2.2 did not sanitise or escape the $_SERVER['REQUEST_URI'] before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue.
ModificadaMedia (5)1.3%—Adastra Trace Mode Data Center18/4/201216/6/2026
Unspecified vulnerability in AdAstrA TRACE MODE Data Center allows remote attackers to read arbitrary files via unknown vectors, as demonstrated by the GLEG Agora SCADA+ Exploit Pack for Immunity CANVAS.
ModificadaAlta (7.5)2.6%💥 ExploitKevin Ludlow Austinsmoke Gastracker16/5/200816/6/2026
AustinSmoke GasTracker (AS-GasTracker) 1.0.0 allows remote attackers to bypass authentication and gain privileges by setting the gastracker_admin cookie to TRUE.
ModificadaMedia (5)1.4%—Aastra Telecom 9112i SIP Phone27/6/200716/6/2026
Format string vulnerability in the Aastra 9112i SIP Phone with firmware 1.4.0.1048 and boot version 1.1.0.10 allows remote attackers to cause a denial of service (blocked call reception and slow calling) via format string specifiers in an SDP header value, a different vulnerability than CVE-2007-3349.
ModificadaAlta (7.8)1.9%—Aastra Telecom 9112i SIP Phone22/6/200716/6/2026
The Aastra 9112i SIP Phone with firmware 1.4.0.1048 and boot version 1.1.0.10 allows remote attackers to (1) cause a denial of service (device freeze) via a malformed SIP message of a certain length or (2) cause a denial of service (continuous ring) via a malformed SIP message of a certain other length.
ModificadaAlta (7.5)3.7%—Denis Sbragion SredirdPeter Astrand Sercd31/12/200416/6/2026
Buffer overflow in the HandleCPCCommand function of sercd before 2.3.1 and sredird 2.2.1 and earlier allows remote attackers to execute arbitrary code.
ModificadaAlta (7.5)3.2%—Denis Sbragion SredirdPeter Astrand Sercd31/12/200416/6/2026
Format string vulnerability in the LogMsg function in sercd before 2.3.1 and sredird 2.2.1 and earlier allows remote attackers to execute arbitrary code via format string specifiers passed from the HandleCPCCommand function.
Orbitaley — Vulnerabilidades