Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

85 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.4)0.51%—Arni Cinco Wpcargo Track TraceAI13/12/202417/6/2026
Missing Authorization vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPCargo Track & Trace: from n/a through <= 8.0.2.
AnalizadaAlta (8.8)0.56%—Mediawiki Cargo5/10/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows SQL Injection.This issue affects Mediawiki - Cargo: from 3.6.X before 3.6.1.
AnalizadaMedia (6.9)0.41%—Mediawiki Cargo5/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Cargo: from 3.6.X before 3.6.1.
AnalizadaMedia (6.9)0.29%—Mediawiki Cargo5/10/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows Cross Site Request Forgery.This issue affects Mediawiki - Cargo: from 3.6.X before 3.6.1.
AplazadaMedia (6.9)0.46%—Samsung EscargotAI10/9/202417/6/2026
Heap-based Buffer Overflow vulnerability in Samsung Open Source Escargot JavaScript engine allows Overflow Buffers.This issue affects Escargot: 4.0.0.
ModificadaMedia (6.9)0.49%—Samsung Escargot29/7/202417/6/2026
Heap-based Buffer Overflow vulnerability in Samsung Open Source Escargot JavaScript engine allows Overflow Buffers.This issue affects Escargot: 4.0.0.
AplazadaMedia (5.3)0.79%—Samsung EscargotAI14/5/202417/6/2026
A Segmentation Fault issue discovered in Samsung Open Source Escargot JavaScript engine allows remote attackers to cause a denial of service via crafted input. This issue affects Escargot: 4.0.0.
AplazadaMedia (5.3)0.65%—Samsung EscargotAI14/5/202417/6/2026
Improper Input Validation vulnerability in Samsung Open Source escargot JavaScript engine allows Overflow Buffers. However, it occurs in the test code and does not include in the release. This issue affects escargot: 4.0.0.
AplazadaAlta (8.6)0.59%—Mediawiki CargoAI27/3/202417/6/2026
An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. There is mishandling of backticks to smartSplit.
ModificadaCrítica (9.8)0.71%—Samsung Escargot6/12/202317/6/2026
Improper input validation vulnerability in Samsung Open Source Escargot allows stack overflow and segmentation fault. This issue affects Escargot: from 3.0.0 through 4.0.0.
ModificadaAlta (7.3)0.70%💥 PoCRust-lang CargoFedoraproject Fedora4/8/202317/6/2026
Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local…
ModificadaAlta (7.8)0.24%—IBM Aspera CargoIBM Aspera Connect5/6/202317/6/2026
IBM Aspera Connect 4.2.5 and IBM Aspera Cargo 4.2.5 is vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overflow a buffer and execute arbitrary code on the system. IBM X-Force ID: 248625.
ModificadaAlta (7.5)0.55%—IBM Aspera CargoIBM Aspera Connect5/6/202317/6/2026
IBM Aspera Connect 4.2.5 and IBM Aspera Cargo 4.2.5 transmits authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
ModificadaAlta (8.8)0.85%—Armoli Cargo Tracking System24/5/202317/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Armoli Technology Cargo Tracking System allows Authentication Abuse, Authentication Bypass. This issue affects Cargo Tracking System: before 3558f28 .
ModificadaMedia (4.8)0.55%—AIR Cargo Management System Project AIR Cargo Management System18/4/202317/6/2026
A vulnerability was found in SourceCodester Air Cargo Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file classes/Master.php?f=save_cargo_type. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The…
ModificadaCrítica (9.8)0.81%—AIR Cargo Management System Project AIR Cargo Management System5/4/202317/6/2026
A vulnerability has been found in SourceCodester Air Cargo Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/transactions/track_shipment.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection.…
ModificadaCrítica (9.8)0.66%—IBM Aspera CargoIBM Aspera Connect2/4/202317/6/2026
IBM Aspera Cargo 4.2.5 and IBM Aspera Connect 4.2.5 are vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overflow a buffer and execute arbitrary code on the system. IBM X-Force ID: 248616.
ModificadaCrítica (9.8)0.66%—IBM Aspera CargoIBM Aspera Connect2/4/202317/6/2026
IBM Aspera Cargo 4.2.5 and IBM Aspera Connect 4.2.5 are vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overflow a buffer and execute arbitrary code on the system. IBM X-Force ID: 248616.
ModificadaCrítica (9.8)0.73%—AIR Cargo Management System Project AIR Cargo Management System30/3/202317/6/2026
A vulnerability was found in SourceCodester Air Cargo Management System 1.0. It has been classified as critical. Affected is an unknown function of the file admin/user/manage_user.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to launch the attack…
ModificadaCrítica (9.8)0.80%—AIR Cargo Management System Project AIR Cargo Management System22/3/202317/6/2026
A vulnerability was found in SourceCodester Air Cargo Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin/transactions/update_status.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack…
ModificadaMedia (5.9)0.65%—Rust-lang Cargo11/1/202317/6/2026
Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes and dependencies via SSH. An attacker could exploit this to perform man-in-the-middle (MITM) attacks. This vulnerability has been assigned CVE-2022-46176. All Rust…
ModificadaMedia (6.5)0.95%—Rust-lang Cargo14/9/202217/6/2026
Cargo is a package manager for the rust programming language. It was discovered that Cargo did not limit the amount of data extracted from compressed archives. An attacker could upload to an alternate registry a specially crafted package that extracts way more data than its size (also known as a "zip bomb"),…
ModificadaAlta (8.1)1.2%—Rust-lang Cargo14/9/202217/6/2026
Cargo is a package manager for the rust programming language. After a package is downloaded, Cargo extracts its source code in the ~/.cargo folder on disk, making it available to the Rust projects it builds. To record when an extraction is successful, Cargo writes "ok" to the .cargo-ok file at the root of the…
ModificadaMedia (6.5)0.87%—AIR Cargo Management System Project AIR Cargo Management System13/5/202217/6/2026
Air Cargo Management System v1.0 is vulnerable to file deletion via /acms/classes/Master.php?f=delete_img.
ModificadaAlta (7.2)0.97%—AIR Cargo Management System Project AIR Cargo Management System13/5/202217/6/2026
Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/admin/?page=transactions/manage_transaction&id=.
Orbitaley — Vulnerabilidades