Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

312 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.41%—Oracle Peoplesoft Enterprise Campus Software Campus Community17/6/202631/7/2026
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Interfaces). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise PeopleSoft Enterprise CS…
AnalizadaAlta (8.1)0.44%—Oracle Peoplesoft Enterprise Campus Software Campus Community17/6/202631/7/2026
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community.…
AplazadaMedia (5.9)0.43%—Fastnetmon Community EditionAI2/6/202622/7/2026
FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the IPv4 packet parser. In src/simple_packet_parser_ng.cpp, after validating that the packet contains at least sizeof(ipv4_header_t) bytes (20 bytes), the code advances the local_pointer by '4 * ipv4_header->get_ihl()' (line 164) without…
AnalizadaMedia (6.5)0.28%—Springaicommunity MCP Security29/5/202621/7/2026
mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mcp-security framework fails to implement the mandatory SSRF mitigations outlined in the Model Context Protocol (MCP) security specifications. Specifically, it processes untrusted URLs for…
AplazadaMedia (6.5)0.44%—Fastnetmon Community EditionAI26/5/202624/7/2026
FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read vulnerability in the NetFlow v9 data flowset processor. In src/netflow_plugin/netflow_v9_collector.cpp, the Data template branch (lines 1695-1702) iterates over flow records without performing a per-iteration bounds check against the packet end…
AnalizadaAlta (8.7)0.50%—Hacs Home Assistant Community Store16/5/202617/6/2026
Home Assistant Community Store (HACS) prior to 1.10.0 contains a path traversal vulnerability that allows unauthenticated attackers to read sensitive files by traversing directories via the /hacsfiles/ endpoint. Attackers can retrieve the .storage/auth file containing user credentials and refresh tokens, then craft…
AplazadaMedia (6.1)0.25%—Diskover-communityAI27/4/20265/7/2026
A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/selectindices.php via the namecontains parameter
AplazadaMedia (6.1)0.25%—Diskover-communityAI27/4/20265/7/2026
A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/view.php via the doctype parameter
AplazadaAlta (8.8)0.24%💥 PoCDiskoverdata Diskover-communityAI27/4/20265/7/2026
Cross Site Request Forgery vulnerability in diskoverdata diskover-community v.2.3.5. and before allows a remote attacker to escalate privileges and obtain sensitive information via the public/settings_process.php
AplazadaCrítica (9.8)0.47%—Sourcecodester Simple Music Cloud Community SystemAI16/4/202617/6/2026
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php.
AplazadaCrítica (9.8)0.47%—Sourcecodester Simple Music Cloud Community SystemAI16/4/202617/6/2026
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_genre.php.
AplazadaCrítica (9.4)0.41%—Sourcecodester Simple Music Cloud Community SystemAI16/4/202617/6/2026
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_user.php.
AplazadaAlta (7.3)0.29%—Sourcecodester Simple Music Cloud Community SystemAI16/4/202617/6/2026
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_playlist.php.
AplazadaAlta (7.3)0.29%—Sourcecodester Simple Music Cloud Community SystemAI16/4/202617/6/2026
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_music.php.
AnalizadaMedia (5.1)0.24%—Endian Firewall Community2/4/202624/7/2026
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/password/web/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.
AnalizadaMedia (5.1)0.15%—Endian Firewall Community2/4/202624/7/2026
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the new_cert_name parameter to /manage/ca/certificate/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.
AnalizadaMedia (5.1)0.27%—Endian Firewall Community2/4/202624/7/2026
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/vpnauthentication/user/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.
AnalizadaMedia (5.1)0.24%—Endian Firewall Community2/4/202624/7/2026
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/ipsec/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.
AnalizadaMedia (5.1)0.24%—Endian Firewall Community2/4/202624/7/2026
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the REMARK parameter to /cgi-bin/openvpnclient.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.
AnalizadaMedia (5.1)0.24%—Endian Firewall Community2/4/202624/7/2026
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dnsmasq/localdomains/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.
AnalizadaMedia (5.1)0.24%—Endian Firewall Community2/4/202624/7/2026
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the ADDRESS BCC parameter to /cgi-bin/smtprouting.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.
AnalizadaMedia (5.1)0.24%—Endian Firewall Community2/4/202624/7/2026
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the domain parameter to /manage/smtpscan/domainrouting/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.
AnalizadaMedia (5.1)0.24%—Endian Firewall Community2/4/202624/7/2026
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the DOMAIN parameter to /cgi-bin/smtpdomains.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.
AnalizadaMedia (5.1)0.24%—Endian Firewall Community2/4/202624/7/2026
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the group parameter to /cgi-bin/proxygroup.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.
AnalizadaMedia (5.1)0.24%—Endian Firewall Community2/4/202624/7/2026
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the user parameter to /cgi-bin/proxyuser.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.
Orbitaley — Vulnerabilidades