Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
312 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.41% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 17/6/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Interfaces). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise PeopleSoft Enterprise CS… | |
| Analizada | Alta (8.1) | 0.44% | — | Oracle Peoplesoft Enterprise Campus Software Campus Community | 17/6/2026 | 31/7/2026 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community.… | |
| Aplazada | Media (5.9) | 0.43% | — | Fastnetmon Community EditionAI | 2/6/2026 | 22/7/2026 | FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the IPv4 packet parser. In src/simple_packet_parser_ng.cpp, after validating that the packet contains at least sizeof(ipv4_header_t) bytes (20 bytes), the code advances the local_pointer by '4 * ipv4_header->get_ihl()' (line 164) without… | |
| Analizada | Media (6.5) | 0.28% | — | Springaicommunity MCP Security | 29/5/2026 | 21/7/2026 | mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mcp-security framework fails to implement the mandatory SSRF mitigations outlined in the Model Context Protocol (MCP) security specifications. Specifically, it processes untrusted URLs for… | |
| Aplazada | Media (6.5) | 0.44% | — | Fastnetmon Community EditionAI | 26/5/2026 | 24/7/2026 | FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read vulnerability in the NetFlow v9 data flowset processor. In src/netflow_plugin/netflow_v9_collector.cpp, the Data template branch (lines 1695-1702) iterates over flow records without performing a per-iteration bounds check against the packet end… | |
| Analizada | Alta (8.7) | 0.50% | — | Hacs Home Assistant Community Store | 16/5/2026 | 17/6/2026 | Home Assistant Community Store (HACS) prior to 1.10.0 contains a path traversal vulnerability that allows unauthenticated attackers to read sensitive files by traversing directories via the /hacsfiles/ endpoint. Attackers can retrieve the .storage/auth file containing user credentials and refresh tokens, then craft… | |
| Aplazada | Media (6.1) | 0.25% | — | Diskover-communityAI | 27/4/2026 | 5/7/2026 | A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/selectindices.php via the namecontains parameter | |
| Aplazada | Media (6.1) | 0.25% | — | Diskover-communityAI | 27/4/2026 | 5/7/2026 | A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/view.php via the doctype parameter | |
| Aplazada | Alta (8.8) | 0.24% | 💥 PoC | Diskoverdata Diskover-communityAI | 27/4/2026 | 5/7/2026 | Cross Site Request Forgery vulnerability in diskoverdata diskover-community v.2.3.5. and before allows a remote attacker to escalate privileges and obtain sensitive information via the public/settings_process.php | |
| Aplazada | Crítica (9.8) | 0.47% | — | Sourcecodester Simple Music Cloud Community SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Sourcecodester Simple Music Cloud Community SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_genre.php. | |
| Aplazada | Crítica (9.4) | 0.41% | — | Sourcecodester Simple Music Cloud Community SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_user.php. | |
| Aplazada | Alta (7.3) | 0.29% | — | Sourcecodester Simple Music Cloud Community SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_playlist.php. | |
| Aplazada | Alta (7.3) | 0.29% | — | Sourcecodester Simple Music Cloud Community SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_music.php. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/password/web/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.15% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the new_cert_name parameter to /manage/ca/certificate/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.27% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/vpnauthentication/user/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/ipsec/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the REMARK parameter to /cgi-bin/openvpnclient.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dnsmasq/localdomains/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the ADDRESS BCC parameter to /cgi-bin/smtprouting.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the domain parameter to /manage/smtpscan/domainrouting/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the DOMAIN parameter to /cgi-bin/smtpdomains.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the group parameter to /cgi-bin/proxygroup.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | |
| Analizada | Media (5.1) | 0.24% | — | Endian Firewall Community | 2/4/2026 | 24/7/2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the user parameter to /cgi-bin/proxyuser.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. |