Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

608 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.63%—Perl Date ManipAI30/7/20262/9/2026
Date::Manip versions through 7.00 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time. _parse_time removes a time from anywhere in the string with the unanchored substitution `s/$timerx/ /`, where $timerx is an auto-generated alternation of time patterns reached…
AplazadaAlta (7.5)0.63%—Date ManipAI30/7/20262/9/2026
Date::Manip versions through 7.00 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check. The parse regexes capture year, month and day with the `\d` shorthand, which on a character string matches the whole Unicode decimal digit property `\p{Nd}` and not just `[0-9]`.…
AplazadaAlta (7.8)0.84%—Tubitak Bilgem Pardus-updateAI23/7/202623/7/2026
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-update allows OS Command Injection. This issue affects pardus-update: from 0.6.6 before 0.7.0.
AplazadaAlta (7.5)0.63%—Http DateAI17/7/202612/8/2026
HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date. parse_date() matches the date string against a chain of alternative regexes, and str2time() delegates to it. Several of these patterns place unbounded quantifiers next to each other before a trailing `\s*$`…
AplazadaMedia (5.9)0.15%—ABB KNX Update ToolAIBJE KNX Update ToolAI17/7/202617/7/2026
Missing support for integrity check vulnerability in ABB KNX Update Tool (ABB), ABB KNX Update Tool (BJE). This issue affects KNX Update Tool (ABB): through 2.0.175; KNX Update Tool (BJE): through 2.0.175.
AplazadaAlta (8.3)0.19%—Capgo Capacitor UpdaterAI10/7/202610/7/2026
In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key to each device that downloads the app. Because the public key can be derived from the private key, an attacker performing a man-in-the-middle attack or compromising the Capgo server can create a…
AplazadaMedia (5.3)0.47%—Bulk Order Update FOR WoocommerceAI8/7/20268/7/2026
The Bulk Order Update for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 1.6. This is due to the bouw_fetch_csv_data() AJAX handler being registered on the wp_ajax_nopriv_ hook with no capability or nonce check, and passing the attacker-supplied csv_url POST…
AplazadaCrítica (9.1)0.61%—Owncloud CoreAIOwncloud UpdaterAI6/7/202630/9/2026
ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classic. In versions prior to 10.15.3, the Updater on ownCloud 10 before 10.15.3 has an exposed dangerous method or function. Attackers with administrative privileges may leverage functionality to execute…
AplazadaAlta (7.8)0.14%—Tubitak Bilgem Pardus UpdateAI5/7/20266/7/2026
Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Update allows Privilege Escalation. This issue affects Pardus Update: from <=0.6.3 before 0.6.6.
AplazadaAlta (8.5)0.15%—Expressupdate AgentAI26/6/202626/6/2026
An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code could be executed with SYSTEM privileges.
ModificadaCrítica (9.2)6.5%—F5 DOSF5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance Manager+717/6/202614/9/2026
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the…
AplazadaAlta (7.1)0.18%—Sweetdate CoreAI17/6/20265/10/2026
Unauthenticated Cross Site Scripting (XSS) in SweetDate Core < 1.1.5 versions.
AplazadaCrítica (9.3)0.40%—Order Delivery DateAI15/6/202617/6/2026
Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions.
Pendiente de análisisAlta (7.3)0.10%—SwupdateAI3/6/202622/7/2026
SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivileged attackers to escalate privileges to root or install untrusted contents using a signed update.
AplazadaMedia (6.4)0.32%—Image Attributes From Filename With Bulk UpdaterAI2/6/202622/7/2026
The Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment metadata in all versions up to, and including, 4.9 due to insufficient input sanitization and output escaping. This makes it possible…
AplazadaMedia (6.4)0.35%—Datenverwurstungszentrale Shariff WrapperAI28/5/202617/6/2026
The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headline' parameter in the [shariff] shortcode in all versions up to, and including, 4.6.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.1)0.35%—Easyupdatesmanager Easy Updates ManagerAI28/5/202617/6/2026
The Easy Updates Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'paged' parameter in versions up to, and including, 9.0.20 This is due to insufficient input sanitization and output escaping in the pagination() function. This makes it possible for attackers to inject arbitrary web…
AplazadaMedia (4.3)0.27%—Prasadkirpekar WP Meta AND Date RemoverAI27/5/202617/6/2026
Missing Authorization vulnerability in Prasad Kirpekar WP Meta and Date Remover allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Meta and Date Remover: from n/a through 2.3.6.
ModificadaAlta (7.8)0.26%—Opensuse LibsolvRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Satellite+226/5/20262/10/2026
A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds…
ModificadaCrítica (9.2)2.7%—F5 Nginx Open SourceF5 Nginx PlusF5 DOSF5 Nginx Gateway Fabric+822/5/202625/8/2026
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple…
ModificadaMedia (6.5)0.57%—Opensuse LibsolvRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Satellite+221/5/20261/9/2026
A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to…
ModificadaMedia (6.5)0.58%—Opensuse LibsolvRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Satellite+220/5/20261/9/2026
A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service…
AnalizadaCrítica (9.8)0.49%—Date Ical Project Date Ical19/5/202623/7/2026
Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing. This issue affects Date iCal: from 0.0.0 before 4.0.15.
AplazadaAlta (8.2)0.50%—Date Menu OF News ArticlesAI19/5/202617/6/2026
The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrary SQL through a URL parameter on pages using the "Date Menu of news articles" plugin. Exploitation requires the "Date Menu of news articles" plugin to be in use and the…
ModificadaAlta (7.5)1.1%—GnutlsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux+1018/5/20262/10/2026
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable…