Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
58 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.24% | — | Linuxfoundation Fluid | 8/5/2023 | 17/6/2026 | Fluid is an open source Kubernetes-native distributed dataset orchestrator and accelerator for data-intensive applications. Starting in version 0.7.0 and prior to version 0.8.6, if a malicious user gains control of a Kubernetes node running fluid csi pod (controlled by the `csi-nodeplugin-fluid` node-daemonset), they… | |
| Modificada | Media (5.5) | 0.94% | — | FluidsynthDebian Linux | 29/4/2021 | 17/6/2026 | fluidsynth is a software synthesizer based on the SoundFont 2 specifications. A use after free violation was discovered in fluidsynth, that can be triggered when loading an invalid SoundFont file. | |
| Modificada | Media (6.1) | 1.0% | — | Typo3 Fluid | 17/11/2020 | 17/6/2026 | TYPO3 Fluid before versions 2.0.8, 2.1.7, 2.2.4, 2.3.7, 2.4.4, 2.5.11 and 2.6.10 is vulnerable to Cross-Site Scripting. Three XSS vulnerabilities have been detected in Fluid: 1. TagBasedViewHelper allowed XSS through maliciously crafted additionalAttributes arrays by creating keys with attribute-closing quotes… | |
| Modificada | Media (6.1) | 0.97% | — | Typo3 Fluid EngineTypo3 | 8/10/2020 | 17/6/2026 | TYPO3 Fluid Engine (package `typo3fluid/fluid`) before versions 2.0.5, 2.1.4, 2.2.1, 2.3.5, 2.4.1, 2.5.5 or 2.6.1 is vulnerable to cross-site scripting when making use of the ternary conditional operator in templates like `{showFullName ? fullName : defaultValue}`. Updated versions of this package are bundled in… | |
| Modificada | Media (6.1) | 0.96% | — | Tonjoostudio Fluid-responsive-slideshow | 17/9/2019 | 17/6/2026 | The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has reflected XSS via the skin parameter. | |
| Modificada | Alta (8.8) | 0.73% | — | Tonjoostudio Fluid-responsive-slideshow | 17/9/2019 | 17/6/2026 | The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has frs_save CSRF with resultant stored XSS. | |
| Modificada | Media (5) | 1.7% | — | Fluidgames THE Rage | 23/3/2004 | 16/6/2026 | The Rage 1.01 and earlier allows remote attackers to cause a denial of service (infinite loop) via a TCP packet with the port and IP address set to zero. | |
| Modificada | Alta (7.5) | 7.2% | 💥 Exploit | Zoltan Milosevic Fluid Dynamics Search Engine | 4/10/2002 | 16/6/2026 | Cross-site scripting vulnerability in search.pl for Fluid Dynamics Search Engine (FDSE) before 2.0.0.0055 allows remote attackers to execute web script via the (1) Rank or (2) Match parameters. |