Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

102 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.6%—Alpinelinux Apk-tools21/4/202117/6/2026
In Alpine Linux apk-tools before 2.12.5, the tarball parser allows a buffer overflow and crash.
ModificadaMedia (6.5)0.94%—Spinetix DsosSpinetix Hmp350 FirmwareSpinetix Hmp300 FirmwareSpinetix Diva Firmware+224/3/202117/6/2026
spxmanage on certain SpinetiX devices allows requests that access unintended resources because of SSRF and Path Traversal. This affects HMP350, HMP300, and DiVA through 4.5.2-1.0.36229; HMP400 and HMP400W through 4.5.2-1.0.2-1eb2ffbd; and DSOS through 4.5.2-1.0.2-1eb2ffbd.
ModificadaCrítica (9.8)2.2%—Kong Alpine Docker Image17/12/202017/6/2026
The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System using the kong docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
ModificadaCrítica (9.8)2.9%—Ghost Alpine Docker Image17/12/202017/6/2026
The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user. System using the ghost docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
ModificadaCrítica (9.8)2.3%—Spiped Alpine Docker Image8/12/202017/6/2026
The official spiped docker images before 1.5-alpine contain a blank password for a root user. Systems using the spiped docker container deployed by affected versions of the docker image may allow an remote attacker to achieve root access with a blank password.
ModificadaCrítica (9.8)2.9%—Elixir Alpine Docker Image8/12/202017/6/2026
The official elixir Docker images before 1.8.0-alpine (Alpine specific) contain a blank password for a root user. Systems using the elixir Linux Docker container deployed by affected versions of the Docker image may allow a remote attacker to achieve root access with a blank password.
ModificadaCrítica (9.8)2.3%—Matomo Piwik Fpm-alpine Docker Image8/12/202017/6/2026
The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems using the Piwik Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access.
ModificadaAlta (7.5)1.8%—Alpine Project AlpineFedoraproject FedoraDebian Linux19/6/202017/6/2026
Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do.
ModificadaMedia (6.5)0.87%—Thealpinepress Alpine-photo-tile-for-instagram26/9/201917/6/2026
The alpine-photo-tile-for-instagram plugin before 1.2.7.6 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=alpine-photo-tile-for-instagram-settings tab parameter.
ModificadaMedia (6.5)1.3%—Alpinelinux Abuild18/6/201917/6/2026
Alpine Linux abuild through 3.4.0 allows an unprivileged member of the abuild group to add an untrusted package via a --keys-dir option that causes acceptance of an untrusted signing key.
ModificadaCrítica (9.8)6.3%—Gliderlabs Docker-alpineOpensuse LeapF5 Big-ip Controller8/5/201917/6/2026
Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using affected versions of the Alpine Linux container which utilize…
ModificadaAlta (8.8)3.5%—Alpinelinux Alpine Linux20/12/201817/6/2026
Alpine Linux version Versions prior to 2.6.10, 2.7.6, and 2.10.1 contains a Other/Unknown vulnerability in apk-tools (Alpine Linux' package manager) that can result in Remote Code Execution. This attack appear to be exploitable via A specially crafted APK-file can cause apk to write arbitrary data to an…
ModificadaAlta (7.8)3.2%—Alpinelinux Alpine Linux17/7/201717/6/2026
A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker to cause a denial of service, or achieve code execution, by crafting a malicious APKINDEX.tar.gz file with a bad pax header block.
ModificadaAlta (7.8)3.2%—Alpinelinux Alpine Linux17/7/201717/6/2026
A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker to cause a denial of service, or achieve code execution by crafting a malicious APKINDEX.tar.gz file.
ModificadaAlta (7.5)37%—Hak5 Wi-fi Pineapple Firmware31/3/201717/6/2026
Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
ModificadaAlta (7.8)1.6%—Philippine Long Distance Telephone Kasda Kw58293 FirmwarePhilippine Long Distance Telephone Speedsurf 504an Firmware21/9/201517/6/2026
Buffer overflow in form2ping.cgi on Philippine Long Distance Telephone (PLDT) SpeedSurf 504AN devices with firmware GAN9.8U26-4-TX-R6B018-PH.EN and Kasda KW58293 devices allows remote attackers to cause a denial of service (device outage) via a long ipaddr parameter.
ModificadaMedia (4.3)1.2%—Philippine Long Distance Telephone Speedsurf 504an FirmwarePhilippine Long Distance Telephone Kasda Kw58293 Firmware21/9/201517/6/2026
Cross-site scripting (XSS) vulnerability in form2WlanSetup.cgi on Philippine Long Distance Telephone (PLDT) SpeedSurf 504AN devices with firmware GAN9.8U26-4-TX-R6B018-PH.EN and Kasda KW58293 devices allows remote attackers to inject arbitrary web script or HTML via the ssid parameter.
ModificadaMedia (6.8)0.66%—Philippine Long Distance Telephone Speedsurf 504an FirmwarePhilippine Long Distance Telephone Kasda Kw58293 Firmware21/9/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in form2WlanSetup.cgi on Philippine Long Distance Telephone (PLDT) SpeedSurf 504AN devices with firmware GAN9.8U26-4-TX-R6B018-PH.EN and Kasda KW58293 devices allows remote attackers to hijack the authentication of administrators for requests that perform setup…
ModificadaAlta (7.2)1.0%—Pineapp Mail-secure 5099sk20/11/201317/6/2026
PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms has a sudoers file that does not properly restrict user specifications, which allows local users to gain privileges via a sudo command that leverages access to the qmailq account.
ModificadaAlta (7.5)8.9%—Pineapp Mail-secure 5099sk20/11/201317/6/2026
admin/confnetworking.html in PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms allows remote attackers to execute arbitrary commands via shell metacharacters in the nsserver parameter during an nslookup operation.
ModificadaAlta (7.5)80%—Pineapp Mail-secure20/11/201317/6/2026
admin/confnetworking.html in PineApp Mail-SeCure allows remote attackers to execute arbitrary commands via shell metacharacters in the pinghost parameter during a ping operation.
ModificadaMedia (6.4)1.3%—Pineapp Mail-secure20/11/201317/6/2026
admin/management.html in PineApp Mail-SeCure allows remote attackers to bypass authentication and perform a sys_usermng operation via the it parameter.
ModificadaMedia (5)1.4%—Pineapp Mail-secure20/11/201317/6/2026
Absolute path traversal vulnerability in admin/viewmsg.php in PineApp Mail-SeCure allows remote attackers to read arbitrary files via a full pathname in the msg parameter.
ModificadaAlta (8.5)2.6%—Pineapp Mail-secure8/11/201316/6/2026
PineApp Mail-SeCure before 3.70 allows remote authenticated users to gain privileges by leveraging console access and providing shell metacharacters in a "system ping" command.
ModificadaAlta (7.5)0.91%—Sopinet COM Jbudgetsmagic23/9/200916/6/2026
SQL injection vulnerability in the JBudgetsMagic (com_jbudgetsmagic) component 0.3.2 through 0.4.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the bid parameter in a mybudget action to index.php.