Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
146 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.22% | — | Code16 SharpAILaravelAI | 28/10/2025 | 30/9/2026 | Sharp is a content management framework built for Laravel as a package. Prior to 9.11.1, a Cross-Site Scripting (XSS) vulnerability was discovered in code16/sharp when rendering content using the SharpShowTextField component. In affected versions, expressions wrapped in {{ & }} were evaluated by Vue. This allowed… | |
| Aplazada | Media (6.1) | 0.33% | — | Code16 SharpAI | 21/10/2025 | 17/6/2026 | code16 Sharp v9.6.6 is vulnerable to Cross Site Scripting (XSS) src/Form/Fields/SharpFormUploadField.php. | |
| Rechazada | Sin puntuar | — | — | Unisharp Laravel-filemanagerAI | 5/9/2025 | 5/9/2025 | Rejected reason: The unisharp/laravel-filemanager is a separate project, unrelated to laravel-filemanager. | |
| Aplazada | Media (5.3) | 0.39% | — | Sixlabors ImagesharpAI | 30/7/2025 | 17/6/2026 | ImageSharp is a 2D graphics library. In versions below 2.1.11 and 3.0.0 through 3.1.10, a specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite loop while attempting to skip the block. This leads to a denial… | |
| Aplazada | Crítica (9.2) | 0.26% | — | YoutubedlsharpAIYtdlp Yt-dlpAIYoutube-dlAI | 24/4/2025 | 17/6/2026 | YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.0-beta4 and prior to 1.1.2, an unsafe conversion of arguments allows the injection of a malicious commands when starting `yt-dlp` from a commands prompt running on Windows OS with the… | |
| Analizada | Alta (7.5) | 0.57% | — | Sixlabors Imagesharp | 6/3/2025 | 17/6/2026 | ImageSharp is a 2D graphics API. An Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. The problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10. | |
| Analizada | Alta (7.8) | 0.14% | — | Jetbrains DottraceJetbrains ETW Host ServiceJetbrains ResharperJetbrains Rider | 28/1/2025 | 17/6/2026 | In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace before 2024.3.4, 2024.2.8, and 2024.1.7, ETW Host Service before 16.43, Local Privilege Escalation via the ETW Host Service was possible | |
| Aplazada | Media (5.9) | 0.50% | — | Sharp RouterAI | 23/12/2024 | 17/6/2026 | Multiple SHARP routers contain an improper authentication vulnerability in the configuration backup function. The product's backup files containing sensitive information may be retrieved by a remote unauthenticated attacker. | |
| Aplazada | Crítica (9.8) | 0.74% | — | Sharp RouterAI | 23/12/2024 | 17/6/2026 | Multiple SHARP routers leave the hidden debug function enabled. An arbitrary OS command may be executed with the root privilege by a remote unauthenticated attacker. | |
| Aplazada | Alta (8.9) | 1.3% | — | Unisharp Laravel-filemanagerAI | 18/12/2024 | 17/6/2026 | Versions of the package unisharp/laravel-filemanager before 2.9.1 are vulnerable to Remote Code Execution (RCE) through using a valid mimetype and inserting the . character after the php file extension. This allows the attacker to execute malicious code. | |
| Aplazada | Alta (7.5) | 0.72% | — | Sharp MFPAIToshibatec MFPAI | 26/11/2024 | 17/6/2026 | Out-of-bounds read vulnerability exists in Sharp Corporation and Toshiba Tec Corporation multiple MFPs (multifunction printers), which may lead to a denial-of-service (DoS) condition. | |
| Aplazada | Alta (7.4) | 0.53% | — | Sharp Corporation MFPAIToshiba Tech Corporation MFPAI | 26/11/2024 | 17/6/2026 | Cross-site scripting vulnerability exists in Sharp Corporation and Toshiba Tech Corporation multiple MFPs (multifunction printers). If this vulnerability is exploited, an arbitrary script may be executed on the administrative page of the affected MFPs. As for the details of affected product names, model numbers, and… | |
| Aplazada | Media (5.3) | 0.89% | — | SharpAI | 26/11/2024 | 17/6/2026 | Admin authentication can be bypassed with some specific invalid credentials, which allows logging in with an administrative privilege. Sharp Corporation states the telnet feature is implemented on older models only, and is planning to provide the firmware update to remove the feature. As for the details of affected… | |
| Analizada | Media (4.8) | 0.35% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site scripting vulnerability. If crafted input is stored by an administrative user, malicious script may be executed on the web browsers of other victim users. | |
| Analizada | Media (6.1) | 0.36% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scripting vulnerability. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser. | |
| Analizada | Media (6.1) | 0.36% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of unintended data to HTTP response headers. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser. | |
| Analizada | Crítica (9.8) | 0.62% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an authentication bypass vulnerability. | |
| Analizada | Alta (8.1) | 0.46% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs provide configuration related APIs. They are expected to be called by administrative users only, but insufficiently restricted. A non-administrative user may execute some configuration APIs. | |
| Analizada | Media (5.3) | 0.55% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability. Unintended internal files may be retrieved when processing crafted HTTP requests. | |
| Analizada | Alta (7.5) | 0.71% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs provide the web page to download data, where query parameters in HTTP requests are improperly processed and resulting in an Out-of-bounds Read vulnerability. Crafted HTTP requests may cause affected products crashed. | |
| Analizada | Alta (7.5) | 0.75% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs improperly process HTTP request headers, resulting in an Out-of-bounds Read vulnerability. Crafted HTTP requests may cause affected products crashed. | |
| Analizada | Alta (7.5) | 0.75% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs contain multiple Out-of-bounds Read vulnerabilities, due to improper processing of keyword search input and improper processing of SOAP messages. Crafted HTTP requests may cause affected products crashed. | |
| Aplazada | Alta (8.7) | 0.37% | — | Messagepack-csharpAI | 17/10/2024 | 17/6/2026 | ### Impact When this library is used to deserialize messagepack data from an untrusted source, there is a risk of a denial of service attack by an attacker that sends data contrived to produce hash collisions, leading to large CPU consumption disproportionate to the size of the data being deserialized. This is similar… | |
| Aplazada | Media (6.5) | 0.32% | — | Sharp NEC ProjectorAI | 27/9/2024 | 17/6/2026 | Sharp NEC Projectors (NP-CB4500UL, NP-CB4500WL, NP-CB4700UL, NP-P525UL, NP-P525UL+, NP-P525ULG, NP-P525ULJL, NP-P525WL, NP-P525WL+, NP-P525WLG, NP-P525WLJL, NP-CG6500UL, NP-CG6500WL, NP-CG6700UL, NP-P605UL, NP-P605UL+, NP-P605ULG, NP-P605ULJL, NP-CA4120X, NP-CA4160W, NP-CA4160X, NP-CA4200U, NP-CA4200W, NP-CA4202W,… | |
| Analizada | Alta (7.8) | 0.32% | — | Restsharp | 29/8/2024 | 17/6/2026 | RestSharp is a Simple REST and HTTP API Client for .NET. The second argument to `RestRequest.AddHeader` (the header value) is vulnerable to CRLF injection. The same applies to `RestRequest.AddOrUpdateHeader` and `RestClient.AddDefaultHeader`. The way HTTP headers are added to a request is via the… |