Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
–

401.980 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisBaja (3.6)0.09%—Progress Telerik Fiddler ClassicAI5/10/20266/10/2026
In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, front-end request desynchronization is possible in the proxy request forwarding component. A request that contains both a Content-Length and a Transfer-Encoding header is forwarded with both headers present, while Fiddler frames…
Pendiente de análisisMedia (6.3)0.09%—Progress Fiddler ClassicAI5/10/20266/10/2026
In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, HTTP request smuggling is possible in the proxy request forwarding component. Requests containing multiple Content-Length headers with conflicting values are forwarded verbatim to the origin server, while Fiddler frames the request…
AplazadaBaja (2)0.25%—Django HaystackAI5/10/20266/10/2026
A vulnerability has been found in django-haystack up to 3.3.0. Affected is the function _to_python of the file haystack/backends/elasticsearch_backend.py of the component more_like_this Template Tag Handler. Such manipulation of the argument result_class leads to improper neutralization of directives in dynamically…
AplazadaAlta (8.5)0.14%—Libreoffice CalcAI5/10/20266/10/2026
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location. In fixed versions an entry in a Java class path has…
AplazadaMedia (6.7)0.12%—LibreofficeAI5/10/20266/10/2026
URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for CVE-2024-12426 did not cover every place a document can supply a URL. XForms instance data and…
AplazadaMedia (6.7)0.11%—LibreofficeAI5/10/20266/10/2026
LibreOffice can link to audio and video files from a document, and on Linux it plays them with GStreamer. A linked media file could be an HLS playlist that made GStreamer read the local files and remote URLs it listed while the document loaded, and their contents could end up in the document. In fixed versions…
AplazadaMedia (6.7)0.12%—Libreoffice CalcAI5/10/20266/10/2026
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A link of the sql type could name a folder of local text files as a database, so opening a document could read a local text file into the sheet. In fixed versions only the csv, html and xml data providers are…
AplazadaMedia (6.7)0.11%—Libreoffice CalcAI5/10/20266/10/2026
LibreOffice Calc can link a cell range to an external csv data source, and the link is saved in the document. Such a link was fetched while the document loaded, so opening a document could read a local file into the sheet, or make a request to a host of the document's choosing. In fixed versions external data links…
AplazadaMedia (6.8)0.16%—Libreoffice CalcAI5/10/20266/10/2026
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. Through such a link a document could open an embedded Firebird database that wrote a file to any location the user could write to. In fixed versions an embedded Firebird database can open or create files only…
AplazadaMedia (4.3)0.16%—WP Syntex PolylangAI5/10/20266/10/2026
Missing Authorization vulnerability in WP SYNTEX Polylang polylang allows Retrieve Embedded Sensitive Data.This issue affects Polylang: from n/a through 3.8.7.
AplazadaMedia (5.3)0.10%—HeymAI5/10/20265/10/2026
Heym before v0.0.112 contains a token leakage vulnerability in build_public_base_url() that allows unauthenticated attackers to redirect HITL review links by spoofing Origin or X-Forwarded-Host headers. Attackers can trigger anonymous workflows with forged headers so reviewer notifications point to attacker domains,…
AplazadaMedia (5.5)0.38%—Casbin CasdoorAI5/10/20265/10/2026
A vulnerability was detected in Casdoor up to 3.161.1. Affected is the function ApiFilter of the file routers/authz_filter.go of the component API Endpoint. Performing a manipulation results in missing authentication. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was…
AplazadaMedia (5.3)0.20%—Arraytics WP Event SolutionAI5/10/20266/10/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Arraytics WP Event Solution wp-event-solution allows Retrieve Embedded Sensitive Data.This issue affects WP Event Solution: from n/a through 4.1.25.
AplazadaMedia (5.3)0.18%—Arraytics WP Event SolutionAI5/10/20266/10/2026
Missing Authorization vulnerability in Arraytics WP Event Solution wp-event-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Event Solution: from n/a through 4.1.25.
AplazadaMedia (5.3)0.18%—Wpmanageninja Fluent Forms PROAI5/10/20266/10/2026
Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Forms Pro Add On Pack: from n/a through 6.2.13.
Pendiente de análisisMedia (5.7)0.25%——5/10/20266/10/2026
The email media type OAuth form passes the Authorization endpoint value to window.open() without validating the URL scheme, so a javascript: URL is executed in the browser. This means a crafted media type configuration, deliverable as an import file, runs arbitrary JavaScript as the Super Admin who grants consent.
Pendiente de análisisMedia (5.3)0.23%—ZabbixAI5/10/20266/10/2026
The Perl SNMP trap receiver script shipped with Zabbix does not properly neutralize the ZBXTRAP record delimiter in trap content. This means someone able to send SNMP traps can inject a record targeting another host, resulting in a loss of integrity.
Pendiente de análisisMedia (6.9)0.20%—Zabbix ServerAIZabbix ProxyAI5/10/20266/10/2026
Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone with access to the Zabbix trapper port can report an arbitrary host using an active agent as available, resulting in a loss of integrity.
Pendiente de análisisMedia (5.1)0.16%——5/10/20266/10/2026
Host search in Frontend allows filtering by fields that are not displayed, including stored IPMI and PSK credentials. A user with read access can guess a credential and see from the search result whether the guess was right, letting them uncover it.
Pendiente de análisisBaja (2.3)0.23%—Zabbix ServerAIZabbix ProxyAI5/10/20266/10/2026
The Zabbix Server/Proxy has a vulnerability where binary items can crash the Server/Proxy on certain NULL byte input leading to potential loss of availability. This only affects deployments where MySQL/MariaDB database is used as the Zabbix database.
Pendiente de análisisMedia (6.9)0.24%—Zabbix ServerAI5/10/20266/10/2026
The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap data potentially resulting in leaked data from other running preprocessors not available to said administrator.
AplazadaMedia (4.3)0.15%—Deepak Anand WP Dummy Content GeneratorAI5/10/20266/10/2026
Missing Authorization vulnerability in Deepak Anand WP Dummy Content Generator wp-dummy-content-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Dummy Content Generator: from n/a through 4.0.0.
AplazadaBaja (2.1)0.44%—Feelec-yishu Feelcrm-osAI5/10/20266/10/2026
A vulnerability was identified in feelec-yishu feelcrm-os 1.0.0. This vulnerability affects the function GroupController::index of the file App/Feelcrm/Index/Controller/GroupController.class.php of the component Department Search Endpoint. The manipulation of the argument keyword leads to cross site scripting. The…
AplazadaMedia (5.5)0.47%—Feelec-yishu Feelcrm-osAI5/10/20266/10/2026
A vulnerability was determined in feelec-yishu feelcrm-os 1.0.0. This affects an unknown part of the file App/Feelcrm/Index/Controller/GoogleController.class.php of the component getCurlData Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. It is possible to launch the…
AplazadaBaja (2)0.33%—Feelec-yishu Feelcrm-osAI5/10/20266/10/2026
A vulnerability was found in feelec-yishu feelcrm-os 1.0.0. Affected by this issue is the function htmlspecialchars_decode of the file App/Feelcrm/Common/Model/CrmDefineFormModel.class.php of the component Create Customer Endpoint. Performing a manipulation of the argument customer_form[remark] results in cross site…