Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

354 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.9)0.52%—Perldancer Dancer\30/4/202617/6/2026
Dancer::Session::Abstract versions through 1.3522 for Perl generates session ids insecurely. The session id is generated from summing the character codepoints of the absolute pathname with the process id, the epoch time and calls to the built-in rand() function to return a number between 0 and 999-billion, and…
AnalizadaCrítica (9.8)0.81%—Perl29/3/202617/6/2026
Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of zlib which has…
AplazadaAlta (8.6)1.5%—Perle Iolan STSAIPerle Iolan SCSAI17/3/202617/6/2026
Perle IOLAN STS/SCS terminal server models with firmware versions prior to 6.0 allow authenticated OS command injection via the restricted shell accessed over Telnet or SSH. The shell 'ps' command does not perform proper argument sanitization and passes user-supplied parameters into an 'sh -c' invocation running as…
AnalizadaMedia (6.9)0.46%—Hamastar Meetinghub Paperless Meetings22/1/202617/6/2026
MeetingHub developed by HAMASTAR Technology has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access specific API functions and obtain meeting-related information.
AnalizadaCrítica (9.3)0.76%—Hamastar Meetinghub Paperless Meetings22/1/202617/6/2026
MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
AnalizadaAlta (8.7)0.67%—Hamastar Meetinghub Paperless Meetings22/1/202617/6/2026
MeetingHub developed by HAMASTAR Technology has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.
AplazadaAlta (8.5)0.19%—Perl2exeAI4/12/202526/9/2026
perl2exe <= V30.10C contains an arbitrary code execution vulnerability that allows local authenticated attackers to execute malicious scripts. Attackers can control the 0th argument of packed executables to execute another executable, allowing them to bypass restrictions and gain unauthorized access.
AplazadaMedia (6.9)0.22%—Perl PreparecompanyprofileexportjsonAI27/8/202517/6/2026
In the PrepareCDExportJSON.pl service, the "getPerfServiceIds" function is vulnerable to SQL injection.
AplazadaAlta (8.6)0.43%—Perl Catalyst Authentication Credential HttpAIPerl Data UuidAI11/8/202517/6/2026
—
AplazadaMedia (5.8)0.30%—Quantum Superloader 3AI1/8/202517/6/2026
Quantum SuperLoader 3 V94.0 005E.0h devices allow attackers to access the hardcoded fa account because there are only 65536 possible passwords.
AplazadaMedia (6.5)0.29%—Perl Authen Digestmd5AI16/7/202517/6/2026
Authen::DigestMD5 versions 0.01 through 0.02 for Perl generate the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from the HTTP…
AplazadaMedia (6.5)0.44%—Authen Sasl Sasl Perl Digest MD5AI16/7/202517/6/2026
Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked…
AplazadaCrítica (9.8)0.54%—Perl CryptxAILibtommathAI11/6/202517/6/2026
Perl CryptX before version 0.087 contains a dependency that may be susceptible to an integer overflow. CryptX embeds a version of the libtommath library that is susceptible to an integer overflow associated with CVE-2023-36328.
AplazadaAlta (8.8)0.80%—Perl File Find RuleAI5/6/202516/6/2026
File::Find::Rule through 0.34 for Perl is vulnerable to Arbitrary Code Execution when `grep()` encounters a crafted filename. A file handle is opened with the 2 argument form of `open()` allowing an attacker controlled filename to provide the MODE parameter to `open()`, turning the filename into a command to be…
AplazadaMedia (5.9)0.50%—PerlAI30/5/202517/6/2026
Perl threads have a working directory race condition where file operations may target unintended paths. If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread…
AplazadaCrítica (9.8)0.63%—Google BrotliAIPerl IO Compress BrotliAI30/5/202517/6/2026
A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library. Versions of IO::Compress::Brotli prior to 0.007 included a version of the brotli library prior to version 1.0.8, where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash,…
AplazadaBaja (2.9)0.46%—Vyperlang VyperAI15/5/202517/6/2026
Vyper is the Pythonic Programming Language for the Ethereum Virtual Machine. In versions up to and including 0.4.2rc1, the `slice()` builtin can elide side effects when the output length is 0, and the source bytestring is a builtin (`msg.data` or `<address>.code`). The reason is that for these source locations, the…
AplazadaBaja (2.9)0.45%—Vyperlang VyperAI15/5/202517/6/2026
Vyper is the Pythonic Programming Language for the Ethereum Virtual Machine. In versions up to and including 0.4.2rc1, `concat()` may skip evaluation of side effects when the length of an argument is zero. This is due to a fastpath in the implementation which skips evaluation of argument expressions when their length…
AplazadaAlta (8.7)0.28%—Hyperledger BesuAIHyperledger Besu-nativeAI7/5/202517/6/2026
Besu Native contains scripts and tooling that is used to build and package the native libraries used by the Ethereum client Hyperledger Besu. Besu 24.7.1 through 25.2.2, corresponding to besu-native versions 0.9.0 through 1.2.1, have a potential consensus bug for the precompiles ALTBN128_ADD (0x06), ALTBN128_MUL…
ModificadaAlta (8.4)0.54%—Perl13/4/202517/6/2026
A heap buffer overflow vulnerability was discovered in Perl. Release branches 5.34, 5.36, 5.38 and 5.40 are affected, including development versions from 5.33.1 through 5.41.10. When there are non-ASCII bytes in the left-hand-side of the `tr` operator, `S_do_trans_invmap` can overflow the destination pointer `d`. $…
AplazadaMedia (4)0.20%—Perl Crypt CBCAI13/4/202517/6/2026
Crypt::CBC versions between 1.21 and 3.05 for Perl may use the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. This issue affects operating systems where "/dev/urandom'" is unavailable. In that case, Crypt::CBC will fallback to use the insecure…
AplazadaMedia (6.5)0.35%—NET XeroAIPerl Data RandomAI5/4/202517/6/2026
Net::Xero 0.044 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically Net::Xero uses the Data::Random library which specifically states that it is "Useful mostly for test programs". Data::Random uses the rand()…
AplazadaMedia (5.3)0.47%—Perl Crypt SaltAI2/4/202517/6/2026
Crypt::Salt for Perl version 0.01 uses insecure rand() function when generating salts for cryptographic purposes.
AplazadaMedia (6.5)0.22%—Daniel Floeter Hyperlink Group BlockAI1/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel Floeter Hyperlink Group Block hyperlink-group-block allows DOM-Based XSS.This issue affects Hyperlink Group Block: from n/a through <= 2.0.1.
AplazadaMedia (6.5)0.43%—Linux Statm TinyAIPerlAI1/4/202517/6/2026
Linux::Statm::Tiny for Perl before 0.0701 allows untrusted code from the current working directory ('.') to be loaded similar to CVE-2016-1238. If an attacker can place a malicious file in current working directory, it may be loaded instead of the intended file, potentially leading to arbitrary code execution.…
Orbitaley — Vulnerabilidades