Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
644 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.54% | 💥 PoC | TCL 65c655 Firmware | 3/10/2025 | 17/6/2026 | A TCL Smart TV running a vulnerable UPnP/DLNA MediaRenderer implementation is affected by a remote, unauthenticated Denial of Service (DoS) condition. By sending a flood of malformed or oversized SetAVTransportURI SOAP requests to the UPnP control endpoint, an attacker can cause the device to become unresponsive. This… | |
| Analizada | Media (4.7) | 0.30% | 💥 PoC | TCL 65c655 Firmware | 3/10/2025 | 17/6/2026 | TCL 65C655 Smart TV, running firmware version V8-R75PT01-LF1V269.001116 (Android TV, Kernel 5.4.242+), is vulnerable to a blind, unauthenticated Server-Side Request Forgery (SSRF) vulnerability via the UPnP MediaRenderer service (AVTransport:1). The device accepts unauthenticated SetAVTransportURI SOAP requests over… | |
| Analizada | Media (5.5) | 0.12% | — | IBM Smartcloud Analytics LOG Analysis | 23/7/2025 | 17/6/2026 | IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, authenticated attacker to bypass client-side enforcement of security to manipulate data. | |
| Analizada | Media (5.5) | 0.12% | — | IBM Smartcloud Analytics LOG Analysis | 23/7/2025 | 17/6/2026 | IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, authenticated attacker to bypass client-side enforcement of security to manipulate data. | |
| Analizada | Media (6.1) | 0.18% | — | IBM Smartcloud Analytics LOG Analysis | 23/7/2025 | 17/6/2026 | IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting,… | |
| Analizada | Media (5.5) | 0.11% | — | IBM Smartcloud Analytics LOG Analysis | 23/7/2025 | 17/6/2026 | IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local user to cause a denial of service due to improper validation of specified type of input. | |
| Aplazada | Baja (2) | 0.11% | — | Pointcloudlibrary PCLAI | 23/6/2025 | 17/6/2026 | Vulnerability in PointCloudLibrary PCL (surface/src/3rdparty/opennurbs modules). This vulnerability is associated with program files crc32.C. This vulnerability is only relevant if the PCL version is older than 1.14.0 or the user specifically requests to not use the system zlib (WITH_SYSTEM_ZLIB=FALSE). | |
| Analizada | Media (4.3) | 0.47% | — | Nextcloud Server | 16/5/2025 | 17/6/2026 | Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 29.0.13, 30.0.7, and 31.0.1 and Nextcloud Enterprise Server prior to 26.0.13.13, 27.1.11.13, 28.0.14.4, 29.0.13, 30.0.7, and 31.0.1, an attacker on a multi-user system may read temporary files from Nextcloud running with a different… | |
| Analizada | Media (6.5) | 0.79% | — | Nextcloud Group FoldersNextcloud Server | 16/5/2025 | 17/6/2026 | Nextcloud Server is a self hosted personal cloud system, and the Nextcloud Groupfolders app provides admin-configured folders shared by everyone in a group or team. In Nextcloud Server prior to 30.0.2, 29.0.9, and 28.0.1, Nextcloud Enterprise Server prior to 30.0.2 and 29.0.9, and Nextcloud Groupfolders app prior to… | |
| Analizada | Media (6.1) | 0.18% | — | Nextcloud Desktop | 16/5/2025 | 17/6/2026 | Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3rdparty applications already installed on a user machine can create link shares for almost all data via the socket API. These shares can then be easily sent off to an external service. Nextcloud Desktop fixes… | |
| Analizada | Media (5.3) | 0.36% | — | Nextcloud Server | 16/5/2025 | 17/6/2026 | Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 28.0.13, 29.0.10, and 30.0.3 and Nextcloud Enterprise Server prior to 28.0.13, 29.0.10, and 30.0.3, a currently unused endpoint to verify a share recipient was not protected correctly, allowing to proxy requests to another server.… | |
| Analizada | Media (6.4) | 0.38% | — | Nextcloud Server | 16/5/2025 | 17/6/2026 | Nextcloud Server is a self hosted personal cloud system. Nextcloud Server prior to 29.0.15, 30.0.9, and 31.0.3 and Nextcloud Enterprise Server prior to 26.0.13.15, 27.1.11.15, 28.0.14.6, 29.0.15, 30.0.9, and 31.0.3 have a bug with session handling. The bug caused skipping the second factor confirmation after a… | |
| Aplazada | Alta (8.3) | 0.40% | — | Pointcloudlibrary PCLAIZlibAI | 14/5/2025 | 17/6/2026 | Out-of-bounds Write vulnerability in PointCloudLibrary pcl allows Overflow Buffers. Since version 1.14.0, PCL by default uses a zlib installation from the system, unless the user sets WITH_SYSTEM_ZLIB=FALSE. So this potential vulnerability is only relevant if the PCL version is older than 1.14.0 or the user… | |
| Analizada | Crítica (9.2) | 0.53% | — | Pointclouds Point Cloud Library | 14/5/2025 | 17/6/2026 | A vulnerability exists in the inftrees.c component of the zlib library, which is bundled within the PointCloudLibrary (PCL). This issue may allow context-dependent attackers to cause undefined behavior by exploiting improper pointer arithmetic. Since version 1.14.0, PCL by default uses a zlib installation from the… | |
| Analizada | Alta (7.8) | 0.14% | — | Fortinet ForticlientFortinet Fortifone Softclient | 13/5/2025 | 17/6/2026 | An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.0 all versions and FortiVoiceUCDesktop 3.0 all versions desktop application may allow an authenticated attacker to inject code via Electron environment variables. | |
| Aplazada | Media (6.4) | 0.30% | — | Kiwichat NextclientAI | 2/5/2025 | 17/6/2026 | The KiwiChat NextClient plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Crítica (9.9) | 0.73% | 💥 PoC | Softclever Limited Sync PostsAI | 11/4/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in SoftClever Limited Sync Posts sync-posts allows Upload a Web Shell to a Web Server.This issue affects Sync Posts: from n/a through <= 1.0. | |
| Modificada | Media (6.1) | 0.38% | — | Swiftcloud Swift Calendar Online Appointment Scheduling | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SwiftCloud Swift Calendar Online Appointment Scheduling online-appointment-scheduling-software allows Reflected XSS.This issue affects Swift Calendar Online Appointment Scheduling: from n/a through <= 1.3.3. | |
| Aplazada | Alta (7.1) | 0.26% | — | Softclever Limited User ReferralAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SoftClever Limited User Referral user-referral-free allows Reflected XSS.This issue affects User Referral: from n/a through <= 8.0. | |
| Aplazada | Media (5.4) | 0.45% | — | Tencentcloud-cosAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in 腾讯云 tencentcloud-cos allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects tencentcloud-cos: from n/a through 1.0.7. | |
| Aplazada | Alta (8.8) | 0.16% | — | Netcloud Exchange ClientAI | 28/11/2024 | 17/6/2026 | The NetCloud Exchange client for Windows, version 1.110.50, contains an insecure file and folder permissions vulnerability. A normal (non-admin) user could exploit the weakness in file and folder permissions to escalate privileges, execute arbitrary code and maintain persistence on the compromised machine. It has been… | |
| Aplazada | Alta (7.5) | 0.71% | — | Pointcloudlibrary PCLAI | 21/11/2024 | 17/6/2026 | While parsing certain malformed PLY files, PCL version 1.14.1 crashes due to an uncaught std::out_of_range exception in PCLPointCloud2::at. This issue could potentially be exploited to cause a denial-of-service (DoS) attack when processing untrusted PLY files. | |
| Analizada | Baja (3.5) | 0.48% | — | Nextcloud Server | 15/11/2024 | 17/6/2026 | Nextcloud Server is a self hosted personal cloud system. After a user received a share with some files inside being blocked by the files access control, the user would still be able to copy the intermediate folder inside Nextcloud allowing them to afterwards potentially access the blocked files depending on the user… | |
| Analizada | Media (4.3) | 0.53% | — | Nextcloud Server | 15/11/2024 | 17/6/2026 | Nextcloud Server is a self hosted personal cloud system. After receiving a "Files drop" or "Password protected" share link a malicious user was able to download attachments that are referenced in Text files without providing the password. It is recommended that the Nextcloud Server is upgraded to 28.0.11, 29.0.8 or… | |
| Analizada | Media (6.1) | 0.42% | — | Nextcloud User Oidc | 15/11/2024 | 17/6/2026 | user_oidc app is an OpenID Connect user backend for Nextcloud. A malicious user could send a malformed login link that would redirect the user to a provided URL after successfully authenticating. It is recommended that the Nextcloud User OIDC app is upgraded to 6.1.0. |