Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

208 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.65%—Pepegxng Smart ContractAI30/10/202417/6/2026
An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the Owned.setOwner function. NOTE: this is disputed by third parties because the impact is limited to function calls.
ModificadaMedia (4.8)0.28%—Kevonadonis WP Abstracts29/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kevon Adonis WP Abstracts wp-abstracts-manuscripts-manager allows Stored XSS.This issue affects WP Abstracts: from n/a through <= 2.7.1.
AnalizadaAlta (8.1)0.45%—Oracle Service Contracts15/10/202417/6/2026
Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Authoring). Supported versions that are affected are 12.2.5-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Service Contracts. Successful attacks of…
AnalizadaMedia (6.9)0.55%—Codeclysm Extract11/10/202417/6/2026
Extract is aA Go library to extract archives in zip, tar.gz or tar.bz2 formats. A maliciously crafted archive may allow an attacker to create a symlink outside the extraction target directory. This vulnerability is fixed in 4.0.0. If you're using the Extractor.FS interface, then upgrading to /v4 will require to…
ModificadaMedia (4.8)0.31%—Kevonadonis WP Abstracts6/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kevon Adonis WP Abstracts wp-abstracts-manuscripts-manager allows Stored XSS.This issue affects WP Abstracts: from n/a through <= 2.6.5.
ModificadaMedia (6.5)0.44%—Opendaylight Model-driven Service Abstraction Layer15/9/202417/6/2026
In OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) through 13.0.1, a controller with a follower role can configure flow entries in an OpenDaylight clustering deployment.
AnalizadaMedia (6.5)0.48%—Openzeppelin Contracts31/8/202417/6/2026
Cairo-Contracts are OpenZeppelin Contracts written in Cairo for Starknet, a decentralized ZK Rollup. This vulnerability can lead to unauthorized ownership transfer, contrary to the original owner's intention of leaving the contract without an owner. It introduces a security risk where an unintended party (pending…
AnalizadaAlta (7.4)0.76%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable21/3/202417/6/2026
OpenZeppelin Contracts is a library for secure smart contract development. The `Base64.encode` function encodes a `bytes` input by iterating over it in chunks of 3 bytes. When this input is not a multiple of 3, the last iteration may read parts of the memory that are beyond the input buffer. The vulnerability is fixed…
ModificadaMedia (5.5)0.22%—Vmware Spring Cloud Contract31/1/202417/6/2026
In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1.10, test execution is vulnerable to local information disclosure via temporary directory created with unsafe permissions through the shaded com.google.guava:guava dependency in the…
ModificadaMedia (4.3)0.68%—Ethex Contracts19/12/202317/6/2026
A vulnerability was found in Ethex Contracts. It has been classified as critical. This affects an unknown part of the file EthexJackpot.sol of the component Monthly Jackpot Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. This product does not use versioning.…
ModificadaAlta (7.5)0.54%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable9/12/202317/6/2026
OpenZeppelin Contracts is a library for smart contract development. A merge issue when porting the 5.0.1 patch to the 4.9 branch caused a line duplication. In the version of `Multicall.sol` released in `@openzeppelin/contracts@4.9.4` and `@openzeppelin/contracts-upgradeable@4.9.4`, all subcalls are executed twice.…
ModificadaMedia (4.8)0.47%—Kevonadonis WP Abstracts30/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kevon Adonis WP Abstracts plugin <= 2.6.3 versions.
ModificadaMedia (5.3)0.74%—Openzeppelin ContractsOpenzeppelin Contracts-upgradable10/8/202317/6/2026
OpenZeppelin Contracts is a library for secure smart contract development. Starting in version 4.0.0 and prior to version 4.9.3, contracts using `ERC2771Context` along with a custom trusted forwarder may see `_msgSender` return `address(0)` in calls that originate from the forwarder with calldata shorter than 20…
AnalizadaAlta (8.8)0.26%—Kevonadonis WP Abstracts11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Kevon Adonis WP Abstracts plugin <= 2.6.2 versions.
ModificadaMedia (5.9)0.37%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable16/6/202317/6/2026
OpenZeppelin Contracts is a library for smart contract development. Starting in version 4.7.0 and prior to version 4.9.2, when the `verifyMultiProof`, `verifyMultiProofCalldata`, `procesprocessMultiProof`, or `processMultiProofCalldat` functions are in use, it is possible to construct merkle trees that allow forging a…
AnalizadaMedia (6.1)0.38%—Kevonadonis WP Abstracts12/6/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kevon Adonis WP Abstracts plugin <= 2.6.2 versions.
ModificadaMedia (5.3)0.60%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable7/6/202317/6/2026
OpenZeppelin Contracts is a library for smart contract development. By frontrunning the creation of a proposal, an attacker can become the proposer and gain the ability to cancel it. The attacker can do this repeatedly to try to prevent a proposal from being proposed at all. This impacts the `Governor` contract in…
ModificadaMedia (5.3)0.81%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable17/4/202317/6/2026
OpenZeppelin Contracts is a library for secure smart contract development. A function in the implementation contract may be inaccessible if its selector clashes with one of the proxy's own selectors. Specifically, if the clashing function has a different signature with incompatible ABI encoding, the proxy could revert…
ModificadaAlta (8.8)0.58%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable16/4/202317/6/2026
OpenZeppelin Contracts is a library for secure smart contract development. The proposal creation entrypoint (`propose`) in `GovernorCompatibilityBravo` allows the creation of proposals with a `signatures` array shorter than the `calldatas` array. This causes the additional elements of the latter to be ignored, and if…
ModificadaMedia (6.5)0.71%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable3/3/202317/6/2026
OpenZeppelin Contracts is a library for secure smart contract development. The ERC721Consecutive contract designed for minting NFTs in batches does not update balances when a batch has size 1 and consists of a single token. Subsequent transfers from the receiver of that token may overflow the balance as reported by…
ModificadaMedia (5.3)0.22%—Openzeppelin Contracts3/2/202317/6/2026
OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. `is_valid_eth_signature` is missing a call to `finalize_keccak` after calling `verify_eth_signature`. As a result, any contract using `is_valid_eth_signature` from the account…
ModificadaCrítica (9.8)0.74%—E-contract Dssp6/1/202317/6/2026
A vulnerability classified as problematic was found in e-Contract dssp up to 1.3.1. Affected by this vulnerability is the function checkSignResponse of the file dssp-client/src/main/java/be/e_contract/dssp/client/SignResponseVerifier.java. The manipulation leads to xml external entity reference. Upgrading to version…
ModificadaMedia (6.1)0.48%—SAP Contract Lifecycle ManagerSAP Sourcing13/12/202217/6/2026
Due to improper input sanitization in SAP Sourcing and SAP Contract Lifecycle Management - version 1100, an attacker can redirect a user to a malicious website. In order to perform this attack, the attacker sends an email to the victim with a manipulated link that appears to be a legitimate SAP Sourcing URL, since the…
ModificadaAlta (8.8)4.0%💥 ExploitWpsmartcontracts28/11/202217/6/2026
The WPSmartContracts WordPress plugin before 1.3.12 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author
ModificadaMedia (5.6)0.53%—Openzeppelin ContractsOpenzeppelin Contracts Upgradeable4/11/202217/6/2026
OpenZeppelin Contracts is a library for secure smart contract development. Before version 4.4.1 but after 3.2.0, initializer functions that are invoked separate from contract creation (the most prominent example being minimal proxies) may be reentered if they make an untrusted non-view external call. Once an…
Orbitaley — Vulnerabilidades