Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
208 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.65% | — | Pepegxng Smart ContractAI | 30/10/2024 | 17/6/2026 | An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the Owned.setOwner function. NOTE: this is disputed by third parties because the impact is limited to function calls. | |
| Modificada | Media (4.8) | 0.28% | — | Kevonadonis WP Abstracts | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kevon Adonis WP Abstracts wp-abstracts-manuscripts-manager allows Stored XSS.This issue affects WP Abstracts: from n/a through <= 2.7.1. | |
| Analizada | Alta (8.1) | 0.45% | — | Oracle Service Contracts | 15/10/2024 | 17/6/2026 | Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Authoring). Supported versions that are affected are 12.2.5-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Service Contracts. Successful attacks of… | |
| Analizada | Media (6.9) | 0.55% | — | Codeclysm Extract | 11/10/2024 | 17/6/2026 | Extract is aA Go library to extract archives in zip, tar.gz or tar.bz2 formats. A maliciously crafted archive may allow an attacker to create a symlink outside the extraction target directory. This vulnerability is fixed in 4.0.0. If you're using the Extractor.FS interface, then upgrading to /v4 will require to… | |
| Modificada | Media (4.8) | 0.31% | — | Kevonadonis WP Abstracts | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kevon Adonis WP Abstracts wp-abstracts-manuscripts-manager allows Stored XSS.This issue affects WP Abstracts: from n/a through <= 2.6.5. | |
| Modificada | Media (6.5) | 0.44% | — | Opendaylight Model-driven Service Abstraction Layer | 15/9/2024 | 17/6/2026 | In OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) through 13.0.1, a controller with a follower role can configure flow entries in an OpenDaylight clustering deployment. | |
| Analizada | Media (6.5) | 0.48% | — | Openzeppelin Contracts | 31/8/2024 | 17/6/2026 | Cairo-Contracts are OpenZeppelin Contracts written in Cairo for Starknet, a decentralized ZK Rollup. This vulnerability can lead to unauthorized ownership transfer, contrary to the original owner's intention of leaving the contract without an owner. It introduces a security risk where an unintended party (pending… | |
| Analizada | Alta (7.4) | 0.76% | — | Openzeppelin ContractsOpenzeppelin Contracts Upgradeable | 21/3/2024 | 17/6/2026 | OpenZeppelin Contracts is a library for secure smart contract development. The `Base64.encode` function encodes a `bytes` input by iterating over it in chunks of 3 bytes. When this input is not a multiple of 3, the last iteration may read parts of the memory that are beyond the input buffer. The vulnerability is fixed… | |
| Modificada | Media (5.5) | 0.22% | — | Vmware Spring Cloud Contract | 31/1/2024 | 17/6/2026 | In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1.10, test execution is vulnerable to local information disclosure via temporary directory created with unsafe permissions through the shaded com.google.guava:guava dependency in the… | |
| Modificada | Media (4.3) | 0.68% | — | Ethex Contracts | 19/12/2023 | 17/6/2026 | A vulnerability was found in Ethex Contracts. It has been classified as critical. This affects an unknown part of the file EthexJackpot.sol of the component Monthly Jackpot Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. This product does not use versioning.… | |
| Modificada | Alta (7.5) | 0.54% | — | Openzeppelin ContractsOpenzeppelin Contracts Upgradeable | 9/12/2023 | 17/6/2026 | OpenZeppelin Contracts is a library for smart contract development. A merge issue when porting the 5.0.1 patch to the 4.9 branch caused a line duplication. In the version of `Multicall.sol` released in `@openzeppelin/contracts@4.9.4` and `@openzeppelin/contracts-upgradeable@4.9.4`, all subcalls are executed twice.… | |
| Modificada | Media (4.8) | 0.47% | — | Kevonadonis WP Abstracts | 30/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kevon Adonis WP Abstracts plugin <= 2.6.3 versions. | |
| Modificada | Media (5.3) | 0.74% | — | Openzeppelin ContractsOpenzeppelin Contracts-upgradable | 10/8/2023 | 17/6/2026 | OpenZeppelin Contracts is a library for secure smart contract development. Starting in version 4.0.0 and prior to version 4.9.3, contracts using `ERC2771Context` along with a custom trusted forwarder may see `_msgSender` return `address(0)` in calls that originate from the forwarder with calldata shorter than 20… | |
| Analizada | Alta (8.8) | 0.26% | — | Kevonadonis WP Abstracts | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kevon Adonis WP Abstracts plugin <= 2.6.2 versions. | |
| Modificada | Media (5.9) | 0.37% | — | Openzeppelin ContractsOpenzeppelin Contracts Upgradeable | 16/6/2023 | 17/6/2026 | OpenZeppelin Contracts is a library for smart contract development. Starting in version 4.7.0 and prior to version 4.9.2, when the `verifyMultiProof`, `verifyMultiProofCalldata`, `procesprocessMultiProof`, or `processMultiProofCalldat` functions are in use, it is possible to construct merkle trees that allow forging a… | |
| Analizada | Media (6.1) | 0.38% | — | Kevonadonis WP Abstracts | 12/6/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kevon Adonis WP Abstracts plugin <= 2.6.2 versions. | |
| Modificada | Media (5.3) | 0.60% | — | Openzeppelin ContractsOpenzeppelin Contracts Upgradeable | 7/6/2023 | 17/6/2026 | OpenZeppelin Contracts is a library for smart contract development. By frontrunning the creation of a proposal, an attacker can become the proposer and gain the ability to cancel it. The attacker can do this repeatedly to try to prevent a proposal from being proposed at all. This impacts the `Governor` contract in… | |
| Modificada | Media (5.3) | 0.81% | — | Openzeppelin ContractsOpenzeppelin Contracts Upgradeable | 17/4/2023 | 17/6/2026 | OpenZeppelin Contracts is a library for secure smart contract development. A function in the implementation contract may be inaccessible if its selector clashes with one of the proxy's own selectors. Specifically, if the clashing function has a different signature with incompatible ABI encoding, the proxy could revert… | |
| Modificada | Alta (8.8) | 0.58% | — | Openzeppelin ContractsOpenzeppelin Contracts Upgradeable | 16/4/2023 | 17/6/2026 | OpenZeppelin Contracts is a library for secure smart contract development. The proposal creation entrypoint (`propose`) in `GovernorCompatibilityBravo` allows the creation of proposals with a `signatures` array shorter than the `calldatas` array. This causes the additional elements of the latter to be ignored, and if… | |
| Modificada | Media (6.5) | 0.71% | — | Openzeppelin ContractsOpenzeppelin Contracts Upgradeable | 3/3/2023 | 17/6/2026 | OpenZeppelin Contracts is a library for secure smart contract development. The ERC721Consecutive contract designed for minting NFTs in batches does not update balances when a batch has size 1 and consists of a single token. Subsequent transfers from the receiver of that token may overflow the balance as reported by… | |
| Modificada | Media (5.3) | 0.22% | — | Openzeppelin Contracts | 3/2/2023 | 17/6/2026 | OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. `is_valid_eth_signature` is missing a call to `finalize_keccak` after calling `verify_eth_signature`. As a result, any contract using `is_valid_eth_signature` from the account… | |
| Modificada | Crítica (9.8) | 0.74% | — | E-contract Dssp | 6/1/2023 | 17/6/2026 | A vulnerability classified as problematic was found in e-Contract dssp up to 1.3.1. Affected by this vulnerability is the function checkSignResponse of the file dssp-client/src/main/java/be/e_contract/dssp/client/SignResponseVerifier.java. The manipulation leads to xml external entity reference. Upgrading to version… | |
| Modificada | Media (6.1) | 0.48% | — | SAP Contract Lifecycle ManagerSAP Sourcing | 13/12/2022 | 17/6/2026 | Due to improper input sanitization in SAP Sourcing and SAP Contract Lifecycle Management - version 1100, an attacker can redirect a user to a malicious website. In order to perform this attack, the attacker sends an email to the victim with a manipulated link that appears to be a legitimate SAP Sourcing URL, since the… | |
| Modificada | Alta (8.8) | 4.0% | 💥 Exploit | Wpsmartcontracts | 28/11/2022 | 17/6/2026 | The WPSmartContracts WordPress plugin before 1.3.12 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author | |
| Modificada | Media (5.6) | 0.53% | — | Openzeppelin ContractsOpenzeppelin Contracts Upgradeable | 4/11/2022 | 17/6/2026 | OpenZeppelin Contracts is a library for secure smart contract development. Before version 4.4.1 but after 3.2.0, initializer functions that are invoked separate from contract creation (the most prominent example being minimal proxies) may be reentered if they make an untrusted non-view external call. Once an… |