Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

645 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.77%—ST X-cube-azrt-h7rsST X-cube-azrtos-f4ST X-cube-azrtos-f7ST X-cube-azrtos-g0+62/4/202517/6/2026
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects the NetX Duo Component…
ModificadaAlta (7.5)0.77%—ST X-cube-azrt-h7rsST X-cube-azrtos-f4ST X-cube-azrtos-f7ST X-cube-azrtos-g0+62/4/202517/6/2026
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects the NetX Duo Web…
ModificadaAlta (7.5)0.77%—ST X-cube-azrt-h7rsST X-cube-azrtos-f4ST X-cube-azrtos-f7ST X-cube-azrtos-g0+62/4/202517/6/2026
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead to denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.This vulnerability…
ModificadaAlta (7.5)0.77%—ST X-cube-azrt-h7rsST X-cube-azrtos-f4ST X-cube-azrtos-f7ST X-cube-azrtos-g0+62/4/202517/6/2026
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead to denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.This vulnerability…
ModificadaAlta (7.5)0.77%—ST X-cube-azrt-h7rsST X-cube-azrtos-f4ST X-cube-azrtos-f7ST X-cube-azrtos-g0+62/4/202517/6/2026
A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects X-CUBE-AZRTOS-F7 NetX…
ModificadaAlta (7.5)0.77%—ST X-cube-azrt-h7rsST X-cube-azrtos-f4ST X-cube-azrtos-f7ST X-cube-azrtos-g0+62/4/202517/6/2026
A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects X-CUBE-AZRTOS-F7 NetX…
AnalizadaCrítica (9.8)1.1%—ST X-cube-azrt-h7rsST X-cube-azrtos-f4ST X-cube-azrtos-f7ST X-cube-azrtos-g0+62/4/202517/6/2026
A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted set of network packets can lead to code execution. An attacker can send a sequence of requests to trigger this vulnerability.
AplazadaMedia (6.5)0.35%—Cubecolour Audio AlbumAI27/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cubecolour Audio Album audio-album allows Stored XSS.This issue affects Audio Album: from n/a through <= 1.5.0.
AnalizadaMedia (6.1)29%—Roundcube Webmail3/2/202517/6/2026
Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session.
AplazadaAlta (7.5)0.54%—Dualcube MoowoodleAI3/2/202517/6/2026
Insertion of Sensitive Information into Log File vulnerability in DualCube MooWoodle moowoodle allows Retrieve Embedded Sensitive Data.This issue affects MooWoodle: from n/a through <= 3.2.4.
AplazadaAlta (7.1)0.28%—Jonathan LAU CubepmAI27/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jonathan Lau CubePM cubepm allows Reflected XSS.This issue affects CubePM: from n/a through <= 1.0.
AplazadaMedia (5.3)0.37%—Imran Tauqeer Cubewp FormsAI7/1/202517/6/2026
Missing Authorization vulnerability in Imran Tauqeer CubeWP Forms cubewp-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CubeWP Forms: from n/a through <= 1.1.10.
ModificadaAlta (8.8)0.32%—Cubewp1/11/202417/6/2026
Missing Authorization vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CubeWP: from n/a through <= 1.1.15.
AplazadaAlta (7.1)0.29%—Imran Tauqeer Cubewp FormsAI6/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Tauqeer CubeWP Forms cubewp-forms allows Stored XSS.This issue affects CubeWP Forms: from n/a through <= 1.1.1.
AplazadaAlta (7.5)67%—RoundcubeAI5/8/202417/6/2026
mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in rendered e-mail messages, allowing a remote attacker to obtain sensitive information.
AnalizadaCrítica (9.3)83%⚠ Explotación activa💥 ExploitRoundcube Webmail5/8/202417/6/2026
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.
ModificadaCrítica (9.3)34%💥 PoCRoundcube Webmail5/8/202417/6/2026
A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header.
AplazadaAlta (7.2)0.27%—Ec-cube EC CubeAI30/7/202417/6/2026
Acceptance of extraneous untrusted data with trusted data vulnerability exists in EC-CUBE 4 series. If this vulnerability is exploited, an attacker who obtained the administrative privilege may install an arbitrary PHP package. If the obsolete versions of PHP packages are installed, the product may be affected by some…
AplazadaMedia (6.1)0.27%—Ec-cube WEB API PluginAI30/7/202417/6/2026
Stored cross-site scripting vulnerability exists in EC-CUBE Web API Plugin. When there are multiple users using OAuth Management feature and one of them inputs some crafted value on the OAuth Management page, an arbitrary script may be executed on the web browser of the other user who accessed the management page.
ModificadaMedia (6.9)3.4%—F-logic Datacube3 Firmware24/7/202417/6/2026
A vulnerability was found in F-logic DataCube3 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/config_time_sync.php of the component HTTP POST Request Handler. The manipulation of the argument ntp_server leads to os command injection. The attack can…
AnalizadaCrítica (9.8)1.5%—Roundcube Webmail7/6/202417/6/2026
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641.
AnalizadaMedia (6.1)0.50%—Roundcube WebmailDebian Linux7/6/202417/6/2026
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.
AnalizadaMedia (6.1)73%⚠ Explotación activa💥 ExploitRoundcube WebmailDebian Linux7/6/202417/6/2026
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
ModificadaCrítica (9.8)5.0%💥 PoCCubecart6/6/202417/6/2026
Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g and node parameters.
AnalizadaCrítica (9.8)13%—F-logic Datacube3 Firmware28/5/202417/6/2026
F-logic DataCube3 v1.0 is vulnerable to File Upload via `/admin/transceiver_schedule.php.`
Orbitaley — Vulnerabilidades