Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.77% | — | ST X-cube-azrt-h7rsST X-cube-azrtos-f4ST X-cube-azrtos-f7ST X-cube-azrtos-g0+6 | 2/4/2025 | 17/6/2026 | An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects the NetX Duo Component… | |
| Modificada | Alta (7.5) | 0.77% | — | ST X-cube-azrt-h7rsST X-cube-azrtos-f4ST X-cube-azrtos-f7ST X-cube-azrtos-g0+6 | 2/4/2025 | 17/6/2026 | An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects the NetX Duo Web… | |
| Modificada | Alta (7.5) | 0.77% | — | ST X-cube-azrt-h7rsST X-cube-azrtos-f4ST X-cube-azrtos-f7ST X-cube-azrtos-g0+6 | 2/4/2025 | 17/6/2026 | An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead to denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.This vulnerability… | |
| Modificada | Alta (7.5) | 0.77% | — | ST X-cube-azrt-h7rsST X-cube-azrtos-f4ST X-cube-azrtos-f7ST X-cube-azrtos-g0+6 | 2/4/2025 | 17/6/2026 | An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead to denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.This vulnerability… | |
| Modificada | Alta (7.5) | 0.77% | — | ST X-cube-azrt-h7rsST X-cube-azrtos-f4ST X-cube-azrtos-f7ST X-cube-azrtos-g0+6 | 2/4/2025 | 17/6/2026 | A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects X-CUBE-AZRTOS-F7 NetX… | |
| Modificada | Alta (7.5) | 0.77% | — | ST X-cube-azrt-h7rsST X-cube-azrtos-f4ST X-cube-azrtos-f7ST X-cube-azrtos-g0+6 | 2/4/2025 | 17/6/2026 | A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects X-CUBE-AZRTOS-F7 NetX… | |
| Analizada | Crítica (9.8) | 1.1% | — | ST X-cube-azrt-h7rsST X-cube-azrtos-f4ST X-cube-azrtos-f7ST X-cube-azrtos-g0+6 | 2/4/2025 | 17/6/2026 | A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted set of network packets can lead to code execution. An attacker can send a sequence of requests to trigger this vulnerability. | |
| Aplazada | Media (6.5) | 0.35% | — | Cubecolour Audio AlbumAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cubecolour Audio Album audio-album allows Stored XSS.This issue affects Audio Album: from n/a through <= 1.5.0. | |
| Analizada | Media (6.1) | 29% | — | Roundcube Webmail | 3/2/2025 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session. | |
| Aplazada | Alta (7.5) | 0.54% | — | Dualcube MoowoodleAI | 3/2/2025 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in DualCube MooWoodle moowoodle allows Retrieve Embedded Sensitive Data.This issue affects MooWoodle: from n/a through <= 3.2.4. | |
| Aplazada | Alta (7.1) | 0.28% | — | Jonathan LAU CubepmAI | 27/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jonathan Lau CubePM cubepm allows Reflected XSS.This issue affects CubePM: from n/a through <= 1.0. | |
| Aplazada | Media (5.3) | 0.37% | — | Imran Tauqeer Cubewp FormsAI | 7/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Imran Tauqeer CubeWP Forms cubewp-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CubeWP Forms: from n/a through <= 1.1.10. | |
| Modificada | Alta (8.8) | 0.32% | — | Cubewp | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CubeWP: from n/a through <= 1.1.15. | |
| Aplazada | Alta (7.1) | 0.29% | — | Imran Tauqeer Cubewp FormsAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Tauqeer CubeWP Forms cubewp-forms allows Stored XSS.This issue affects CubeWP Forms: from n/a through <= 1.1.1. | |
| Aplazada | Alta (7.5) | 67% | — | RoundcubeAI | 5/8/2024 | 17/6/2026 | mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in rendered e-mail messages, allowing a remote attacker to obtain sensitive information. | |
| Analizada | Crítica (9.3) | 83% | ⚠ Explotación activa💥 Exploit | Roundcube Webmail | 5/8/2024 | 17/6/2026 | A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php. | |
| Modificada | Crítica (9.3) | 34% | 💥 PoC | Roundcube Webmail | 5/8/2024 | 17/6/2026 | A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header. | |
| Aplazada | Alta (7.2) | 0.27% | — | Ec-cube EC CubeAI | 30/7/2024 | 17/6/2026 | Acceptance of extraneous untrusted data with trusted data vulnerability exists in EC-CUBE 4 series. If this vulnerability is exploited, an attacker who obtained the administrative privilege may install an arbitrary PHP package. If the obsolete versions of PHP packages are installed, the product may be affected by some… | |
| Aplazada | Media (6.1) | 0.27% | — | Ec-cube WEB API PluginAI | 30/7/2024 | 17/6/2026 | Stored cross-site scripting vulnerability exists in EC-CUBE Web API Plugin. When there are multiple users using OAuth Management feature and one of them inputs some crafted value on the OAuth Management page, an arbitrary script may be executed on the web browser of the other user who accessed the management page. | |
| Modificada | Media (6.9) | 3.4% | — | F-logic Datacube3 Firmware | 24/7/2024 | 17/6/2026 | A vulnerability was found in F-logic DataCube3 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/config_time_sync.php of the component HTTP POST Request Handler. The manipulation of the argument ntp_server leads to os command injection. The attack can… | |
| Analizada | Crítica (9.8) | 1.5% | — | Roundcube Webmail | 7/6/2024 | 17/6/2026 | Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641. | |
| Analizada | Media (6.1) | 0.50% | — | Roundcube WebmailDebian Linux | 7/6/2024 | 17/6/2026 | Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences. | |
| Analizada | Media (6.1) | 73% | ⚠ Explotación activa💥 Exploit | Roundcube WebmailDebian Linux | 7/6/2024 | 17/6/2026 | Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes. | |
| Modificada | Crítica (9.8) | 5.0% | 💥 PoC | Cubecart | 6/6/2024 | 17/6/2026 | Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g and node parameters. | |
| Analizada | Crítica (9.8) | 13% | — | F-logic Datacube3 Firmware | 28/5/2024 | 17/6/2026 | F-logic DataCube3 v1.0 is vulnerable to File Upload via `/admin/transceiver_schedule.php.` |