Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
119 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 1.5% | — | Helm | 16/6/2020 | 17/6/2026 | In Helm greater than or equal to 3.0.0 and less than 3.2.4, a path traversal attack is possible when installing Helm plugins from a tar archive over HTTP. It is possible for a malicious plugin author to inject a relative path into a plugin archive, and copy a file outside of the intended directory. This has been fixed… | |
| Modificada | Media (5) | 1.3% | — | Helm | 24/4/2020 | 17/6/2026 | Their is an information disclosure vulnerability in Helm from version 3.1.0 and before version 3.2.0. `lookup` is a Helm template function introduced in Helm v3. It is able to lookup resources in the cluster to check for the existence of specific resources and get details about them. This can be used as part of the… | |
| Modificada | Crítica (9.8) | 1.7% | — | Helm | 12/11/2019 | 17/6/2026 | In Helm 2.x before 2.15.2, commands that deal with loading a chart as a directory or packaging a chart provide an opportunity for a maliciously designed chart to include sensitive content such as /etc/passwd, or to execute a denial of service (DoS) via a special file such as /dev/urandom, via symlinks. No version of… | |
| Modificada | Crítica (9.8) | 1.4% | — | Helm | 17/7/2019 | 17/6/2026 | helm Before 2.7.2 is affected by: CWE-295: Improper Certificate Validation. The impact is: Unauthorized clients could connect to the server because self-signed client certs were aloowed. The component is: helm (many files updated, see… | |
| Modificada | Media (6.5) | 1.3% | — | Helm Chartmuseum | 4/2/2019 | 17/6/2026 | Helm ChartMuseum version >=0.1.0 and < 0.8.1 contains a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in HTTP API to save charts that can result in a specially crafted chart could be uploaded and saved outside the intended location. This attack appears to be… | |
| Modificada | Media (6.5) | 1.5% | — | Helm | 4/2/2019 | 17/6/2026 | All versions of Helm between Helm >=2.0.0 and < 2.12.2 contains a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The commands `helm fetch --untar` and `helm lint some.tgz` that can result when chart archive files are unpacked a file may be unpacked outside of… | |
| Modificada | Media (6.5) | 1.9% | — | Helmut Hummel Typo3 Webservice | 14/2/2012 | 16/6/2026 | Unspecified vulnerability in the Webservices for TYPO3 (typo3_webservice) extension before 0.3.8 for TYPO3 allows remote authenticated users to execute arbitrary code via unknown vectors. | |
| Modificada | Alta (7.5) | 1.1% | — | Martin Helmich Hbook | 13/3/2009 | 16/6/2026 | SQL injection vulnerability in the HBook (h_book) extension 2.3.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 0.52% | — | Webhost Automation Helm WEB Hosting Control Panel | 6/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Helm 3.2.16 allow remote attackers to inject arbitrary web script or HTML via (1) the showOption parameter to domain.asp, or the (2) Folder or (3) StartPath parameter to FileManager.asp. | |
| Modificada | Media (4.3) | 1.2% | 💥 Exploit | Gobi AND Helma Gobi | 11/7/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Gobi as of 20070711, built on Helma, allows remote attackers to inject arbitrary web script or HTML via the q parameter to the search function. | |
| Modificada | Media (6.8) | 1.5% | — | Webhost Automation Helm WEB Hosting Control Panel | 20/11/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 allow remote authenticated users to inject arbitrary web script or HTML via the (1) txtCompanyName, (2) txtEmail, or (3) txtUserAccNum parameter to (a) users.asp, or the (4) setThemeColour parameter to (b) default.asp in the… | |
| Modificada | Media (5.8) | 2.5% | 💥 Exploit | Webhost Automation Helm WEB Hosting Control Panel | 28/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) txtDomainName parameter to domains.asp or (2) SearchText or (3) UserLevel parameters to default.asp. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Helmsman Research Homeftp | 22/1/2006 | 16/6/2026 | Helmsman Research (aka CoolUtils) HomeFtp 1.1 allows remote attackers to cause an unspecified denial of service via a long USER command combined with a long PASS command and an NLST command. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Helm Hosting Control Panel | 14/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in forgotPassword.asp in Helm Hosting Control Panel 3.2.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the txtEmailAddress parameter. | |
| Modificada | Media (4.3) | 1.2% | — | HelmAI | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in WebHost Automation Ltd Helm before 3.2.6 allows remote attackers to inject arbitrary web script or HTML via unknown vectors involving the default page. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Webhost Automation Helm Control Panel | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary web script or HTML via the Subject field. | |
| Modificada | Alta (7.5) | 1.2% | — | Webhost Automation Helm Control Panel | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter. | |
| Modificada | Alta (10) | 4.8% | — | Max-wilhelm Bruker Bftpd | 12/2/2001 | 16/6/2026 | Buffer overflow in bftpd 1.0.13 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long SITE CHOWN command. | |
| Modificada | Alta (7.5) | 3.8% | — | Max-wilhelm Bruker Bftpd | 19/12/2000 | 23/9/2026 | Buffer overflow in bftp daemon (bftpd) 1.0.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long USER command. |