Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
112 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.52% | — | Nvidia Nemo | 11/3/2025 | 17/6/2026 | NVIDIA Nemo Framework contains a vulnerability where a user could cause a relative path traversal issue by arbitrary file write. A successful exploit of this vulnerability may lead to code execution and data tampering. | |
| Analizada | Alta (7.8) | 0.24% | — | Nvidia Nemo | 15/10/2024 | 17/6/2026 | NVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user may cause a path traversal issue via an unsafe .tar file extraction. A successful exploit of this vulnerability may lead to code execution and data tampering. | |
| Analizada | Alta (7.5) | 0.62% | — | Nvidia Nemo | 5/4/2024 | 17/6/2026 | NVIDIA NeMo framework for Ubuntu contains a vulnerability in tools/asr_webapp where an attacker may cause an allocation of resources without limits or throttling. A successful exploit of this vulnerability may lead to a server-side denial of service. | |
| Modificada | Crítica (9.8) | 2.8% | — | Paypal Nemo-appium | 31/1/2023 | 17/6/2026 | Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports.setup' function. **Note:** In order to exploit this vulnerability appium-running 0.1.3 has to be installed as one of nemo-appium dependencies. | |
| Modificada | Media (4.4) | 0.30% | — | Nvidia Nemo | 10/1/2022 | 17/6/2026 | NVIDIA NeMo before 1.6.0 contains a vulnerability in ASR WebApp, in which ../ Path Traversal may lead to deletion of any directory when admin privileges are available. | |
| Modificada | Media (5.3) | 0.93% | — | Babyphonemobile Wifi Baby Monitor | 4/3/2018 | 17/6/2026 | Papenmeier WiFi Baby Monitor Free & Lite before 2.02.2 allows remote attackers to obtain audio data via certain requests to TCP ports 8258 and 8257. | |
| Modificada | Alta (7.8) | 0.38% | — | Zend-cacheDebian LinuxDoctrine-project Object Relational MapperDoctrine-project Doctrinemongodbbundle+6 | 7/6/2016 | 17/6/2026 | Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB ODM Bundle before 3.0.1 use world-writable permissions for cache directories, which allows local users to execute… | |
| Modificada | Media (4.3) | 1.2% | — | Clonemonster Social Book Facebook Clone Monster | 20/9/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Social Book Facebook Clone 2010 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO parameter to (1) signup.php, (2) lostpass.php, (3) login.php, (4) index.php, (5) help_tos.php, (6) help_contact.php, or (7) help.php. | |
| Modificada | Alta (10) | 2.7% | — | Horde GroupwareHorde Groupware Webmail EditionHorde Kronolith H3Horde Mnemo H3+1 | 13/9/2009 | 16/6/2026 | Horde Kronolith H3 2.1 before 2.1.7 and 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and H3 2.2 before 2.2-RC2; Groupware 1.0 before 1.0.3 and 1.1 before 1.1-RC2; and Groupware Webmail Edition 1.0 before 1.0.4 and 1.1 before 1.1-RC2 does not validate ownership when… | |
| Modificada | Alta (10) | 2.2% | — | Horde GroupwareHorde Groupware Webmail EditionHordeHorde Kronolith H3+3 | 13/9/2009 | 16/6/2026 | Unspecified vulnerability in the Horde API in Horde 3.1 before 3.1.6 and 3.2 before 3.2 before 3.2-RC2; Turba H3 2.1 before 2.1.6 and 2.2 before 2.2-RC2; Kronolith H3 2.1 before 2.1.7 and H3 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and 2.2 before 2.2-RC2; Horde… | |
| Modificada | Baja (3.5) | 1.1% | — | Horde MnemoAI | 13/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in templates/notepads/notepads.inc in Horde Mnemo Note Manager H3 before 2.0.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) the notepad's name or (2) description, when creating a new notepad. | |
| Modificada | Media (4.3) | 1.2% | — | Horde Mnemo | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Horde Mnemo Note Manager before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title. |