Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

474 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)2.1%—Douchat28/5/202417/6/2026
Douchat 4.0.5 suffers from an arbitrary file upload vulnerability via Public/Plugins/webuploader/server/preview.php.
AplazadaAlta (7.2)0.17%—B&R Industrial Automation Scene ViewerAIB&R Industrial Automation Mapp VisionAIB&R Industrial Automation Mapp ViewAIB&R Industrial Automation Mapp CockpitAI+2114/5/202417/6/2026
An Uncontrolled Search Path Element vulnerability in B&R Industrial Automation Scene Viewer, B&R Industrial Automation Automation Runtime, B&R Industrial Automation mapp Vision, B&R Industrial Automation mapp View, B&R Industrial Automation mapp Cockpit, B&R Industrial Automation mapp Safety, B&R Industrial Automation…
AplazadaMedia (4.3)0.21%—Codemenschen Gift VouchersAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Codemenschen Gift Vouchers.This issue affects Gift Vouchers: from n/a through 4.4.0.
AnalizadaAlta (7.5)0.75%—Couchbase Server27/3/202417/6/2026
An issue was discovered in Couchbase Server 6.6.x through 7.2.0, before 7.1.5 and 7.2.1. Unauthenticated users may cause memcached to run out of memory via large commands.
AnalizadaAlta (7.5)0.75%—Couchbase Server29/2/202417/6/2026
Couchbase Server before 7.2.4 has a private key leak in goxdcr.log.
AnalizadaAlta (8.6)0.68%—Couchbase Server29/2/202417/6/2026
An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with full admin on pools/default/serverGroups and engageCluster2.
AnalizadaMedia (5.3)0.24%—Couchbase Server29/2/202417/6/2026
An issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the diag.log file. The earliest affected version is 7.1.5.
AnalizadaMedia (5.4)0.53%—Couchbase Server29/2/202417/6/2026
An issue was discovered in Couchbase Server before 7.2.4. An attacker can bypass SQL++ N1QL cURL host restrictions.
AnalizadaCrítica (9.8)0.90%—Couchbase Server29/2/202417/6/2026
An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted.
ModificadaCrítica (9.8)0.90%—Couchbase Server29/2/202417/6/2026
An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted.
ModificadaMedia (4.3)0.76%—Couchbase Server29/2/202417/6/2026
An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (outage of reader threads).
AnalizadaMedia (6.3)0.44%—Couchbase Server29/2/202417/6/2026
An issue was discovered in Couchbase Server through 7.1.4 before 7.1.5 and before 7.2.1. There are Unauthenticated RMI Service Ports Exposed in Analytics.
AnalizadaAlta (7.5)0.60%—Couchbase Server28/2/202417/6/2026
Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost.
AnalizadaMedia (6.5)0.66%—Couchbase Server28/2/202417/6/2026
An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (application exist) because of the OOM killer.
ModificadaAlta (7.5)1.1%—Redhat Ansible Automation PlatformRedhat Enterprise LinuxRedhat Update InfrastructureCryptography.io Cryptography+15/2/202417/6/2026
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
AnalizadaAlta (8.8)3.8%⚠ Explotación activa💥 PoCGoogle ChromeFedoraproject FedoraCouchbase Server16/1/202417/6/2026
Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
ModificadaCrítica (9.6)0.52%—Perfood Couchauth3/1/202417/6/2026
A host header injection vulnerability exists in the NPM package @perfood/couch-auth versions <= 0.20.0. By sending a specially crafted host header in the forgot password request, it is possible to send password reset links to users which, once clicked, lead to an attacker-controlled server and thus leak the password…
ModificadaMedia (5.7)1.2%—Apache Couchdb13/12/202317/6/2026
Design document functions which receive a user http request object may expose authorization or session cookie headers of the user who accesses the document. An attacker can leak the session component using an HTML-like output, insert the session as an external resource (such as an image), or store the credential in a…
ModificadaAlta (8.8)0.96%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000 SLCodesys Control FOR Linux ARM SL+75/12/202317/6/2026
A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device.
ModificadaMedia (5.3)0.20%—Wago Compact Controller 100 FirmwareWago Edge Controller FirmwareWago Pfc100 FirmwareWago Pfc200 Firmware+320/11/202317/6/2026
Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.
ModificadaAlta (7.1)0.22%—Aveva Batch ManagementAveva Communication DriversAveva EdgeAveva Enterprise Licensing+915/11/202317/6/2026
This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service.
ModificadaAlta (7.8)0.24%—Aveva Batch ManagementAveva Communication DriversAveva EdgeAveva Enterprise Licensing+915/11/202317/6/2026
This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privilege on the machine where these products are installed, resulting in complete compromise of the target machine.
ModificadaAlta (7.5)1.00%—Couchbase Server8/11/202317/6/2026
Couchbase Server 7.1.4 before 7.1.5 and 7.2.0 before 7.2.1 allows Directory Traversal.
ModificadaAlta (7.5)0.74%—Couchbase Server8/11/202317/6/2026
An issue was discovered in Couchbase Server 7.2.0. There is a private key leak in debug.log while adding a pre-7.0 node to a 7.2 cluster.
ModificadaBaja (2.7)0.47%—Wago Compact Controller 100 FirmwareWago Edge Controller FirmwareWago Pfc100 FirmwareWago Pfc200 Firmware+317/10/202317/6/2026
On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected.
Orbitaley — Vulnerabilidades