Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
474 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 2.1% | — | Douchat | 28/5/2024 | 17/6/2026 | Douchat 4.0.5 suffers from an arbitrary file upload vulnerability via Public/Plugins/webuploader/server/preview.php. | |
| Aplazada | Alta (7.2) | 0.17% | — | B&R Industrial Automation Scene ViewerAIB&R Industrial Automation Mapp VisionAIB&R Industrial Automation Mapp ViewAIB&R Industrial Automation Mapp CockpitAI+21 | 14/5/2024 | 17/6/2026 | An Uncontrolled Search Path Element vulnerability in B&R Industrial Automation Scene Viewer, B&R Industrial Automation Automation Runtime, B&R Industrial Automation mapp Vision, B&R Industrial Automation mapp View, B&R Industrial Automation mapp Cockpit, B&R Industrial Automation mapp Safety, B&R Industrial Automation… | |
| Aplazada | Media (4.3) | 0.21% | — | Codemenschen Gift VouchersAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Codemenschen Gift Vouchers.This issue affects Gift Vouchers: from n/a through 4.4.0. | |
| Analizada | Alta (7.5) | 0.75% | — | Couchbase Server | 27/3/2024 | 17/6/2026 | An issue was discovered in Couchbase Server 6.6.x through 7.2.0, before 7.1.5 and 7.2.1. Unauthenticated users may cause memcached to run out of memory via large commands. | |
| Analizada | Alta (7.5) | 0.75% | — | Couchbase Server | 29/2/2024 | 17/6/2026 | Couchbase Server before 7.2.4 has a private key leak in goxdcr.log. | |
| Analizada | Alta (8.6) | 0.68% | — | Couchbase Server | 29/2/2024 | 17/6/2026 | An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with full admin on pools/default/serverGroups and engageCluster2. | |
| Analizada | Media (5.3) | 0.24% | — | Couchbase Server | 29/2/2024 | 17/6/2026 | An issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the diag.log file. The earliest affected version is 7.1.5. | |
| Analizada | Media (5.4) | 0.53% | — | Couchbase Server | 29/2/2024 | 17/6/2026 | An issue was discovered in Couchbase Server before 7.2.4. An attacker can bypass SQL++ N1QL cURL host restrictions. | |
| Analizada | Crítica (9.8) | 0.90% | — | Couchbase Server | 29/2/2024 | 17/6/2026 | An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted. | |
| Modificada | Crítica (9.8) | 0.90% | — | Couchbase Server | 29/2/2024 | 17/6/2026 | An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted. | |
| Modificada | Media (4.3) | 0.76% | — | Couchbase Server | 29/2/2024 | 17/6/2026 | An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (outage of reader threads). | |
| Analizada | Media (6.3) | 0.44% | — | Couchbase Server | 29/2/2024 | 17/6/2026 | An issue was discovered in Couchbase Server through 7.1.4 before 7.1.5 and before 7.2.1. There are Unauthenticated RMI Service Ports Exposed in Analytics. | |
| Analizada | Alta (7.5) | 0.60% | — | Couchbase Server | 28/2/2024 | 17/6/2026 | Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost. | |
| Analizada | Media (6.5) | 0.66% | — | Couchbase Server | 28/2/2024 | 17/6/2026 | An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (application exist) because of the OOM killer. | |
| Modificada | Alta (7.5) | 1.1% | — | Redhat Ansible Automation PlatformRedhat Enterprise LinuxRedhat Update InfrastructureCryptography.io Cryptography+1 | 5/2/2024 | 17/6/2026 | A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data. | |
| Analizada | Alta (8.8) | 3.8% | ⚠ Explotación activa💥 PoC | Google ChromeFedoraproject FedoraCouchbase Server | 16/1/2024 | 17/6/2026 | Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Crítica (9.6) | 0.52% | — | Perfood Couchauth | 3/1/2024 | 17/6/2026 | A host header injection vulnerability exists in the NPM package @perfood/couch-auth versions <= 0.20.0. By sending a specially crafted host header in the forgot password request, it is possible to send password reset links to users which, once clicked, lead to an attacker-controlled server and thus leak the password… | |
| Modificada | Media (5.7) | 1.2% | — | Apache Couchdb | 13/12/2023 | 17/6/2026 | Design document functions which receive a user http request object may expose authorization or session cookie headers of the user who accesses the document. An attacker can leak the session component using an HTML-like output, insert the session as an external resource (such as an image), or store the credential in a… | |
| Modificada | Alta (8.8) | 0.96% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000 SLCodesys Control FOR Linux ARM SL+7 | 5/12/2023 | 17/6/2026 | A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device. | |
| Modificada | Media (5.3) | 0.20% | — | Wago Compact Controller 100 FirmwareWago Edge Controller FirmwareWago Pfc100 FirmwareWago Pfc200 Firmware+3 | 20/11/2023 | 17/6/2026 | Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges. | |
| Modificada | Alta (7.1) | 0.22% | — | Aveva Batch ManagementAveva Communication DriversAveva EdgeAveva Enterprise Licensing+9 | 15/11/2023 | 17/6/2026 | This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service. | |
| Modificada | Alta (7.8) | 0.24% | — | Aveva Batch ManagementAveva Communication DriversAveva EdgeAveva Enterprise Licensing+9 | 15/11/2023 | 17/6/2026 | This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privilege on the machine where these products are installed, resulting in complete compromise of the target machine. | |
| Modificada | Alta (7.5) | 1.00% | — | Couchbase Server | 8/11/2023 | 17/6/2026 | Couchbase Server 7.1.4 before 7.1.5 and 7.2.0 before 7.2.1 allows Directory Traversal. | |
| Modificada | Alta (7.5) | 0.74% | — | Couchbase Server | 8/11/2023 | 17/6/2026 | An issue was discovered in Couchbase Server 7.2.0. There is a private key leak in debug.log while adding a pre-7.0 node to a 7.2 cluster. | |
| Modificada | Baja (2.7) | 0.47% | — | Wago Compact Controller 100 FirmwareWago Edge Controller FirmwareWago Pfc100 FirmwareWago Pfc200 Firmware+3 | 17/10/2023 | 17/6/2026 | On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected. |