Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
355 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.43% | — | Linux Statm TinyAIPerlAI | 1/4/2025 | 17/6/2026 | Linux::Statm::Tiny for Perl before 0.0701 allows untrusted code from the current working directory ('.') to be loaded similar to CVE-2016-1238. If an attacker can place a malicious file in current working directory, it may be loaded instead of the intended file, potentially leading to arbitrary code execution.… | |
| Aplazada | Alta (7.7) | 0.19% | — | Perl Data EntropyAI | 28/3/2025 | 17/6/2026 | Data::Entropy for Perl 0.007 and earlier use the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. | |
| Aplazada | Alta (7.5) | 0.52% | — | Szad670401 HyperlprAI | 20/3/2025 | 17/6/2026 | A vulnerability in szad670401/hyperlpr v3.0 allows for a Denial of Service (DoS) attack. The server fails to handle excessive characters appended to the end of multipart boundaries, regardless of the character used. This flaw can be exploited by sending malformed multipart requests with arbitrary characters at the end… | |
| Analizada | Baja (2.3) | 0.57% | — | Vyperlang Vyper | 21/2/2025 | 17/6/2026 | vyper is a Pythonic Smart Contract Language for the EVM. Vyper handles AugAssign statements by first caching the target location to avoid double evaluation. However, in the case when target is an access to a DynArray and the rhs modifies the array, the cached target will evaluate first, and the bounds check will not… | |
| Analizada | Baja (2.3) | 0.45% | — | Vyperlang Vyper | 21/2/2025 | 17/6/2026 | vyper is a Pythonic Smart Contract Language for the EVM. Multiple evaluation of a single expression is possible in the iterator target of a for loop. While the iterator expression cannot produce multiple writes, it can consume side effects produced in the loop body (e.g. read a storage variable updated in the loop… | |
| Analizada | Baja (2.3) | 0.33% | — | Vyperlang Vyper | 21/2/2025 | 17/6/2026 | vyper is a Pythonic Smart Contract Language for the EVM. Vyper `sqrt()` builtin uses the babylonian method to calculate square roots of decimals. Unfortunately, improper handling of the oscillating final states may lead to sqrt incorrectly returning rounded up results. This issue is being addressed and a fix is… | |
| Modificada | Baja (2.3) | 0.65% | — | Vyperlang Vyper | 14/1/2025 | 17/6/2026 | Vyper is a Pythonic Smart Contract Language for the EVM. When the Vyper Compiler uses the precompiles EcRecover (0x1) and Identity (0x4), the success flag of the call is not checked. As a consequence an attacker can provide a specific amount of gas to make these calls fail but let the overall execution continue. Then… | |
| Aplazada | Media (5.4) | 0.38% | — | Perl NET EasytcpAI | 2/1/2025 | 17/6/2026 | The Net::EasyTCP package 0.15 through 0.26 for Perl uses Perl's builtin rand() if no strong randomization module is present. | |
| Aplazada | Media (5.4) | 0.30% | — | Perl NET EasytcpAI | 2/1/2025 | 16/6/2026 | The Net::EasyTCP package before 0.15 for Perl always uses Perl's builtin rand(), which is not a strong random number generator, for cryptographic keys. | |
| Aplazada | Alta (7.5) | 0.43% | — | Perl Crypt Random SourceAI | 29/12/2024 | 17/6/2026 | The Crypt::Random::Source package before 0.13 for Perl has a fallback to the built-in rand() function, which is not a secure source of random bits. | |
| Aplazada | Media (6.5) | 0.27% | — | Daniel Floeter Hyperlink Group BlockAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel Floeter Hyperlink Group Block hyperlink-group-block allows Stored XSS.This issue affects Hyperlink Group Block: from n/a through <= 1.17.5. | |
| Modificada | Media (5.3) | 0.59% | 💥 PoC | Hyperledger Fabric | 25/8/2024 | 17/6/2026 | Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window. | |
| Analizada | Alta (7.1) | 0.38% | — | Pepperl-fuchs Icdm-rx/tcp Socketserver FirmwarePepperl-fuchs Profinet FirmwarePepperl-fuchs Profinet/modbus FirmwarePepperl-fuchs Modbus Router Firmware+4 | 13/8/2024 | 17/6/2026 | An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once. | |
| Analizada | Alta (7.1) | 0.34% | — | Pepperl-fuchs Icdm-rx/tcp Socketserver FirmwarePepperl-fuchs Profinet FirmwarePepperl-fuchs Profinet/modbus FirmwarePepperl-fuchs Modbus Router Firmware+4 | 13/8/2024 | 17/6/2026 | An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once. | |
| Analizada | Media (6.1) | 0.33% | — | Pepperl-fuchs Icdm-rx/tcp Socketserver FirmwarePepperl-fuchs Profinet FirmwarePepperl-fuchs Profinet/modbus FirmwarePepperl-fuchs Modbus Router Firmware+4 | 13/8/2024 | 17/6/2026 | An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML code and gain low-privileged access on the affected device. | |
| Analizada | Crítica (9.3) | 0.48% | — | Hamastar Meetinghub Paperless Meetings | 5/8/2024 | 17/6/2026 | A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials and gain access to the product via an XML file. | |
| Analizada | Crítica (9.3) | 0.52% | — | Hamastar Meetinghub Paperless Meetings | 5/8/2024 | 17/6/2026 | A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Paperless Meetings 2021 allows remote authenticated users to perform arbitrary system commands via a crafted ASP file. | |
| Modificada | Crítica (9.8) | 0.59% | — | Pepperl-fuchs Oit700-f113-b12-cb FirmwarePepperl-fuchs Oit500-f113-b12-cb FirmwarePepperl-fuchs Oit200-f113-b12-cb FirmwarePepperl-fuchs Oit1500-f113-b12-cb Firmware | 10/7/2024 | 17/6/2026 | An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data. | |
| Modificada | Alta (7.5) | 0.51% | — | Pepperl-fuchs Oit700-f113-b12-cb FirmwarePepperl-fuchs Oit500-f113-b12-cb FirmwarePepperl-fuchs Oit200-f113-b12-cb FirmwarePepperl-fuchs Oit1500-f113-b12-cb Firmware | 10/7/2024 | 17/6/2026 | An unauthenticated remote attacker can read out sensitive device information through a incorrectly configured FTP service. | |
| Aplazada | Media (5.5) | 0.49% | — | Paperless-ngxAI | 15/5/2024 | 17/6/2026 | Paperless-ngx is a document management system that transforms physical documents into a searchable online archive. Starting in version 2.5.0 and prior to version 2.8.6, remote user authentication allows API access even if API access is explicitly disabled. Version 2.8.6 contains a patchc for the issue. | |
| Analizada | Media (5.3) | 0.46% | — | Vyperlang Vyper | 25/4/2024 | 17/6/2026 | Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, using the `sqrt` builtin can result in double eval vulnerability when the argument has side-effects. It can be seen that the `build_IR` function of the `sqrt` builtin doesn't cache the argument to the stack. As… | |
| Analizada | Media (5.3) | 0.41% | — | Vyperlang Vyper | 25/4/2024 | 17/6/2026 | Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. Prior to version 0.3.0, default functions don't respect nonreentrancy keys and the lock isn't emitted. No vulnerable production contracts were found. Additionally, using a lock on a `default` function is a very sparsely used pattern. As… | |
| Analizada | Media (5.3) | 0.46% | — | Vyperlang Vyper | 25/4/2024 | 17/6/2026 | Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, using the `create_from_blueprint` builtin can result in a double eval vulnerability when `raw_args=True` and the `args` argument has side-effects. It can be seen that the `_build_create_IR` function of the… | |
| Analizada | Media (5.3) | 0.46% | — | Vyperlang Vyper | 25/4/2024 | 17/6/2026 | Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, using the `slice` builtin can result in a double eval vulnerability when the buffer argument is either `msg.data`, `self.code` or `<address>.code` and either the `start` or `length` arguments have side-effects.… | |
| Analizada | Media (5.3) | 0.46% | — | Vyperlang Vyper | 25/4/2024 | 17/6/2026 | Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, incorrect values can be logged when `raw_log` builtin is called with memory or storage arguments to be used as topics. A contract search was performed and no vulnerable contracts were found in production. The… |