Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

155 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.89%—Sharp Jh-rvb1 FirmwareSharp Jh-rv11 Firmware14/2/202417/6/2026
Path traversal vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to obtain an arbitrary file in the affected product.
ModificadaCrítica (9.3)0.79%—Sharp Jh-rvb1 FirmwareSharp Jh-rv11 Firmware14/2/202417/6/2026
Cross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the management page of the affected product.
ModificadaMedia (6.5)0.36%—Sharp Jh-rvb1 FirmwareSharp Jh-rv11 Firmware14/2/202417/6/2026
Cross-site request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a remote unauthenticated attacker to change the product settings.
ModificadaMedia (6.5)0.39%—Sharp Jh-rvb1 FirmwareSharp Jh-rv11 Firmware14/2/202417/6/2026
Improper access control vulnerability exists in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier, which may allow a network-adjacent unauthenticated attacker to obtain a username and its hashed password displayed on the management page of the affected product.
ModificadaAlta (8.8)0.52%—Sharp Jh-rvb1 FirmwareSharp Jh-rv11 Firmware14/2/202417/6/2026
Improper authentication vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to access the affected product without authentication.
ModificadaCrítica (9.8)0.69%—Sharp NEC E705 FirmwareSharp NEC E805 FirmwareSharp NEC E905 FirmwareSharp NEC Md551c8 Firmware+225/2/202417/6/2026
Sharp NEC Displays (P403, P463, P553, P703, P801, X554UN, X464UN, X554UNS, X464UNV, X474HB, X464UNS, X554UNV, X555UNS, X555UNV, X754HB, X554HB, E705, E805, E905, UN551S, UN551VS, X551UHD, X651UHD, X841UHD, X981UHD, MD551C8) allows an attacker execute remote code by sending unintended parameters in http request.
ModificadaCrítica (9.8)0.96%—Csharp CWS Collaborative Development Platform15/12/202317/6/2026
SmartStar Software CWS is a web-based integration platform, its file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.
ModificadaAlta (8.8)0.69%—Csharp CWS Collaborative Development Platform15/12/202317/6/2026
SmartStar Software CWS is a web-based integration platform, it has a vulnerability of missing authorization and users are able to access data or perform actions that they should not be allowed to perform via commands. An authenticated with normal user privilege can execute administrator privilege, resulting in…
ModificadaMedia (6.5)0.55%—Csharp CWS Collaborative Development Platform15/12/202317/6/2026
SmartStar Software CWS is a web-base integration platform, it has a vulnerability of using a hard-coded for a specific account with low privilege. An unauthenticated remote attacker can exploit this vulnerability to run partial processes and obtain partial information, but can't disrupt service or obtain sensitive…
ModificadaAlta (7.8)0.43%—Serenity SereneSerenity Startsharp27/4/202317/6/2026
An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. Password reset links are sent by email. A link contains a token that is used to reset the password. This token remains valid even after the password reset and can be used a second time to change the password of the corresponding user. The token…
ModificadaMedia (5.3)1.0%—Serenity SereneSerenity Startsharp27/4/202317/6/2026
An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When a password reset request occurs, the server response leaks the existence of users. If one tries to reset a password of a non-existent user, an error message indicates that this user does not exist.
ModificadaMedia (6.1)0.78%—Serenity SereneSerenity Startsharp27/4/202317/6/2026
An XSS issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When users upload temporary files, some specific file endings are not allowed, but it is possible to upload .html or .htm files containing an XSS payload. The resulting link can be sent to an administrator user.
AnalizadaMedia (4.3)0.88%—Gatsbyjs Gatsby-plugin-sharp17/4/202329/9/2026
gatsby-plugin-sharp is a plugin for the gatsby framework which exposes functions built on the Sharp image processing library. The gatsby-plugin-sharp plugin prior to versions 5.8.1 and 4.25.1 contains a path traversal vulnerability exposed when running the Gatsby develop server (`gatsby develop`). It should be noted…
ModificadaAlta (8.1)0.54%—Ssharpsmartthreadpool Project Ssharpsmartthreadpool18/1/202317/6/2026
A vulnerability was found in oznetmaster SSharpSmartThreadPool. It has been classified as problematic. This affects an unknown part of the file SSharpSmartThreadPool/SmartThreadPool.cs. The manipulation leads to race condition within a thread. The complexity of an attack is rather high. The exploitability is told to…
ModificadaAlta (7.2)3.3%—Sharp Bp-30c25 FirmwareSharp Bp-30c25t FirmwareSharp Bp-30c25y FirmwareSharp Bp-30c25z Firmware+15416/12/202217/6/2026
Command injection vulnerability in nw_interface.html in SHARP multifunction printers (MFPs)'s Digital Full-color Multifunctional System 202 or earlier, 120 or earlier, 600 or earlier, 121 or earlier, 500 or earlier, 402 or earlier, 790 or earlier, and Digital Multifunctional System (Monochrome) 200 or earlier, 211 or…
ModificadaMedia (6.5)5.2%—Unisharp Laravel Filemanager14/9/202217/6/2026
UniSharp laravel-filemanager (aka Laravel Filemanager) before 2.6.4 allows download?working_dir=%2F.. directory traversal to read arbitrary files, as exploited in the wild in June 2022. This is related to league/flysystem before 2.0.0.
ModificadaMedia (6.7)0.38%—Sharp Project Sharp25/5/202217/6/2026
sharp is an application for Node.js image processing. Prior to version 0.30.5, there is a possible vulnerability in logic that is run only at `npm install` time when installing versions of `sharp` prior to the latest v0.30.5. If an attacker has the ability to set the value of the `PKG_CONFIG_PATH` environment variable…
ModificadaMedia (6.5)0.88%—Aitsys Discatsharp14/4/202217/6/2026
DisCatSharp is a Discord API wrapper for .NET. Users of versions 9.8.5, 9.8.6, 9.9.0 and previously published prereleases of 10.0.0 who have used either one of the two `RequireDisCatSharpDeveloperAttribute`s or the `BaseDiscordClient.LibraryDeveloperTeam` have potentially had their bot token sent to a web server not…
ModificadaMedia (5.3)1.1%—Sharpziplib Project Sharpziplib26/1/202217/6/2026
SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Starting version 1.3.0 and prior to version 1.3.3, a check was added if the destination file is under destination directory. However, it is not enforced that `destDir` ends with slash. If the `destDir` is not slash terminated like `/home/user/dir` it is…
ModificadaMedia (5.3)0.90%—Sharpziplib Project Sharpziplib26/1/202217/6/2026
SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Starting version 1.0.0 and prior to version 1.3.3, a check was added if the destination file is under a destination directory. However, it is not enforced that `_baseDirectory` ends with slash. If the _baseDirectory is not slash terminated like…
ModificadaCrítica (9.8)1.9%—Sharpziplib Project Sharpziplib26/1/202217/6/2026
SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry `../evil.txt` may be extracted in the parent directory of `destFolder`. This leads to arbitrary file write that may lead to code execution. The vulnerability was patched in version 1.3.3.
ModificadaAlta (8.8)1.8%—Unisharp Laravel-filemanager17/12/202117/6/2026
This affects versions of the package unisharp/laravel-filemanager before 2.6.2. The upload() function does not sufficiently validate the file type when uploading. An attacker may be able to reproduce the following steps: 1. Install a package with a web Laravel application. 2. Navigate to the Upload window 3. Upload an…
ModificadaMedia (4.3)1.2%—Sharpcompress Project Sharpcompress16/9/202117/6/2026
SharpCompress is a fully managed C# library to deal with many compression types and formats. Versions prior to 0.29.0 are vulnerable to partial path traversal. SharpCompress recreates a hierarchy of directories under destinationDirectory if ExtractFullPath is set to true in options. In order to prevent extraction…
ModificadaAlta (7.5)1.5%—Restsharp12/7/202117/6/2026
RestSharp < 106.11.8-alpha.0.13 uses a regular expression which is vulnerable to Regular Expression Denial of Service (ReDoS) when converting strings into DateTimes. If a server responds with a malicious string, the client using RestSharp will be stuck processing it for an exceedingly long time. Thus the remote server…
ModificadaCrítica (9.8)1.7%—Sharp-nec-displays Un462a FirmwareSharp-nec-displays Un462va FirmwareSharp-nec-displays Un492s FirmwareSharp-nec-displays Un492vs Firmware+307/6/202117/6/2026
Sharp NEC Displays ((UN462A R1.300 and prior to it, UN462VA R1.300 and prior to it, UN492S R1.300 and prior to it, UN492VS R1.300 and prior to it, UN552A R1.300 and prior to it, UN552S R1.300 and prior to it, UN552VS R1.300 and prior to it, UN552 R1.300 and prior to it, UN552V R1.300 and prior to it, UX552S R1.300 and…