Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 1.6% | — | F-logic Datacube3 Firmware | 28/5/2024 | 17/6/2026 | F-logic DataCube3 v1.0 is affected by command injection due to improper string filtering at the command execution point in the ./admin/transceiver_schedule.php file. An unauthenticated remote attacker can exploit this vulnerability by sending a file name containing command injection. Successful exploitation of this… | |
| Aplazada | Crítica (9.8) | 0.50% | — | Digincube MdgiftproductAI | 29/4/2024 | 17/6/2026 | SQL Injection vulnerability in Digincube mdgiftproduct before 1.4.1 allows an attacker to run arbitrary SQL commands via the MdGiftRule::addGiftToCart method. | |
| Analizada | Alta (8) | 1.1% | 💥 PoC | Cubecart | 29/4/2024 | 17/6/2026 | File Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted .phar file. | |
| Analizada | Crítica (9.8) | 19% | 💥 Exploit | F-logic Datacube3 Firmware | 19/4/2024 | 17/6/2026 | SQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the req_id parameter. | |
| Modificada | Alta (8.8) | 0.64% | — | Cubewp | 29/3/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in CubeWP CubeWP – All-in-One Dynamic Content Framework.This issue affects CubeWP – All-in-One Dynamic Content Framework: from n/a through 1.1.12. | |
| Analizada | Crítica (9.8) | 2.8% | — | F-logic Datacube3 | 29/2/2024 | 17/6/2026 | F-logic DataCube3 v1.0 is vulnerable to unauthenticated SQL injection, which could allow an unauthenticated malicious actor to execute arbitrary SQL queries in database. | |
| Modificada | Alta (8.8) | 13% | 💥 Exploit | F-logic Datacube3 | 29/2/2024 | 17/6/2026 | F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension. | |
| Analizada | Media (5.4) | 0.55% | — | F-logic Datacube3 | 29/2/2024 | 17/6/2026 | F-logic DataCube3 Version 1.0 is affected by a reflected cross-site scripting (XSS) vulnerability due to improper input sanitization. An authenticated, remote attacker can execute arbitrary JavaScript code in the web management interface. | |
| Analizada | Crítica (9.8) | 24% | 💥 Exploit | F-logic Datacube3 Firmware | 29/2/2024 | 17/6/2026 | F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this, by sending a URI that contains the path of the configuration file. A successful exploit could allow the attacker to extract the root and admin password. | |
| Modificada | Crítica (9.8) | 0.65% | — | Kddi Home Spot Cube 2 Firmware | 2/2/2024 | 17/6/2026 | Heap-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. By processing invalid values, arbitrary code may be executed. Note that the affected products are no longer supported. | |
| Modificada | Alta (7.5) | 0.65% | — | Kddi Home Spot Cube 2 Firmware | 2/2/2024 | 17/6/2026 | Stack-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. Processing a specially crafted command may result in a denial of service (DoS) condition. Note that the affected products are no longer supported. | |
| Modificada | Media (6.5) | 0.27% | — | Linuxfoundation Cubefs | 3/1/2024 | 17/6/2026 | CubeFS is an open-source cloud-native file storage system. CubeFS prior to version 3.3.1 was found to leak users secret keys and access keys in the logs in multiple components. When CubeCS creates new users, it leaks the users secret key. This could allow a lower-privileged user with access to the logs to retrieve… | |
| Modificada | Crítica (9.8) | 0.30% | — | Linuxfoundation Cubefs | 3/1/2024 | 17/6/2026 | CubeFS is an open-source cloud-native file storage system. A vulnerability was found in CubeFS prior to version 3.3.1 that could allow users to read sensitive data from the logs which could allow them escalate privileges. CubeFS leaks configuration keys in plaintext format in the logs. These keys could allow anyone to… | |
| Modificada | Crítica (9.8) | 0.44% | — | Linuxfoundation Cubefs | 3/1/2024 | 17/6/2026 | CubeFS is an open-source cloud-native file storage system. Prior to version 3.3.1, CubeFS used an insecure random string generator to generate user-specific, sensitive keys used to authenticate users in a CubeFS deployment. This could allow an attacker to predict and/or guess the generated string and impersonate a… | |
| Modificada | Media (5.9) | 0.35% | — | Linuxfoundation Cubefs | 3/1/2024 | 17/6/2026 | CubeFS is an open-source cloud-native file storage system. A vulnerability was found during in the CubeFS master component in versions prior to 3.3.1 that could allow an untrusted attacker to steal user passwords by carrying out a timing attack. The root case of the vulnerability was that CubeFS used raw string… | |
| Modificada | Media (6.5) | 0.56% | — | Linuxfoundation Cubefs | 3/1/2024 | 17/6/2026 | CubeFS is an open-source cloud-native file storage system. A security vulnerability was found in CubeFS HandlerNode in versions prior to 3.3.1 that could allow authenticated users to send maliciously-crafted requests that would crash the ObjectNode and deny other users from using it. The root cause was improper… | |
| Modificada | Alta (7.5) | 0.60% | — | ST X-cube-safea1 | 1/1/2024 | 17/6/2026 | STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to the I2C bus. This is caused by an StSafeA_ReceiveBytes buffer overflow in the X-CUBE-SAFEA1 Software Package for STSAFE-A sample applications (1.2.0), and thus can affect… | |
| Modificada | Alta (7.5) | 0.72% | — | Cube.js | 13/12/2023 | 17/6/2026 | Cube is a semantic layer for building data applications. Prior to version 0.34.34, it is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint. The issue has been patched in `v0.34.34` and it's recommended that all users exposing Cube APIs to the public… | |
| Modificada | Crítica (9.8) | 1.0% | — | Netwrix Usercube | 28/11/2023 | 17/6/2026 | Netwrix Usercube before 6.0.215, in certain misconfigured on-premises installations, allows authentication bypass on deployment endpoints, leading to privilege escalation. This only occurs if the configuration omits the required restSettings.AuthorizedClientId and restSettings.AuthorizedSecret fields (for the POST… | |
| Modificada | Alta (7.2) | 0.98% | — | Cubecart | 17/11/2023 | 17/6/2026 | CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to execute an arbitrary OS command. | |
| Modificada | Media (4.9) | 1.2% | — | Cubecart | 17/11/2023 | 17/6/2026 | Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to obtain files in the system. | |
| Modificada | Media (6.5) | 1.3% | — | Cubecart | 17/11/2023 | 17/6/2026 | Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to delete directories and files in the system. | |
| Modificada | Alta (8.1) | 0.35% | — | Cubecart | 17/11/2023 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in CubeCart prior to 6.5.3 allows a remote unauthenticated attacker to delete data in the system. | |
| Modificada | Alta (7.2) | 1.6% | — | Ec-cube | 7/11/2023 | 17/6/2026 | EC-CUBE 3 series (3.0.0 to 3.0.18-p6) and 4 series (4.0.0 to 4.0.6-p3, 4.1.0 to 4.1.2-p2, and 4.2.0 to 4.2.2) contain an arbitrary code execution vulnerability due to improper settings of the template engine Twig included in the product. As a result, arbitrary code may be executed on the server where the product is… | |
| Modificada | Media (6.1) | 0.64% | — | Roundcube WebmailFedoraproject FedoraDebian Linux | 6/11/2023 | 17/6/2026 | Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download). |