Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
380 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.21% | — | Vault Group PTY LTD Vaultre Contact Form 7AI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vault Group Pty Ltd VaultRE Contact Form 7 allows Stored XSS.This issue affects VaultRE Contact Form 7: from n/a through 1.0. | |
| Aplazada | Media (6.5) | 0.24% | — | Vaultdweller LeykaAI | 16/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VaultDweller Leyka leyka allows Stored XSS.This issue affects Leyka: from n/a through <= 3.31.8. | |
| Analizada | Alta (7.5) | 0.68% | — | Dani-garcia Vaultwarden | 27/1/2025 | 17/6/2026 | vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker can obtain owner rights of other organization. Hacker should know the ID of victim organization (in real case the user can be a part of the organization as an unprivileged user) and be the owner/admin of… | |
| Analizada | Alta (7.2) | 1.0% | — | Dani-garcia Vaultwarden | 27/1/2025 | 17/6/2026 | vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker with authenticated access to the vaultwarden admin panel can execute arbitrary code in the system. The attacker could then change some settings to use sendmail as mail agent but adjust the settings in… | |
| Analizada | Media (5.4) | 0.38% | — | Dani-garcia Vaultwarden | 9/1/2025 | 17/6/2026 | Vaultwarden v1.32.5 was discovered to contain an authenticated reflected cross-site scripting (XSS) vulnerability via the component /api/core/mod.rs. | |
| Analizada | Crítica (9.8) | 0.60% | — | Dani-garcia Vaultwarden | 9/1/2025 | 17/6/2026 | An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, including Administrators, via a crafted authorization request. | |
| Analizada | Crítica (9.6) | 0.82% | — | Dani-garcia Vaultwarden | 9/1/2025 | 17/6/2026 | An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting a crafted payload into the username field of an e-mail message. | |
| Analizada | Alta (7.5) | 0.34% | — | Dani-garcia Vaultwarden | 20/12/2024 | 17/6/2026 | vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected versions an attacker is capable of updating or deleting groups from an organization given a few conditions: 1. The attacker has a user account in the server. 2. The attacker's account has admin or… | |
| Analizada | Crítica (9.8) | 0.94% | — | Veritas Enterprise Vault | 24/11/2024 | 17/6/2026 | An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24405. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized. | |
| Analizada | Crítica (9.8) | 0.94% | — | Veritas Enterprise Vault | 24/11/2024 | 17/6/2026 | An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24344. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized. | |
| Analizada | Crítica (9.8) | 0.94% | — | Veritas Enterprise Vault | 24/11/2024 | 17/6/2026 | An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24343. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized. | |
| Analizada | Crítica (9.8) | 0.94% | — | Veritas Enterprise Vault | 24/11/2024 | 17/6/2026 | An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24341. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized. | |
| Analizada | Crítica (9.8) | 0.94% | — | Veritas Enterprise Vault | 24/11/2024 | 17/6/2026 | An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24339. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized. | |
| Analizada | Crítica (9.8) | 0.94% | — | Veritas Enterprise Vault | 24/11/2024 | 17/6/2026 | An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24336. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized. | |
| Analizada | Crítica (9.8) | 0.94% | — | Veritas Enterprise Vault | 24/11/2024 | 17/6/2026 | An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24334. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized. | |
| Analizada | Media (5.4) | 0.35% | — | Veritas Enterprise Vault | 18/11/2024 | 17/6/2026 | An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting while viewing archived content. This could reflect back to an authenticated user without sanitization if… | |
| Analizada | Media (5.4) | 1.1% | — | Veritas Enterprise Vault | 18/11/2024 | 17/6/2026 | An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24697. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an authenticated user without sanitization… | |
| Analizada | Media (5.4) | 0.35% | — | Veritas Enterprise Vault | 18/11/2024 | 17/6/2026 | An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24696. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an authenticated user without sanitization… | |
| Aplazada | Media (5.4) | 0.34% | — | Veritas Enterprise VaultAI | 18/11/2024 | 17/6/2026 | An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24695. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This could reflect back to an authenticated user without sanitization… | |
| Analizada | Alta (7.5) | 0.48% | — | Hashicorp VaultOpenbao | 31/10/2024 | 17/6/2026 | Vault Community and Vault Enterprise (“Vault”) clusters using Vault’s Integrated Storage backend are vulnerable to a denial-of-service (DoS) attack through memory exhaustion through a Raft cluster join API endpoint . An attacker may send a large volume of requests to the endpoint which may cause Vault to consume… | |
| Aplazada | Media (5.3) | 0.36% | — | Vaultdweller LeykaAI | 16/10/2024 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in VaultDweller Leyka leyka.This issue affects Leyka: from n/a through <= 3.31.6. | |
| Analizada | Alta (7.2) | 0.53% | — | OpenbaoHashicorp Vault | 10/10/2024 | 17/6/2026 | A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s privileges to Vault’s root policy. Fixed in Vault Community Edition 1.18.0 and Vault Enterprise 1.18.0, 1.17.7, 1.16.11, and 1.15.16. | |
| Analizada | Alta (8.8) | 0.27% | — | Hashicorp VaultOpenbao | 26/9/2024 | 17/6/2026 | Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_principals and default_user fields of the SSH secrets engine configuration are not set, an SSH certificate requested by an authorized user to Vault’s SSH secrets engine could be used to authenticate as any… | |
| Analizada | Media (5.4) | 0.46% | — | Dani-garcia Vaultwarden | 13/9/2024 | 17/6/2026 | An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A stored cross-site scripting (XSS) or, due to the default CSP, HTML injection vulnerability has been discovered in the admin dashboard. This potentially allows an authenticated attacker to inject malicious code into the dashboard, which is then… | |
| Analizada | Media (6.5) | 0.57% | — | Dani-garcia Vaultwarden | 13/9/2024 | 17/6/2026 | An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. It lacks an offboarding process for members who leave an organization. As a result, the shared organization key is not rotated when a member departs. Consequently, the departing member, whose access should be revoked, retains a copy of the… |