Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
4419 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.25% | — | ASK ME Anything AnonymouslyAI | 25/1/2025 | 17/6/2026 | The Ask Me Anything (Anonymously) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'askmeanythingpeople' shortcode in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.37% | — | Christian Leuenberg Restrict Anonymous AccessAI | 24/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Christian Leuenberg Restrict Anonymous Access restrict-anonymous-access allows Stored XSS.This issue affects Restrict Anonymous Access: from n/a through <= 1.2. | |
| Aplazada | Alta (7.1) | 0.17% | — | Schalk Burger Anonymize LinksAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Schalk Burger Anonymize Links anonymize-links allows Stored XSS.This issue affects Anonymize Links: from n/a through <= 1.1. | |
| Aplazada | Alta (7.1) | 0.26% | — | Andon Ivanov OZ CanonicalAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andon Ivanov OZ Canonical oz-canonical allows Reflected XSS.This issue affects OZ Canonical: from n/a through <= 0.5. | |
| Analizada | Baja (3.8) | 0.16% | — | Canonical LXD | 6/12/2024 | 17/6/2026 | Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured. | |
| Analizada | Baja (3.8) | 0.16% | — | Canonical LXD | 6/12/2024 | 17/6/2026 | Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store. | |
| Analizada | Media (5.3) | 0.57% | — | Cayenne Anonymous Restricted Content | 21/11/2024 | 17/6/2026 | The Anonymous Restricted Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.5 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to logged-in users. | |
| Aplazada | Crítica (10) | 0.51% | — | AZZ Anonim PostingAI | 16/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Denis Azz Anonim Posting azz-anonim-posting allows Upload a Web Shell to a Web Server.This issue affects Azz Anonim Posting: from n/a through <= 0.9. | |
| Analizada | Media (6.4) | 0.28% | — | Canonical Authd | 10/10/2024 | 17/6/2026 | Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions. A local attacker who can register user names could spoof another user's ID and gain their privileges. | |
| Analizada | Alta (8.8) | 0.58% | — | Canonical Authd | 3/10/2024 | 17/6/2026 | Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM operation with it, including authenticating as them. | |
| Analizada | Media (5.5) | 0.21% | — | Canonical Juju | 2/10/2024 | 17/6/2026 | Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available without authentication locally to network namespace users. This enables denial of service attacks. | |
| Analizada | Media (6.5) | 0.19% | — | Canonical Juju | 2/10/2024 | 17/6/2026 | Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the default network namespace may connect to the @/var/lib/juju/agents/unit-xxxx-yyyy/agent.socket and perform actions that are normally reserved to a juju charm. | |
| Analizada | Alta (8) | 0.50% | — | Canonical Juju | 2/10/2024 | 17/6/2026 | JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace can connect to an abstract domain socket and guess the JUJU_CONTEXT_ID value. This gives the unprivileged user access to the same… | |
| Analizada | Alta (7.5) | 0.18% | — | Canonical Anbox Cloud | 18/9/2024 | 17/6/2026 | Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent. An attacker must be able to machine-in-the-middle the Anbox Stream Agent from within an internal network before they can attempt to take advantage of this. | |
| Modificada | Baja (3.8) | 0.38% | — | Canonical Juju | 29/7/2024 | 17/6/2026 | An issue was discovered in Juju that resulted in the leak of the sensitive context ID, which allows a local unprivileged attacker to access other sensitive data or relation accessible to the local charm. | |
| Modificada | Alta (7.3) | 0.23% | — | Canonical Snapd | 25/7/2024 | 17/6/2026 | In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap. The snap format is a squashfs file-system image and so can contain symbolic links and other file types. Various file entries within the snap squashfs image (such as icons and desktop files etc) are… | |
| Modificada | Media (6.6) | 0.21% | — | Canonical Snapd | 25/7/2024 | 17/6/2026 | In snapd versions prior to 2.62, snapd failed to properly check the file type when extracting a snap. The snap format is a squashfs file-system image and so can contain files that are non-regular files (such as pipes or sockets etc). Various file entries within the snap squashfs image (such as icons etc) are directly… | |
| Modificada | Alta (8.2) | 0.31% | — | Canonical Snapd | 25/7/2024 | 17/6/2026 | In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict writes to the $HOME/bin path. In Ubuntu, when this path exists, it is automatically added to the users PATH. An attacker who could convince a user to install a malicious snap which used the 'home' plug… | |
| Analizada | Alta (7.8) | 0.26% | — | Canonical Ubuntu Desktop Provision | 23/7/2024 | 17/6/2026 | An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate their privilege. | |
| Aplazada | Media (4.4) | 0.20% | — | Canonical OPSAI | 22/7/2024 | 17/6/2026 | The ops library is a Python framework for developing and testing Kubernetes and machine charms. The issue here is that ops passes the secret content as one of the args via CLI. This issue may affect any of the charms that are using: Juju (>=3.0), Juju secrets and not correctly capturing and processing… | |
| Modificada | Alta (8.1) | 100% | 💥 Exploit | Sonicwall SMA 6200 FirmwareSonicwall SMA 7200 FirmwareArista EOSCanonical Ubuntu Linux+49 | 1/7/2024 | 1/9/2026 | A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period. | |
| Analizada | Media (5.5) | 0.15% | — | Canonical Ubuntu Advantage Desktop Daemon | 27/6/2024 | 17/6/2026 | Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext. | |
| Analizada | Alta (8.8) | 0.26% | — | Canonical SnapdCanonical Ubuntu Linux | 21/6/2024 | 17/6/2026 | When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd will move processes from the containers created and managed by these snaps into the cgroup of the main daemon within the snap itself when reloading system units. This may… | |
| Aplazada | Media (4.3) | 0.21% | — | Decentralizejustice AnonymouslockerAIDecentralizejustice AnonbackendAI | 13/6/2024 | 17/6/2026 | An issue in Annonshop.app DecentralizeJustice/anonymousLocker commit 2b2b4 to ba9fd and DecentralizeJustice/anonBackend commit 57837 to cd815 was discovered to store credentials in plaintext. | |
| Aplazada | Media (6.5) | 0.39% | — | Annonshop APPAIDecentralizejustice AnonymouslockerAI | 13/6/2024 | 17/6/2026 | An issue in Annonshop.app DecentralizeJustice/ anonymousLocker commit 2b2b4 allows attackers to send messages erroneously attributed to arbitrary users via a crafted HTTP request. |