Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

236 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.2)1.5%—FlatpakDebian LinuxFedoraproject Fedora11/3/202117/6/2026
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In Flatpack since version 0.9.4 and before version 1.10.2 has a vulnerability in the "file forwarding" feature which can be used by an attacker to gain access to files that would not ordinarily be allowed by the app's…
ModificadaAlta (7.2)6.8%—Batflat15/2/202117/6/2026
Sruu.pl in Batflat 1.3.6 allows an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Users tab. To exploit this, one must login to the administration panel and edit an arbitrary user's data (username, displayed name, etc.). NOTE: This vulnerability only…
ModificadaMedia (4.8)0.98%—Flatcore15/1/202117/6/2026
An issue was discovered in flatCore before 2.0.0 build 139. A reflected XSS vulnerability was identified in the media_filter HTTP request body parameter for the acp interface. The affected parameter accepts malicious client-side script without proper input sanitization. For example, a malicious user can leverage this…
ModificadaMedia (6.5)1.5%—Flatcore15/1/202117/6/2026
An issue was discovered in flatCore before 2.0.0 build 139. A time-based blind SQL injection was identified in the selected_folder HTTP request body parameter for the acp interface. The affected parameter (which retrieves the file contents of the specified folder) was found to be accepting malicious user input without…
ModificadaMedia (4.8)0.92%—Flatcore15/1/202117/6/2026
An issue was discovered in flatCore before 2.0.0 build 139. A stored XSS vulnerability was identified in the prefs_smtp_psw HTTP request body parameter for the acp interface. An admin user can inject malicious client-side script into the affected parameter without any form of input sanitization. The injected payload…
ModificadaMedia (4.9)1.7%—Flatcore15/1/202117/6/2026
An issue was discovered in flatCore before 2.0.0 build 139. A local file disclosure vulnerability was identified in the docs_file HTTP request body parameter for the acp interface. This can be exploited with admin access rights. The affected parameter (which retrieves the contents of the specified file) was found to…
ModificadaAlta (8.8)0.57%—FlatpakDebian Linux14/1/202117/6/2026
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `flatpak-portal` service that can allow sandboxed applications to execute arbitrary code on the host system (a sandbox escape). This sandbox-escape bug is present in versions from 0.11.4 and…
ModificadaAlta (7.5)0.59%—Google Flatbuffers31/12/202017/6/2026
An issue was discovered in the flatbuffers crate through 2020-04-11 for Rust. read_scalar (and read_scalar_at) can transmute values without unsafe blocks.
ModificadaCrítica (9.8)0.58%—Google Flatbuffers31/12/202017/6/2026
An issue was discovered in the flatbuffers crate before 0.6.1 for Rust. Arbitrary bytes can be reinterpreted as a bool, defeating soundness.
ModificadaMedia (4.8)2.2%💥 ExploitFlatpress30/12/202017/6/2026
FlatPress 1.0.3 is affected by cross-site scripting (XSS) in the Blog Content component. This vulnerability can allow an attacker to inject the XSS payload in Blog content via the admin panel. Each time any user will go to that blog page, the XSS triggers and the attacker can steal the cookie according to the crafted…
ModificadaCrítica (9.8)3.1%—Flattenizer Project Flattenizer29/12/202017/6/2026
Prototype pollution vulnerability in 'flattenizer' versions 0.0.5 through 1.0.5 allows an attacker to cause a denial of service and may lead to remote code execution.
ModificadaCrítica (9.8)1.9%—Arr-flatten-unflatten Project Arr-flatten-unflatten1/9/202017/6/2026
All versions of package arr-flatten-unflatten are vulnerable to Prototype Pollution via the constructor.
ModificadaAlta (7.2)2.4%—Flatcore9/8/202017/6/2026
flatCore before 1.5.7 allows upload and execution of a .php file by an admin.
ModificadaMedia (4.8)0.61%—Flatcore9/8/202017/6/2026
flatCore before 1.5.7 allows XSS by an admin via the acp/acp.php?tn=pages&sub=edit&editpage=1 page_linkname, page_title, page_content, or page_extracontent parameter, or the acp/acp.php?tn=system&sub=sys_pref prefs_pagename, prefs_pagetitle, or prefs_pagesubtitle parameter.
ModificadaMedia (6.3)0.73%—Component-flatten Project Component-flatten18/2/202017/6/2026
All versions of component-flatten are vulnerable to Prototype Pollution. The a function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
ModificadaCrítica (9.8)2.5%—Libflate Project Libflate26/8/201917/6/2026
An issue was discovered in the libflate crate before 0.1.25 for Rust. MultiDecoder::read has a use-after-free, leading to arbitrary code execution.
ModificadaAlta (8.8)2.3%💥 ExploitFlatcore18/7/201917/6/2026
A CSRF vulnerability was found in flatCore before 1.5, leading to the upload of arbitrary .php files via acp/core/files.upload-script.php.
ModificadaAlta (7.2)7.0%💥 ExploitFlatcore30/3/201917/6/2026
An issue was discovered in flatCore 1.4.7. acp/acp.php allows remote authenticated administrators to upload arbitrary .php files, related to the addons feature.
ModificadaCrítica (9.8)2.6%—HP Color Laserjet Cm4540 MFP FirmwareHP Color Laserjet Cp5525 FirmwareHP Color Laserjet Enterprise Flow MFP M681f FirmwareHP Color Laserjet Enterprise Flow MFP M681z Firmware+13427/3/201917/6/2026
In HP LaserJet Enterprise, HP PageWide Enterprise, HP LaserJet Managed, and HP OfficeJet Enterprise Printers, solution application signature checking may allow potential execution of arbitrary code.
ModificadaCrítica (9)1.9%—Flatpak26/3/201917/6/2026
Flatpak before 1.0.8, 1.1.x and 1.2.x before 1.2.4, and 1.3.x before 1.3.1 allows a sandbox bypass. Flatpak versions since 0.8.1 address CVE-2017-5226 by using a seccomp filter to prevent sandboxed apps from using the TIOCSTI ioctl, which could otherwise be used to inject commands into the controlling terminal so that…
ModificadaAlta (8.2)0.47%—FlatpakDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+412/2/201917/6/2026
Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file.
ModificadaAlta (8.8)0.41%—FlatpakRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+32/2/201817/6/2026
In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.
ModificadaMedia (6.1)0.84%—Flatcore-cms10/1/201817/6/2026
flatCore-CMS 1.4.6 is vulnerable to reflected XSS in user_management.php due to the use of $_SERVER['PHP_SELF'] to build links and a stored XSS in the admin log panel by specifying a malformed User-Agent string.
ModificadaAlta (7.8)0.36%—FlatpakDebian Linux21/6/201717/6/2026
In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example setuid or world-writable. The files are deployed with those permissions, which would let a local attacker run the setuid executable or write to the world-writable location.…
ModificadaMedia (6.1)0.74%—Flatcore6/6/201717/6/2026
Cross site scripting (XSS) vulnerability in pages.edit_form.php in flatCore 1.4.6 allows remote attackers to inject arbitrary JavaScript via the PATH_INFO in an acp.php URL, due to use of unsanitized $_SERVER['PHP_SELF'] to generate URLs.
Orbitaley — Vulnerabilidades