Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
158 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.7% | — | Immer Project Immer | 2/9/2021 | 17/6/2026 | immer is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Modificada | Crítica (9.8) | 1.8% | — | Immer Project Immer | 1/9/2021 | 17/6/2026 | This affects the package immer before 9.0.6. A type confusion vulnerability can lead to a bypass of CVE-2020-28477 when the user-provided keys used in the path parameter are arrays. In particular, this bypass is possible because the condition (p === "__proto__" || p === "constructor") in applyPatches_ returns false if… | |
| Modificada | Alta (7.5) | 2.3% | — | Immer Project Immer | 19/1/2021 | 17/6/2026 | This affects all versions of package immer. | |
| Modificada | Crítica (9.8) | 2.4% | — | Redswimmer Kiosksimple | 3/7/2018 | 17/6/2026 | KioskSimpleService.exe in RedSwimmer KioskSimple 1.4.7.0 suffers from a privilege escalation vulnerability in the WCF endpoint. The exposed methods allow read and write access to the Windows registry and control of services. These methods may be abused to achieve privilege escalation via execution of attacker… | |
| Modificada | Media (4.3) | 26% | 💥 Exploit | Holger Zimmermann Pi3web | 11/8/2009 | 16/6/2026 | Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi3, allows remote attackers to cause a denial of service (crash or hang) and obtain the full pathname of the server via a request to a file in the ISAPI directory that is not an executable DLL, which… | |
| Modificada | Alta (7.5) | 3.7% | — | Immersion Games Cellfactor Revolution | 12/9/2007 | 16/6/2026 | Format string vulnerability in CellFactor Revolution 1.03 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a malformed nickname. | |
| Modificada | Alta (7.5) | 6.1% | 💥 Exploit | Immersion Games Cellfactor Revolution | 12/9/2007 | 16/6/2026 | Multiple buffer overflows in CellFactor Revolution 1.03 and earlier allow remote attackers to execute arbitrary code via a long string in a (1) 0x21, (2) 0x22, or (3) 0x23 packet. | |
| Modificada | Media (5) | 8.0% | 💥 Exploit | ABE Timmerman Zml.cgi | 31/12/2001 | 16/6/2026 | Directory traversal vulnerability in zml.cgi allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. |