Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

158 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.7%—Immer Project Immer2/9/202117/6/2026
immer is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
ModificadaCrítica (9.8)1.8%—Immer Project Immer1/9/202117/6/2026
This affects the package immer before 9.0.6. A type confusion vulnerability can lead to a bypass of CVE-2020-28477 when the user-provided keys used in the path parameter are arrays. In particular, this bypass is possible because the condition (p === "__proto__" || p === "constructor") in applyPatches_ returns false if…
ModificadaAlta (7.5)2.3%—Immer Project Immer19/1/202117/6/2026
This affects all versions of package immer.
ModificadaCrítica (9.8)2.4%—Redswimmer Kiosksimple3/7/201817/6/2026
KioskSimpleService.exe in RedSwimmer KioskSimple 1.4.7.0 suffers from a privilege escalation vulnerability in the WCF endpoint. The exposed methods allow read and write access to the Windows registry and control of services. These methods may be abused to achieve privilege escalation via execution of attacker…
ModificadaMedia (4.3)26%💥 ExploitHolger Zimmermann Pi3web11/8/200916/6/2026
Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi3, allows remote attackers to cause a denial of service (crash or hang) and obtain the full pathname of the server via a request to a file in the ISAPI directory that is not an executable DLL, which…
ModificadaAlta (7.5)3.7%—Immersion Games Cellfactor Revolution12/9/200716/6/2026
Format string vulnerability in CellFactor Revolution 1.03 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a malformed nickname.
ModificadaAlta (7.5)6.1%💥 ExploitImmersion Games Cellfactor Revolution12/9/200716/6/2026
Multiple buffer overflows in CellFactor Revolution 1.03 and earlier allow remote attackers to execute arbitrary code via a long string in a (1) 0x21, (2) 0x22, or (3) 0x23 packet.
ModificadaMedia (5)8.0%💥 ExploitABE Timmerman Zml.cgi31/12/200116/6/2026
Directory traversal vulnerability in zml.cgi allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
Orbitaley — Vulnerabilidades