Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

233 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.66%—Peppermint30/10/202317/6/2026
Peppermint Ticket Management through 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/ticket/1/file/download?filepath=../ POST request.
ModificadaAlta (7.5)0.85%—Peppermint30/10/202317/6/2026
Peppermint Ticket Management before 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/users/file/download?filepath=./../ POST request.
ModificadaCrítica (9.8)1.2%—Mintty Project Mintty26/10/202317/6/2026
An issue in Mintty v.3.6.4 and before allows a remote attacker to execute arbitrary code via crafted commands to the terminal.
ModificadaCrítica (9.8)1.2%—Mintty Project Mintty19/10/202317/6/2026
Terminal character injection in Mintty before 3.6.3 allows code execution via unescaped output to the terminal.
ModificadaAlta (8.8)1.5%—Peppermint18/9/202317/6/2026
An issue in PeppermintLabs Peppermint v.0.2.4 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the hardcoded session cookie.
ModificadaAlta (8.8)0.78%—Mintplexlabs Anything-llm12/9/202317/6/2026
SQL Injection in GitHub repository mintplex-labs/anything-llm prior to 0.0.1.
ModificadaAlta (7.5)0.69%—Mintplexlabs Anything-llm12/9/202317/6/2026
Authentication Bypass by Primary Weakness in GitHub repository mintplex-labs/anything-llm prior to 0.0.1.
ModificadaCrítica (9.8)0.90%—Mintplexlabs Anythingllm11/9/202317/6/2026
Relative Path Traversal in GitHub repository mintplex-labs/anything-llm prior to 0.0.1.
ModificadaAlta (7.5)1.8%—Linuxmint Warpinator29/5/202317/6/2026
Warpinator before 1.6.0 allows remote file deletion via directory traversal in top_dir_basenames.
ModificadaAlta (8.1)0.92%💥 PoCPeppermint29/3/202317/6/2026
An issue in the password reset function of Peppermint v0.2.4 allows attackers to access the emails and passwords of the Tickets page via a crafted request.
ModificadaMedia (4.8)0.39%—Advancedformintegration Advanced Form Integration23/3/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in nasirahmed Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration plugin <= 1.62.0 versions.
ModificadaAlta (7.5)1.2%—Tendermint27/12/202217/6/2026
Due to support of Gzip compression in request bodies, as well as a lack of limiting response body sizes, a malicious server can cause a client to consume a significant amount of system resources, which may be used as a denial of service vector.
ModificadaMedia (6.5)0.30%—Tendermint-light-client-js Project Tendermint-light-client-jsTendermint-light-client-verifier Project Tendermint-light-client-verifierTendermint-light-client Project Tendermint-light-client15/12/202217/6/2026
Tendermint is a high-performance blockchain consensus engine for Byzantine fault tolerant applications. Versions prior to 0.28.0 contain a potential attack via Improper Verification of Cryptographic Signature, affecting anyone using the tendermint-light-client and related packages to perform light client verification…
ModificadaAlta (7.5)1.6%—Linuxmint Warpinator10/10/202217/6/2026
Warpinator through 1.2.14 allows access outside of an intended directory, as demonstrated by symbolic directory links.
ModificadaMedia (5.3)1.4%—Evmos EthermintKavaCrypto CronosEvmos5/8/202217/6/2026
Ethermint is an Ethereum library. In Ethermint running versions before `v0.17.2`, the contract `selfdestruct` invocation permanently removes the corresponding bytecode from the internal database storage. However, due to a bug in the `DeleteAccount`function, all contracts that used the identical bytecode (i.e shared…
ModificadaAlta (7.8)0.30%—ABB Automation BuilderABB Drive ComposerABB Mint Workbench15/6/202217/6/2026
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product.
ModificadaAlta (7.8)0.32%—ABB Automation BuilderABB Drive ComposerABB Mint Workbench15/6/202217/6/2026
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product.
ModificadaAlta (7.8)0.32%—ABB Automation BuilderABB Drive ComposerABB Mint Workbench15/6/202217/6/2026
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product.
ModificadaAlta (7.8)0.32%—ABB Automation BuilderABB Drive ComposerABB Mint Workbench15/6/202217/6/2026
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product.
ModificadaAlta (7.8)0.21%—ABB Mint Workbench15/6/202217/6/2026
Vulnerabilities in the Mint WorkBench allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Mint WorkBench installer file allows a low-privileged user to run a "repair" operation on the product
ModificadaAlta (7.2)1.00%—Badminton Center Management System Project Badminton Center Management System2/6/202217/6/2026
Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=sales/view_details&id.
ModificadaCrítica (9.8)1.1%—Badminton Center Management System Project Badminton Center Management System2/6/202217/6/2026
Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/classes/Master.php?f=delete_service.
ModificadaAlta (7.2)1.00%—Badminton Center Management System Project Badminton Center Management System2/6/202217/6/2026
Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=court_rentals/view_court_rental&id=.
ModificadaCrítica (9.8)1.1%—Badminton Center Management System Project Badminton Center Management System2/6/202217/6/2026
Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/classes/Master.php?f=delete_court.
ModificadaCrítica (9.8)1.1%—Badminton Center Management System Project Badminton Center Management System2/6/202217/6/2026
Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/classes/Master.php?f=delete_product.
Orbitaley — Vulnerabilidades