Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
233 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.66% | — | Peppermint | 30/10/2023 | 17/6/2026 | Peppermint Ticket Management through 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/ticket/1/file/download?filepath=../ POST request. | |
| Modificada | Alta (7.5) | 0.85% | — | Peppermint | 30/10/2023 | 17/6/2026 | Peppermint Ticket Management before 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/users/file/download?filepath=./../ POST request. | |
| Modificada | Crítica (9.8) | 1.2% | — | Mintty Project Mintty | 26/10/2023 | 17/6/2026 | An issue in Mintty v.3.6.4 and before allows a remote attacker to execute arbitrary code via crafted commands to the terminal. | |
| Modificada | Crítica (9.8) | 1.2% | — | Mintty Project Mintty | 19/10/2023 | 17/6/2026 | Terminal character injection in Mintty before 3.6.3 allows code execution via unescaped output to the terminal. | |
| Modificada | Alta (8.8) | 1.5% | — | Peppermint | 18/9/2023 | 17/6/2026 | An issue in PeppermintLabs Peppermint v.0.2.4 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the hardcoded session cookie. | |
| Modificada | Alta (8.8) | 0.78% | — | Mintplexlabs Anything-llm | 12/9/2023 | 17/6/2026 | SQL Injection in GitHub repository mintplex-labs/anything-llm prior to 0.0.1. | |
| Modificada | Alta (7.5) | 0.69% | — | Mintplexlabs Anything-llm | 12/9/2023 | 17/6/2026 | Authentication Bypass by Primary Weakness in GitHub repository mintplex-labs/anything-llm prior to 0.0.1. | |
| Modificada | Crítica (9.8) | 0.90% | — | Mintplexlabs Anythingllm | 11/9/2023 | 17/6/2026 | Relative Path Traversal in GitHub repository mintplex-labs/anything-llm prior to 0.0.1. | |
| Modificada | Alta (7.5) | 1.8% | — | Linuxmint Warpinator | 29/5/2023 | 17/6/2026 | Warpinator before 1.6.0 allows remote file deletion via directory traversal in top_dir_basenames. | |
| Modificada | Alta (8.1) | 0.92% | 💥 PoC | Peppermint | 29/3/2023 | 17/6/2026 | An issue in the password reset function of Peppermint v0.2.4 allows attackers to access the emails and passwords of the Tickets page via a crafted request. | |
| Modificada | Media (4.8) | 0.39% | — | Advancedformintegration Advanced Form Integration | 23/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in nasirahmed Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration plugin <= 1.62.0 versions. | |
| Modificada | Alta (7.5) | 1.2% | — | Tendermint | 27/12/2022 | 17/6/2026 | Due to support of Gzip compression in request bodies, as well as a lack of limiting response body sizes, a malicious server can cause a client to consume a significant amount of system resources, which may be used as a denial of service vector. | |
| Modificada | Media (6.5) | 0.30% | — | Tendermint-light-client-js Project Tendermint-light-client-jsTendermint-light-client-verifier Project Tendermint-light-client-verifierTendermint-light-client Project Tendermint-light-client | 15/12/2022 | 17/6/2026 | Tendermint is a high-performance blockchain consensus engine for Byzantine fault tolerant applications. Versions prior to 0.28.0 contain a potential attack via Improper Verification of Cryptographic Signature, affecting anyone using the tendermint-light-client and related packages to perform light client verification… | |
| Modificada | Alta (7.5) | 1.6% | — | Linuxmint Warpinator | 10/10/2022 | 17/6/2026 | Warpinator through 1.2.14 allows access outside of an intended directory, as demonstrated by symbolic directory links. | |
| Modificada | Media (5.3) | 1.4% | — | Evmos EthermintKavaCrypto CronosEvmos | 5/8/2022 | 17/6/2026 | Ethermint is an Ethereum library. In Ethermint running versions before `v0.17.2`, the contract `selfdestruct` invocation permanently removes the corresponding bytecode from the internal database storage. However, due to a bug in the `DeleteAccount`function, all contracts that used the identical bytecode (i.e shared… | |
| Modificada | Alta (7.8) | 0.30% | — | ABB Automation BuilderABB Drive ComposerABB Mint Workbench | 15/6/2022 | 17/6/2026 | Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product. | |
| Modificada | Alta (7.8) | 0.32% | — | ABB Automation BuilderABB Drive ComposerABB Mint Workbench | 15/6/2022 | 17/6/2026 | Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product. | |
| Modificada | Alta (7.8) | 0.32% | — | ABB Automation BuilderABB Drive ComposerABB Mint Workbench | 15/6/2022 | 17/6/2026 | Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product. | |
| Modificada | Alta (7.8) | 0.32% | — | ABB Automation BuilderABB Drive ComposerABB Mint Workbench | 15/6/2022 | 17/6/2026 | Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product. | |
| Modificada | Alta (7.8) | 0.21% | — | ABB Mint Workbench | 15/6/2022 | 17/6/2026 | Vulnerabilities in the Mint WorkBench allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Mint WorkBench installer file allows a low-privileged user to run a "repair" operation on the product | |
| Modificada | Alta (7.2) | 1.00% | — | Badminton Center Management System Project Badminton Center Management System | 2/6/2022 | 17/6/2026 | Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=sales/view_details&id. | |
| Modificada | Crítica (9.8) | 1.1% | — | Badminton Center Management System Project Badminton Center Management System | 2/6/2022 | 17/6/2026 | Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/classes/Master.php?f=delete_service. | |
| Modificada | Alta (7.2) | 1.00% | — | Badminton Center Management System Project Badminton Center Management System | 2/6/2022 | 17/6/2026 | Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=court_rentals/view_court_rental&id=. | |
| Modificada | Crítica (9.8) | 1.1% | — | Badminton Center Management System Project Badminton Center Management System | 2/6/2022 | 17/6/2026 | Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/classes/Master.php?f=delete_court. | |
| Modificada | Crítica (9.8) | 1.1% | — | Badminton Center Management System Project Badminton Center Management System | 2/6/2022 | 17/6/2026 | Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/classes/Master.php?f=delete_product. |