Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
822 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.83% | — | Kingdee Cloud Starry SKY Enterprise EditionAI | 4/8/2025 | 17/6/2026 | A security vulnerability has been detected in Kingdee Cloud-Starry-Sky Enterprise Edition up to 8.2. This issue affects the function BaseServiceFactory.getFileUploadService.deleteFileAction of the file… | |
| Aplazada | Media (5.3) | 0.58% | — | Encode StarletteAI | 21/7/2025 | 17/6/2026 | Starlette is a lightweight ASGI (Asynchronous Server Gateway Interface) framework/toolkit, designed for building async web services in Python. In versions 0.47.1 and below, when parsing a multi-part form with large files (greater than the default max spool size) starlette will block the main thread to roll the file… | |
| Aplazada | Media (5.3) | 0.31% | — | Dromara NorthstarAI | 14/7/2025 | 17/6/2026 | A vulnerability was found in Dromara Northstar up to 7.3.5. It has been rated as critical. Affected by this issue is the function preHandle of the file northstar-main/src/main/java/org/dromara/northstar/web/interceptor/AuthorizationInterceptor.java of the component Path Handler. The manipulation of the argument… | |
| Analizada | Media (5.4) | 0.38% | — | Starcitizen.tools Citizen | 3/7/2025 | 17/6/2026 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. From versions 1.9.4 to before 3.4.0, short descriptions set via the ShortDescription extension are inserted as raw HTML by the Citizen skin, allowing any user to insert arbitrary HTML into the DOM by editing a page. This issue has been… | |
| Analizada | Media (5.4) | 0.34% | — | Starcitizen.tools Citizen | 3/7/2025 | 17/6/2026 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. From versions 1.9.4 to before 3.4.0, page descriptions are inserted into raw HTML without proper sanitization by the Citizen skin when using the old search bar. Any user with page editing privileges can insert cross-site scripting (XSS)… | |
| Aplazada | Media (6.5) | 0.24% | — | Winstar Wn572hp3AI | 2/7/2025 | 5/7/2026 | WINSTAR WN572HP3 v230525 was discovered to contain a heap overflow via the CONTENT_LENGTH variable at /cgi-bin/upload.cgi. | |
| Aplazada | Media (5.9) | 0.25% | — | Ecoal95 EC Stars RatingAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ecoal95 EC Stars Rating ec-stars-rating allows Stored XSS.This issue affects EC Stars Rating: from n/a through <= 1.0.11. | |
| Aplazada | Alta (7.1) | 0.26% | — | Themeton Seven StarsAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeton Seven Stars allows Stored XSS. This issue affects Seven Stars: from n/a through 1.4.4. | |
| Aplazada | Media (5.5) | 0.43% | — | Kingdee Cloud-starry-sky Enterprise EditionAIApache FreemarkerAI | 27/6/2025 | 17/6/2026 | A vulnerability was found in Kingdee Cloud-Starry-Sky Enterprise Edition 6.x/7.x/8.x/9.0. It has been rated as critical. Affected by this issue is the function plugin.buildMobilePopHtml of the file \k3\o2o\bos\webapp\action\DynamicForm 4 Action.class of the component Freemarker Engine. The manipulation leads to… | |
| Aplazada | Crítica (9.3) | 0.53% | — | Hamastar Technology WimpAI | 16/6/2025 | 17/6/2026 | The WIMP website co-construction management platform from HAMASTAR Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Analizada | Media (4.8) | 0.41% | — | Starcitizen.tools Citizen | 12/6/2025 | 17/6/2026 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. All system messages in menu headings using the Menu.mustache template are inserted as raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This impacts wikis where a group has the `editinterface`… | |
| Analizada | Media (5.4) | 0.42% | — | Starcitizen.tools Citizen | 12/6/2025 | 17/6/2026 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various date messages returned by `Language::userDate` are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This impacts wikis where a group has the `editinterface` but not the… | |
| Analizada | Media (5.4) | 0.41% | — | Starcitizen.tools Citizen | 12/6/2025 | 17/6/2026 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various preferences messages are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This vulnerability is fixed in 3.3.1. | |
| Analizada | Media (5.4) | 0.41% | — | Starcitizen.tools Citizen | 12/6/2025 | 17/6/2026 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The citizen-search-noresults-title and citizen-search-noresults-desc system messages are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This vulnerability is fixed in 3.3.1. | |
| Analizada | Media (5.4) | 0.41% | — | Starcitizen.tools Citizen | 12/6/2025 | 17/6/2026 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Multiple system messages are inserted into the CommandPaletteFooter as raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This impacts wikis where a group has the `editinterface` but not the… | |
| Aplazada | Media (6.3) | 0.24% | — | Istar Configuration UtilityAI | 11/6/2025 | 17/6/2026 | The iSTAR Configuration Utility (ICU) tool leaks memory, which could result in the unintended exposure of unauthorized data from the Windows PC that ICU is running on. | |
| Aplazada | Alta (8.8) | 0.44% | — | Openknowledgemaps HeadstartAI | 29/5/2025 | 17/6/2026 | An issue in OpenKnowledgeMaps Headstart v7 allows a remote attacker to escalate privileges via the url parameter of the getPDF.php component | |
| Aplazada | Crítica (9.8) | 0.59% | — | Themeton Hotstar - Multi-purpose Business ThemeAI | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in themeton HotStar – Multi-Purpose Business Theme allows Object Injection. This issue affects HotStar – Multi-Purpose Business Theme: from n/a through 1.4. | |
| Analizada | Alta (8.8) | 0.39% | — | Lumigo Measure-cold-start | 22/5/2025 | 17/6/2026 | Insecure permissions in measure-cold-start v1.4.1 allows attackers to escalate privileges and compromise the customer cloud account. | |
| Aplazada | Media (5.3) | 0.31% | — | Themeton Hotstar Multi Purpose Business ThemeAI | 16/5/2025 | 17/6/2026 | Missing Authorization vulnerability in themeton HotStar – Multi-Purpose Business Theme allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects HotStar – Multi-Purpose Business Theme: from n/a through 1.4. | |
| Aplazada | Media (4.3) | 0.20% | — | Themeton Seven StarsAI | 16/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in themeton Seven Stars allows Cross Site Request Forgery. This issue affects Seven Stars: from n/a through 1.4.4. | |
| Modificada | Baja (3.5) | 0.32% | — | Vollstart Event Tickets With Ticket Scanner | 15/5/2025 | 17/6/2026 | The Event Tickets with Ticket Scanner WordPress plugin before 2.3.8 does not sanitise and escape some parameters, which could allow users with a role as low as admin to perform Cross-Site Scripting attacks | |
| Aplazada | Media (6.5) | 0.26% | — | Jeff Starr Simple Blog StatsAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Simple Blog Stats simple-blog-stats allows Stored XSS.This issue affects Simple Blog Stats: from n/a through <= 20250416. | |
| Analizada | Media (5.3) | 0.30% | — | Withstars Books-management-system | 27/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in withstars Books-Management-System 1.0. Affected is an unknown function of the file /api/article/del of the component Article Handler. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has… | |
| Analizada | Media (6.9) | 0.66% | — | Withstars Books-management-system | 27/4/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in withstars Books-Management-System 1.0. This issue affects some unknown processing of the file /admin/article/list of the component Background Interface. The manipulation leads to missing authorization. The attack may be initiated remotely. The… |