Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 334 respecto a la semana anterior
Críticas / altas1340▲ 73 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.50% | — | Ancorathemes DentaluxAI | 25/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Dentalux dentalux allows PHP Local File Inclusion.This issue affects Dentalux: from n/a through <= 3.3. | |
| Analizada | Alta (8.7) | 0.57% | — | Protocol Yamux | 16/3/2026 | 17/6/2026 | Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. Prior to 0.13.10, the Rust implementation of Yamux can panic when processing a crafted inbound Data frame that sets SYN and uses a body length greater than DEFAULT_CREDIT (e.g. 262145). On the first packet of a new inbound stream, stream… | |
| Analizada | Alta (8.7) | 0.57% | — | Protocol Yamux | 13/3/2026 | 17/6/2026 | Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. From 0.13.0 to before 0.13.9, a specially crafted WindowUpdate can cause arithmetic overflow in send-window accounting, which triggers a panic in the connection state machine. This is remotely reachable over a normal network connection… | |
| Aplazada | Alta (7.5) | 0.76% | — | Libp2pAIProtocol YamuxAI | 1/5/2024 | 17/6/2026 | Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. The Rust implementation of the Yamux stream multiplexer uses a vector for pending frames. This vector is not bounded in length. Every time the Yamux protocol requires sending of a new frame, this frame gets appended to this vector. This… | |
| Modificada | Alta (7.5) | 1.1% | — | Aluxdigital Aluxtoken | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for ALUXToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Baja (2.1) | 0.43% | — | SGI IrixApple A UXBSDSunos | 31/12/1999 | 16/6/2026 | lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other BSD-based operating systems allows local users to create or overwrite arbitrary files via a symlink attack that is triggered after invoking lpr 1000 times. | |
| Modificada | Alta (7.2) | 0.70% | — | Apple A UXDigital OSF 1FreebsdHp-ux+5 | 26/6/1996 | 16/6/2026 | The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access. |