Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2629▼ 216 respecto a la semana anterior
Críticas / altas1378▲ 154 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.45% | — | Cleanuparr Project Cleanuparr | 16/3/2026 | 17/6/2026 | Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. From 2.7.0 to 2.8.0, the /api/auth/login endpoint contains a logic flaw that allows unauthenticated remote attackers to enumerate valid usernames by measuring the… | |
| Modificada | Media (6.5) | 0.30% | — | Dolibarr Project Timesheet Project Dolibarr Project Timesheet | 27/12/2022 | 17/6/2026 | A vulnerability was found in dolibarr_project_timesheet up to 4.5.5. It has been declared as problematic. This vulnerability affects unknown code of the component Form Handler. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. Upgrading to version 4.5.6.a is able to address… | |
| Modificada | Crítica (9.8) | 2.1% | — | Go-unarr Project Go-unarr | 8/8/2021 | 17/6/2026 | unarr.go in go-unarr (aka Go bindings for unarr) 0.1.1 allows Directory Traversal via ../ in a pathname within a TAR archive. | |
| Modificada | Crítica (9.8) | 1.5% | — | ARR Project ARR | 31/12/2020 | 17/6/2026 | An issue was discovered in the arr crate through 2020-08-25 for Rust. Uninitialized memory is dropped by Array::new_from_template. | |
| Modificada | Crítica (9.8) | 1.5% | — | ARR Project ARR | 31/12/2020 | 17/6/2026 | An issue was discovered in the arr crate through 2020-08-25 for Rust. There is a buffer overflow in Index and IndexMut. | |
| Modificada | Media (4.7) | 0.19% | — | ARR Project ARR | 31/12/2020 | 17/6/2026 | An issue was discovered in the arr crate through 2020-08-25 for Rust. An attacker can smuggle non-Sync/Send types across a thread boundary to cause a data race. |