Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2649▼ 259 respecto a la semana anterior
Críticas / altas1356▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (3.7) | 0.41% | — | Thinkst OpencanaryAIRedisAI | 21/9/2026 | 22/9/2026 | Denial-of-Service in Redis module in Thinkst Canary's OpenCanary 0.9.9 allows an unauthenticated remote attacker cause unconstrained memory usage. | |
| Aplazada | Baja (3.7) | 0.41% | — | Thinkst CanaryAIRedisAI | 21/9/2026 | 22/9/2026 | A vulnerability in the Thinkst Canary honeypot Redis service allows an unauthenticated remote attacker to execute a Denial-of-Service attack against the honeypot. The vulnerability is accessible when the Redis service is enabled only. The Canary is NOT affected if the Redis service is disabled. Thinkst has addressed… | |
| Aplazada | Media (6.9) | 0.43% | — | MongodbAIThinkst OpencanaryAI | 22/7/2026 | 23/7/2026 | Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB module) allows Excessive Allocation. This issue affects OpenCanary 0.9.8 only. | |
| Pendiente de análisis | Baja (1.1) | 0.29% | — | Thinkst CanarytokensAI | 24/6/2026 | 25/6/2026 | Stored Cross-Site Scripting in the exposed AWS API key store of Thinkst Applied Research Canarytokens. Anonymous exploitation requires knowledge of a random identifier. This issue affects Canarytokens: from Docker tag sha-4116b92cb before sha-f5aa5c4e, from Git commit 4116b92cb before f5aa5c4e. | |
| Pendiente de análisis | Baja (2) | 0.44% | — | Thinkst CanarytokensAI | 22/6/2026 | 23/6/2026 | An HTML injection vulnerability exists in the Google Chat webhook notification sent by Thinkst Applied Research Canarytokens, enabling Interface Manipulation in Google Chat. An attacker can insert limited HTML content including links. This issue affects Canarytokens: from Docker tag sha-4aef1db90 before sha-8ab4dccd,… | |
| Pendiente de análisis | Baja (2) | 0.26% | — | Thinkst CanarytokensAI | 10/6/2026 | 17/6/2026 | An HTML injection vulnerability in the "fetch links" email sent by Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails clients that render HTML emails. This issue affects Canarytokens: from Docker tag sha-c0f3cf142 before sha-08c3f93d, from Git commit c0f3cf142… | |
| Aplazada | Baja (1.2) | 0.20% | — | Thinkst CanarytokensAI | 3/6/2026 | 22/7/2026 | An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens exists in Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails clients that render HTML emails. This issue affects Canarytokens: from Docker tag… | |
| Aplazada | Baja (1.3) | 0.45% | — | Thinkst CanarytokensAI | 27/2/2026 | 17/6/2026 | Canarytokens help track activity and actions on a network. Versions prior to `sha-7ff0e12` have a Self Cross-Site Scripting vulnerability in the "PWA" Canarytoken, whereby the Canarytoken's creator can attack themselves or someone they share the link with. The creator of a PWA Canarytoken can insert Javascript into… | |
| Modificada | Crítica (9.1) | 0.56% | — | Canarymail Canary Mail | 16/12/2025 | 5/7/2026 | When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass the built-in file protection mechanisms of both Windows OS and third-party software. | |
| Analizada | Media (5.8) | 0.22% | — | Thinkst Opencanary | 14/10/2024 | 17/6/2026 | OpenCanary, a multi-protocol network honeypot, directly executed commands taken from its config file. Prior to version 0.9.4, where the config file is stored in an unprivileged user directory but the daemon is executed by root, it’s possible for the unprivileged user to change the config file and escalate permissions… | |
| Aplazada | Media (5.4) | 0.38% | — | Thinkst CanarytokensAI | 23/7/2024 | 17/6/2026 | Canarytokens help track activity and actions on a network. Prior to `sha-8ea5315`, Canarytokens.org was vulnerable to a blind SSRF in the Webhook alert feature. When a Canarytoken is created, users choose to receive alerts either via email or via a webhook. If a webhook is supplied when a Canarytoken is first created,… | |
| Aplazada | Baja (3.5) | 0.35% | — | Thinkst CanarytokensAI | 23/7/2024 | 17/6/2026 | Canarytokens help track activity and actions on a network. A Cross-Site Scripting vulnerability was identified in the "Cloned Website" Canarytoken, whereby the Canarytoken's creator can attack themselves. The creator of a slow-redirect Canarytoken can insert Javascript into the destination URL of their slow redirect… | |
| Analizada | Media (6.5) | 0.63% | — | Thinkst Canarytokens | 6/3/2024 | 17/6/2026 | Canarytokens helps track activity and actions on a network. Canarytokens.org supports exporting the history of a Canarytoken's incidents in CSV format. The generation of these CSV files is vulnerable to a CSV Injection vulnerability. This flaw can be used by an attacker who discovers an HTTP-based Canarytoken to… | |
| Modificada | Media (6.1) | 0.52% | — | Thinkst Canarytokens | 6/1/2023 | 17/6/2026 | Canarytokens is an open source tool which helps track activity and actions on your network. A Cross-Site Scripting vulnerability was identified in the history page of triggered Canarytokens prior to sha-fb61290. An attacker who discovers an HTTP-based Canarytoken (a URL) can use this to execute Javascript in the… | |
| Modificada | Media (6.1) | 0.58% | — | Thinkst Canarytokens | 1/7/2022 | 17/6/2026 | Canarytokens is an open source tool which helps track activity and actions on your network. A Cross-Site Scripting vulnerability was identified in the history page of triggered Canarytokens. This permits an attacker who recognised an HTTP-based Canarytoken (a URL) to execute Javascript in the Canarytoken's history… | |
| Modificada | Alta (7.4) | 1.1% | — | Canarymail Canary MailLibmailcore Mailcore2 | 17/2/2021 | 17/6/2026 | core/imap/MCIMAPSession.cpp in Canary Mail before 3.22 has Missing SSL Certificate Validation for IMAP in STARTTLS mode. | |
| Modificada | Alta (7.5) | 12% | — | Thinkst Canarytokens | 14/3/2019 | 17/6/2026 | Thinkst Canarytokens through commit hash 4e89ee0 (2019-03-01) relies on limited variation in size, metadata, and timestamp, which makes it easier for attackers to estimate whether a Word document contains a token. | |
| Modificada | Alta (7.5) | 2.9% | — | Canarylabs Trendweb | 2/10/2015 | 17/6/2026 | Buffer overflow in Canary Labs Trend Web Server before 9.5.2 allows remote attackers to execute arbitrary code via a crafted TCP packet. | |
| Modificada | Alta (8.5) | 1.3% | — | Canarylabs Trendlink | 16/4/2013 | 16/6/2026 | The SaveToFile method in a certain ActiveX control in TrendDisplay.dll in Canary Labs TrendLink 9.0.2.27051 and earlier does not properly restrict the creation of files, which allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via a crafted web site. |