Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▲ 36 respecto a la semana anterior
Críticas / altas1474▲ 366 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 0.16% | — | GNU CflowAI | 8/8/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in GNU cflow up to 1.8. Affected by this issue is the function yylex of the file c.c of the component Lexer. The manipulation leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and… | |
| Aplazada | Baja (1.9) | 0.15% | — | GNU CflowAI | 8/8/2025 | 17/6/2026 | A vulnerability classified as problematic was found in GNU cflow up to 1.8. Affected by this vulnerability is the function yylex of the file c.c of the component Lexer. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be… | |
| Aplazada | Alta (7.5) | 0.82% | — | RAD Secflow-2AI | 8/3/2024 | 17/6/2026 | RAD SecFlow-2 devices with Hardware 0202, Firmware 4.1.01.63, and U-Boot 2010.12 allow URIs beginning with /.. for Directory Traversal, as demonstrated by reading /etc/shadow. | |
| Modificada | Alta (7.5) | 1.2% | — | GNU Cflow | 18/5/2023 | 17/6/2026 | A vulnerability was found in GNU cflow 1.7. It has been rated as problematic. This issue affects the function func_body/parse_variable_declaration of the file parser.c. The manipulation leads to denial of service. The exploit has been disclosed to the public and may be used. The identifier VDB-229373 was assigned to… | |
| Modificada | Media (5.5) | 0.42% | — | GNU CflowFedoraproject Fedora | 18/5/2021 | 17/6/2026 | Use-after-Free vulnerability in cflow 1.6 in the void call(char *name, int line) function at src/parser.c, which could cause a denial of service via the pointer variable caller->callee. | |
| Modificada | Media (6.1) | 2.0% | — | RAD Secflow-1v Firmware | 17/9/2020 | 17/6/2026 | A vulnerability in the web-based management interface of RAD SecFlow-1v through 2020-05-21 could allow an authenticated attacker to upload a JavaScript file, with a stored XSS payload, that will remain stored in the system as an OVPN file in Configuration-Services-Security-OpenVPN-Config or as the static key file in… | |
| Modificada | Alta (8.8) | 4.7% | — | RAD Secflow-1v Firmware | 16/9/2020 | 17/6/2026 | A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI on an affected device.… | |
| Modificada | Media (6.5) | 1.1% | — | GNU Cflow | 9/9/2019 | 17/6/2026 | GNU cflow through 1.6 has a heap-based buffer over-read in the nexttoken function in parser.c. | |
| Modificada | Media (6.5) | 1.1% | — | GNU Cflow | 9/9/2019 | 17/6/2026 | GNU cflow through 1.6 has a use-after-free in the reference function in parser.c. | |
| Modificada | Media (6.1) | 1.4% | — | Jenkins Electricflow | 11/6/2019 | 17/6/2026 | A reflected cross site scripting vulnerability in Jenkins ElectricFlow Plugin 1.1.6 and earlier allowed attackers able to control the output of the ElectricFlow API to inject arbitrary HTML and JavaScript in job configuration forms containing post-build steps provided by this plugin. | |
| Modificada | Media (5.4) | 1.1% | — | Jenkins Electricflow | 11/6/2019 | 17/6/2026 | A stored cross site scripting vulnerability in Jenkins ElectricFlow Plugin 1.1.5 and earlier allowed attackers able to configure jobs in Jenkins or control the output of the ElectricFlow API to inject arbitrary HTML and JavaScript in the plugin-provided output on build status pages. | |
| Modificada | Media (6.5) | 1.3% | — | Jenkins Electricflow | 11/6/2019 | 17/6/2026 | Jenkins ElectricFlow Plugin 1.1.5 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM when MultipartUtility.java is used to upload files. | |
| Modificada | Media (4.3) | 1.3% | — | Jenkins Electricflow | 11/6/2019 | 17/6/2026 | Missing permission checks in Jenkins ElectricFlow Plugin 1.1.5 and earlier in various HTTP endpoints allowed users with Overall/Read access to obtain information about the Jenkins ElectricFlow Plugin configuration and configuration of connected ElectricFlow instances. | |
| Modificada | Media (4.3) | 1.8% | — | Jenkins Electricflow | 11/6/2019 | 17/6/2026 | A missing permission check in Jenkins ElectricFlow Plugin 1.1.5 and earlier in Configuration#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials. | |
| Modificada | Media (4.3) | 1.1% | — | Jenkins Electricflow | 11/6/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins ElectricFlow Plugin 1.1.5 and earlier in Configuration#doTestConnection allowed attackers to connect to an attacker-specified URL using attacker-specified credentials. |