Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
50 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.32% | — | Simple Hierarchical Select Project Simple Hierarchical Select | 21/5/2026 | 23/7/2026 | Simple Hierarchical Select (SHS) for Drupal 7 contains cross-site scripting risk due to improper output escaping of term-derived text. Confirmed affected paths include field formatter output (shs_field_formatter_view) and term-tree child-term data generation (shs_term_get_children). Malicious taxonomy term names can… | |
| Analizada | Alta (8.6) | 0.21% | — | HNB Project Hierarchical Notebook | 28/3/2026 | 17/6/2026 | HNB Organizer 1.9.18-10 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized argument to the -rc command-line parameter. Attackers can craft a malicious input string exceeding 108 bytes containing shellcode and a return address to overwrite the… | |
| Aplazada | Media (5.4) | 0.24% | — | Edge-themes ArchiconAI | 25/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Edge-Themes Archicon archicon allows Object Injection.This issue affects Archicon: from n/a through < 1.7. | |
| Aplazada | Media (6.4) | 0.14% | — | No-chicken Echo-mateAI | 24/3/2026 | 17/6/2026 | Use After Free vulnerability in No-Chicken Echo-Mate.This issue affects Echo-Mate: before V250329. | |
| Aplazada | Alta (7.3) | 0.12% | — | No-chicken Echo-mateAI | 24/3/2026 | 17/6/2026 | Use After Free vulnerability in No-Chicken Echo-Mate (SDK/rv1106-sdk/sysdrv/source/kernel/mm modules). This vulnerability is associated with program files rmap.C. This issue affects Echo-Mate: before V250329. | |
| Aplazada | Alta (7.3) | 0.12% | — | No-chicken Echo-mateAI | 24/3/2026 | 17/6/2026 | Improper Handling of Values vulnerability in No-Chicken Echo-Mate (SDK/rv1106-sdk/sysdrv/source/kernel/include/net/netfilter modules). This vulnerability is associated with program files nf_tables.H, nft_byteorder.C, nft_meta.C. This issue affects Echo-Mate: before V250329. | |
| Analizada | Alta (7.3) | 0.27% | — | Uchicago Parsl | 8/1/2026 | 17/6/2026 | Parsl is a Python parallel scripting library. A SQL Injection vulnerability exists in the parsl-visualize component of versions prior to 2026.01.05. The application constructs SQL queries using unsafe string formatting (Python % operator) with user-supplied input (workflow_id) directly from URL routes. This allows an… | |
| Aplazada | Alta (7.1) | 0.17% | — | Klbtheme Machic CoreAI | 5/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in KlbTheme Machic Core allows DOM-Based XSS.This issue affects Machic Core: from n/a through 1.2.6. | |
| Aplazada | Alta (8.1) | 0.50% | — | Ancorathemes GlamchicAI | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes GlamChic glamchic allows PHP Local File Inclusion.This issue affects GlamChic: from n/a through <= 1.0.11. | |
| Aplazada | Media (6.5) | 0.23% | — | Atakanau Automatically Hierarchic Categories IN MenuAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atakan Au Automatically Hierarchic Categories in Menu automatically-hierarchic-categories-in-menu allows Stored XSS.This issue affects Automatically Hierarchic Categories in Menu: from n/a through <= 2.0.9. | |
| Aplazada | Media (6.4) | 0.34% | — | Automatically Hierarchic Categories IN MenuAI | 30/1/2025 | 17/6/2026 | The Automatically Hierarchic Categories in Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'autocategorymenu' shortcode in all versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Media (4.3) | 0.18% | — | Rarathemes Chic | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in raratheme Chic Lite chic-lite allows Cross Site Request Forgery.This issue affects Chic Lite: from n/a through <= 1.1.3. | |
| Aplazada | Media (6.5) | 0.25% | — | Atakanau Automatically Hierarchic Categories IN MenuAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atakan Au Automatically Hierarchic Categories in Menu automatically-hierarchic-categories-in-menu allows Stored XSS.This issue affects Automatically Hierarchic Categories in Menu: from n/a through <= 2.0.5. | |
| Aplazada | Media (4.3) | 0.26% | — | Klbtheme ClotyaAIKlbtheme CosmetsyAIKlbtheme FurnobAIKlbtheme BacolaAI+3 | 26/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in KlbTheme Clotya theme, KlbTheme Cosmetsy theme, KlbTheme Furnob theme, KlbTheme Bacola theme, KlbTheme Partdo theme, KlbTheme Medibazar theme, KlbTheme Machic theme.This issue affects Clotya theme: from n/a through 1.1.6; Cosmetsy theme: from n/a through 1.7.7; Furnob… | |
| Modificada | Alta (8.8) | 0.64% | — | Campcodes Chic Beauty Salon | 29/12/2023 | 17/6/2026 | A vulnerability classified as critical was found in Campcodes Chic Beauty Salon 20230703. Affected by this vulnerability is an unknown functionality of the file product-list.php of the component Product Handler. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 1.3% | — | Call-cc Chicken | 10/12/2022 | 17/6/2026 | egg-compile.scm in CHICKEN 5.x before 5.3.1 allows arbitrary OS command execution during package installation via escape characters in a .egg file. | |
| Modificada | Crítica (9.8) | 1.6% | — | Cct95 Chichen Tech CMS | 22/10/2021 | 17/6/2026 | Chichen Tech CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the file product_list.php via the id and cid parameters. | |
| Modificada | Crítica (9.8) | 4.7% | — | Call-cc ChickenDebian Linux | 22/11/2019 | 17/6/2026 | Buffer overflow in CHICKEN 4.9.0 and 4.9.0.1 may allow remote attackers to execute arbitrary code via the 'select' function. | |
| Modificada | Alta (8.8) | 2.2% | — | Call-cc Chicken | 31/10/2019 | 16/6/2026 | Multiple buffer overflows in the (1) R5RS char-ready, (2) tcp-accept-ready, and (3) file-select procedures in Chicken through 4.8.0.3 allows attackers to cause a denial of service (crash) by opening a file descriptor with a large integer value. NOTE: this issue exists because of an incomplete fix for CVE-2012-6122. | |
| Modificada | Crítica (9.8) | 1.8% | — | Call-cc Chicken | 31/10/2019 | 16/6/2026 | Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions. | |
| Modificada | Media (5.3) | 1.3% | — | Call-cc Chicken | 31/10/2019 | 16/6/2026 | A casting error in Chicken before 4.8.0 on 64-bit platform caused the random number generator to return a constant value. NOTE: the vendor states "This function wasn't used for security purposes (and is advertised as being unsuitable)." | |
| Modificada | Media (6.5) | 1.3% | — | Call-cc ChickenDebian Linux | 31/10/2019 | 16/6/2026 | Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack." | |
| Modificada | Alta (7.5) | 2.3% | — | Call-cc Chicken | 31/10/2019 | 16/6/2026 | Buffer overflow in the thread scheduler in Chicken before 4.8.0.1 allows attackers to cause a denial of service (crash) by opening a file descriptor with a large integer value. | |
| Modificada | Alta (8.8) | 4.6% | — | Call-cc ChickenDebian Linux | 31/10/2019 | 16/6/2026 | OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4.9.0. | |
| Modificada | Alta (7.5) | 0.94% | — | Call-cc Chicken | 17/7/2017 | 17/6/2026 | Due to an incomplete fix for CVE-2012-6125, all versions of CHICKEN Scheme up to and including 4.12.0 are vulnerable to an algorithmic complexity attack. An attacker can provide crafted input which, when inserted into the symbol table, will result in O(n) lookup time. |