Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3070▲ 562 respecto a la semana anterior
Críticas / altas1457▲ 278 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.3) | 0.37% | — | ClaircoreAI | 11/8/2026 | 14/8/2026 | A flaw was found in claircore's RPM package scanner. Crafted RPM header data in a container layer can cause an unchecked type assertion to panic the scanner. The panic is not recovered, causing the Clair indexer process to crash, leading to a denial of service. | |
| Pendiente de análisis | Media (4.3) | 0.37% | — | ClaircoreAI | 20/7/2026 | 21/7/2026 | A flaw was found in claircore's apk package scanner. Malformed package-database data in a container layer can cause an out-of-bounds access that panics the scanner. If that panic is not recovered, the Clair indexer process can crash, leading to a denial of service. | |
| Rechazada | Sin puntuar | — | — | Quay ClaircoreAIRedhat ClairAI | 1/6/2026 | 27/7/2026 | Rejected reason: Retracted following review by Red Hat Product Security and confirmation from the upstream Clair/Claircore maintainer. This CVE misattributes the described behavior to github.com/quay/claircore: the authentication mechanism in question (optional PSK, HTTP endpoint /indexer/api/v1/index_report) is… | |
| Aplazada | Alta (7.1) | 0.29% | — | Claire Ryan Author ShowcaseAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Claire Ryan Author Showcase author-showcase allows Reflected XSS.This issue affects Author Showcase: from n/a through <= 1.4.3. | |
| Aplazada | Media (5.3) | 0.46% | — | Declaire RedirectsAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in mattdeclaire Redirects redirects allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Redirects: from n/a through <= 1.2.1. | |
| Aplazada | Alta (8.1) | 0.60% | — | LnbitsAIAcinq EclairAI | 14/6/2024 | 17/6/2026 | LNbits is a Lightning wallet and accounts system. Paying invoices in Eclair that do not get settled within the internal timeout (about 30s) lead to a payment being considered failed, even though it may still be in flight. This vulnerability can lead to a total loss of funds for the node backend. This vulnerability is… | |
| Modificada | Media (6.5) | 0.53% | — | Declaire Redirects | 28/2/2024 | 17/6/2026 | The Redirects plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save function in all versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to change redirects created with this plugin. This could lead to undesired… | |
| Modificada | Crítica (9.8) | 4.8% | — | Redhat ClairRedhat Quay | 3/3/2022 | 17/6/2026 | A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the filesystem, potentially allowing for remote code execution. | |
| Modificada | Crítica (9.4) | 1.7% | — | Acinq Eclair | 4/10/2021 | 17/6/2026 | ACINQ Eclair before 0.6.3 allows loss of funds because of dust HTLC exposure. | |
| Modificada | Alta (7.5) | 2.2% | — | Acinq Eclair | 31/1/2020 | 17/6/2026 | Eclair through 0.3 allows attackers to trigger loss of funds because of Incorrect Access Control. NOTE: README.md states "it is beta-quality software and don't put too much money in it." | |
| Modificada | Media (5) | 7.6% | — | Cedric Claire Portailphp | 7/2/2007 | 16/6/2026 | Multiple directory traversal vulnerabilities in Cedric CLAIRE PortailPhp 2 allow remote attackers to read arbitrary files via a .. (dot dot) in the chemin parameter to (1) mod_news/index.php or (2) mod_news/goodies.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third… | |
| Modificada | Alta (7.5) | 8.3% | — | Cedric Claire Portailphp | 7/2/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Cedric CLAIRE PortailPhp 2 allow remote attackers to execute arbitrary PHP code via a URL in the chemin parameter to (1) mod_news/index.php, (2) mod_news/goodies.php, or (3) mod_search/index.php. NOTE: The provenance of this information is unknown; the details are… |