Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 0.14% | — | Nicbarker ClayAI | 18/1/2026 | 17/6/2026 | A security flaw has been discovered in nicbarker clay up to 0.14. This affects the function Clay__MeasureTextCached in the library clay.h. The manipulation results in null pointer dereference. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The… | |
| Aplazada | Crítica (10) | 0.51% | — | Jclay06 Feed Comments NumberAI | 16/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in jclay06 Feed Comments Number feed-comments-number allows Upload a Web Shell to a Web Server.This issue affects Feed Comments Number: from n/a through <= 0.2.1. | |
| Modificada | Alta (7.5) | 77% | — | Nanopool Claymore Dual Miner | 9/2/2018 | 17/6/2026 | Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner API. The flaw can be exploited only if the software is executed with read/write mode enabled. | |
| Modificada | Crítica (9.1) | 44% | — | Claymore Dual Miner Project Claymore Dual Miner | 2/2/2018 | 17/6/2026 | The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format string vulnerability, allowing remote attackers to read memory or cause a denial of service. | |
| Modificada | Crítica (9.8) | 34% | — | Claymore Dual Miner Project Claymore Dual Miner | 5/12/2017 | 17/6/2026 | The remote management interface on the Claymore Dual GPU miner 10.1 allows an unauthenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the request handler. This can be exploited via a long API request that is mishandled during logging. | |
| Modificada | Alta (8.1) | 13% | — | Claymore Dual Miner Project Claymore Dual Miner | 5/12/2017 | 17/6/2026 | The remote management interface on the Claymore Dual GPU miner 10.1 is vulnerable to an authenticated directory traversal vulnerability exploited by issuing a specially crafted request, allowing a remote attacker to read/write arbitrary files. This can be exploited via ../ sequences in the pathname to miner_file or… | |
| Modificada | Alta (8.8) | 8.5% | — | Claydip Airbnb Clone | 26/9/2017 | 17/6/2026 | Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Laravel Airbnb Clone 1.0 allow remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/profile. | |
| Modificada | Media (5) | 0.55% | — | Claymore Systems INC Puretls | 31/12/2005 | 16/6/2026 | PureTLS before 0.9b5 does not clear optional Extensions and Algorithm.Parameters values before parsing, which might trigger an information leak of values from earlier certificates. | |
| Modificada | Alta (7.5) | 1.6% | — | Claymore Systems INC Puretls | 12/8/2002 | 16/6/2026 | Vulnerability in PureTLS before 0.9b2 related to injection attacks, which could possibly allow remote attackers to corrupt or hijack user sessions. |