Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3064▲ 561 respecto a la semana anterior
Críticas / altas1461▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

16 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.7)4.3%—Cloudcli Cloud CLI11/3/202617/6/2026
Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.25.0, OS Command Injection via WebSocket Shell. Both projectPath and initialCommand in server/index.js are taken directly from the WebSocket message payload and interpolated into a bash command…
AnalizadaAlta (8.8)0.57%—Cloudcli Cloud CLI11/3/202617/6/2026
Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.24.0, multiple Git-related API endpoints use execAsync() with string interpolation of user-controlled parameters (file, branch, message, commit), allowing authenticated attackers to execute…
AnalizadaAlta (8.7)0.68%—Cloudcli Cloud CLI11/3/202617/6/2026
Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.24.0, The /api/user/git-config endpoint constructs shell commands by interpolating user-supplied gitName and gitEmail values into command strings passed to child_process.exec(). The input is placed…
AplazadaAlta (7.8)0.17%—Revoworks Cloud ClientAI1/10/202417/6/2026
RevoWorks Cloud Client 3.0.91 and earlier contains an incorrect authorization vulnerability. If this vulnerability is exploited, unintended processes may be executed in the sandbox environment. Even if malware is executed in the sandbox environment, it does not compromise the client's local environment. However,…
ModificadaMedia (4.9)1.4%—Phoenixcontact Cloud Client 1101t-tx FirmwarePhoenixcontact TC Cloud Client 1002-4g ATT FirmwarePhoenixcontact TC Cloud Client 1002-4g FirmwarePhoenixcontact TC Cloud Client 1002-4g VZW Firmware+38/8/202317/6/2026
In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an authenticated remote attacker with admin privileges could upload a crafted XML file which causes a denial-of-service.
ModificadaCrítica (9.6)1.8%—Phoenixcontact Cloud Client 1101t-tx FirmwarePhoenixcontact TC Cloud Client 1002-4g ATT FirmwarePhoenixcontact TC Cloud Client 1002-4g FirmwarePhoenixcontact TC Cloud Client 1002-4g VZW Firmware+38/8/202317/6/2026
In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an unauthenticated remote attacker could use a reflective XSS within the license viewer page of the devices in order to execute code in the context of the user's browser.
AnalizadaMedia (4.4)0.52%—Owncloud Client13/2/202317/6/2026
The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Prior to version 3.0, the app has an incomplete fix for a path traversal issue and is vulnerable to two bypass methods. The bypasses may lead to information disclosure when uploading the app’s internal files, and to arbitrary…
ModificadaMedia (5.5)0.46%—Owncloud Client13/2/202317/6/2026
The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Version 2.21.1 of the ownCloud Android app is vulnerable to SQL injection in `FileContentProvider.kt`. This issue can lead to information disclosure. Two databases, `filelist` and `owncloud_database`, are affected. In version…
AnalizadaMedia (5.5)0.22%—Owncloud Client7/4/202217/6/2026
ownCloud owncloud/android 2.20 has Incorrect Access Control for local attackers.
AnalizadaMedia (6.8)0.24%—Owncloud Client7/4/202217/6/2026
ownCloud owncloud/android before 2.20 has Incorrect Access Control for physically proximate attackers.
ModificadaMedia (4.6)0.14%—Owncloud Client19/2/202117/6/2026
The ownCloud application before 2.15 for Android allows attackers to use adb to include a PIN preferences value in a backup archive, and consequently bypass the PIN lock feature by restoring from this archive.
ModificadaMedia (4.6)0.27%—Owncloud Client19/2/202117/6/2026
In the ownCloud application before 2.15 for Android, the lock protection mechanism can be bypassed by moving the system date/time into the past.
ModificadaAlta (8.8)2.6%—Phoenixcontact TC Router 3002t-4g FirmwarePhoenixcontact TC Router 2002t-3g FirmwarePhoenixcontact TC Router 3002t-4g VZW FirmwarePhoenixcontact TC Router 3002t-4g ATT Firmware+212/3/202017/6/2026
PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CLIENT 1002-TXTX through 1.03.17 devices allow authenticated users to inject system commands through…
ModificadaAlta (7.5)1.2%—Phoenixcontact TC Router 3002t-4g FirmwarePhoenixcontact TC Router 2002t-3g FirmwarePhoenixcontact TC Router 3002t-4g VZW FirmwarePhoenixcontact TC Router 3002t-4g ATT Firmware+212/3/202017/6/2026
PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CLIENT 1002-TXTX through 1.03.17 devices contain a hardcoded certificate (and key) that is used by…
ModificadaAlta (7.5)0.49%—IBM Cloud CLI12/2/202017/6/2026
IBM Cloud CLI 0.6.0 through 0.16.1 windows installers are signed using SHA1 certificate. An attacker might be able to exploit the weak algorithm to generate a installer with malicious software inside. IBM X-Force ID: 162773.
ModificadaMedia (5)1.1%—Owncloud Client29/10/201517/6/2026
ownCloud iOS app before 3.4.4 does not properly switch state between multiple instances, which might allow remote instance administrators to obtain sensitive credential and cookie information by reading authentication headers.