Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.1) | 0.80% | — | Craftycontrol Crafty Controller | 11/8/2026 | 18/8/2026 | Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution. | |
| Analizada | Crítica (9) | 0.51% | — | Craftycontrol Crafty Controller | 21/4/2026 | 17/6/2026 | An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actions via improper API permissions validation. | |
| Analizada | Alta (8.8) | 0.75% | — | Craftycontrol Crafty Controller | 30/1/2026 | 17/6/2026 | An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via path traversal. | |
| Analizada | Alta (8.8) | 0.66% | — | Craftycontrol Crafty Controller | 30/1/2026 | 17/6/2026 | An input neutralization vulnerability in the Backup Configuration component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via path traversal. | |
| Analizada | Crítica (9.9) | 6.6% | 💥 PoC | Craftycontrol Crafty Controller | 17/12/2025 | 17/6/2026 | An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remote code execution via Server Side Template Injection. | |
| Analizada | Alta (7.1) | 0.29% | — | Craftycontrol Crafty Controller | 17/12/2025 | 25/9/2026 | An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated attacker to perform stored XSS via server MOTD modification. | |
| Analizada | Media (5.4) | 0.26% | — | Craftycontrol Crafty Controller | 15/6/2025 | 17/6/2026 | An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a remote, authenticated attacker to perform stored XSS via malicious form input. | |
| Modificada | Alta (7.5) | 0.81% | — | Craftycontrol Crafty Controller | 3/2/2024 | 17/6/2026 | A host header injection vulnerability in the HTTP handler component of Crafty Controller allows a remote, unauthenticated attacker to trigger a Denial of Service (DoS) condition via a modified host header | |
| Modificada | Media (6.1) | 0.91% | — | Crafty Social Buttons Project Crafty Social Buttons | 22/8/2019 | 17/6/2026 | The crafty-social-buttons plugin before 1.5.8 for WordPress has XSS. | |
| Modificada | Media (5) | 1.3% | — | Craftysyntax Crafty Syntax | 23/9/2011 | 16/6/2026 | Crafty Syntax 3.0.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by README_FILES/livehelp.php and certain other files. | |
| Modificada | Alta (7.5) | 1.8% | 💥 Exploit | Craftysyntax Crafty Syntax Live Help | 27/8/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in Crafty Syntax Live Help (CSLH) 2.14.6 and earlier allow remote attackers to execute arbitrary SQL commands via the department parameter to (1) is_xmlhttp.php and (2) is_flush.php. | |
| Modificada | Media (5) | 1.2% | — | Craftysyntax Crafty Syntax Live Help | 27/8/2008 | 16/6/2026 | Crafty Syntax Live Help (CSLH) 2.14.6 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Crafty Syntax Live Help | 7/8/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in livehelp_js.php in Crafty Syntax Live Help (CSLH) 2.14.6 allows remote attackers to inject arbitrary web script or HTML via the department parameter. | |
| Modificada | Media (4.3) | 1.0% | — | Crafty Syntax Live Help | 6/3/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Crafty Syntax Live Help (CSLH) before 2.14.6 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) livehelp.php, (2) user_questions.php, and (3) leavemessage.php. NOTE: the lostsheep.php vector is covered by CVE-2008-0848. | |
| Modificada | Media (4.3) | 1.3% | — | Crafty Syntax Live Help | 21/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in lostsheep.php in Crafty Syntax Live Help (CSLH) before 2.14.16, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the versions claimed by the original researcher are probably incorrect. | |
| Modificada | Alta (9) | 4.2% | 💥 Exploit | Crafty Syntax Image Gallery | 7/4/2006 | 16/6/2026 | newimage.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows remote authenticated users to upload and execute arbitrary PHP code via a multipart/form-data POST with a .jpg filename in the fullimage parameter and the ext parameter set to .php. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Crafty Syntax Image Gallery | 7/4/2006 | 16/6/2026 | SQL injection vulnerability in slides.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows remote authenticated users to execute arbitrary SQL commands via the limitquery_s parameter when the $projectid variable is less than 1, which prevents the $limitquery_s… | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Crafty Syntax Live Help | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Crafty Syntax Live Help (CSLH) before 2.7.4 allows remote attackers to inject arbitrary web script or HTML via the name field of a livehelp or chat session. | |
| Modificada | Media (4.6) | 0.42% | — | Robert Hyatt Crafty | 29/3/2004 | 16/6/2026 | Multiple buffer overflows in main.c for Crafty 19.3 allow local users to gain group "games" privileges via long command line arguments to crafty.bin. |