Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2750▲ 27 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
30 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.8) | 0.10% | — | CrunAILibkrunAI | 10/9/2026 | 15/9/2026 | A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.use_passt), crun can execute attacker-controlled payload from the container image with host root privileges. The issue is a regression in crun 1.29. It affects crun >= 1.29 | |
| Pendiente de análisis | Media (5.6) | 0.12% | — | CrunAI | 10/9/2026 | 2/10/2026 | A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio, then change that file's ownership. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet. | |
| Pendiente de análisis | Media (5.6) | 0.12% | — | CrunAI | 10/9/2026 | 25/9/2026 | A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redirect /dev/console onto an attacker-controlled path, including via the read-only-rootfs bind-mount fallback. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh… | |
| Aplazada | Media (5.1) | 0.20% | — | CrunAI | 14/8/2026 | 18/9/2026 | crun is an open source OCI Container Runtime fully written in C. Prior to version 1.28, crun's default device setup opens the container rootfs `/dev` directory without `O_NOFOLLOW`. If an OCI bundle contains `rootfs/dev` as a symlink and the bundle configuration does not mount `/dev`, crun follows that symlink and… | |
| Analizada | Alta (8.5) | 0.31% | — | Crun Realterm | 5/4/2026 | 24/7/2026 | RealTerm Serial Terminal 2.0.0.70 contains a structured exception handling (SEH) buffer overflow vulnerability in the Echo Port tab that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a buffer overflow payload with a POP POP RET gadget chain and shellcode that… | |
| Analizada | Alta (7.8) | 0.17% | — | Crun Project Crun | 26/3/2026 | 17/6/2026 | crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the `crun exec` option `-u` (`--user`) is incorrectly parsed. The value `1` is interpreted as UID 0 and GID 0 when it should have been UID 1 and GID 0. The process thus runs with higher privileges than expected. Version… | |
| Analizada | Media (6.8) | 0.22% | — | Crun Realterm | 21/3/2026 | 17/6/2026 | RealTerm Serial Terminal 2.0.0.70 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Port field. Attackers can paste a buffer of 1000 characters into the Port input field and click the open button to trigger a crash. | |
| Analizada | Media (6.9) | 0.19% | — | Crun Realterm | 21/3/2026 | 17/6/2026 | RealTerm Serial Terminal 2.0.0.70 contains a stack-based buffer overflow vulnerability in the Echo Port field that allows local attackers to crash the application by triggering a structured exception handler (SEH) chain corruption. Attackers can craft a malicious input string with 268 bytes of padding followed by SEH… | |
| Analizada | Crítica (9.8) | 2.2% | — | Spicethemes Newscrunch | 4/3/2025 | 17/6/2026 | The Newscrunch theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check in the newscrunch_install_and_activate_plugin() function in all versions up to, and including, 1.8.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload… | |
| Analizada | Alta (8.8) | 0.53% | — | Spicethemes Newscrunch | 4/3/2025 | 17/6/2026 | The Newscrunch theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.4. This is due to missing or incorrect nonce validation on the newscrunch_install_and_activate_plugin() function. This makes it possible for unauthenticated attackers to upload arbitrary files via a… | |
| Aplazada | Alta (8.5) | 0.58% | — | CrunAI | 19/2/2025 | 17/6/2026 | crun is an open source OCI Container Runtime fully written in C. In affected versions A malicious container image could trick the krun handler into escaping the root filesystem, allowing file creation or modification on the host. No special permissions are needed, only the ability for the current user to write to the… | |
| Analizada | Media (6.5) | 0.53% | — | Authcrunch Caddy-security | 17/2/2024 | 17/6/2026 | All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Restriction of Excessive Authentication Attempts via the two-factor authentication (2FA). Although the application blocks the user after several failed attempts to provide 2FA codes, attackers can bypass this blocking mechanism… | |
| Analizada | Media (5.3) | 0.55% | — | Authcrunch Caddy-security | 17/2/2024 | 17/6/2026 | All versions of the package github.com/greenpau/caddy-security are vulnerable to Server-side Request Forgery (SSRF) via X-Forwarded-Host header manipulation. An attacker can expose sensitive information, interact with internal services, or exploit other vulnerabilities within the network by exploiting this… | |
| Analizada | Media (6.1) | 0.58% | — | Authcrunch Caddy-security | 17/2/2024 | 17/6/2026 | All versions of the package github.com/greenpau/caddy-security are vulnerable to Cross-site Scripting (XSS) via the Referer header, due to improper input sanitization. Although the Referer header is sanitized by escaping some characters that can allow XSS (e.g., [&], [<], [>], ["], [']), it does not account for the… | |
| Analizada | Alta (8.1) | 0.71% | — | Authcrunch Caddy-security | 17/2/2024 | 17/6/2026 | All versions of the package github.com/greenpau/caddy-security are vulnerable to Insufficient Session Expiration due to improper user session invalidation upon clicking the "Sign Out" button. User sessions remain valid even after requests are sent to /logout and /oauth2/google/logout. Attackers who gain access to an… | |
| Modificada | Media (6.1) | 0.37% | — | Authcrunch Caddy-security | 12/2/2024 | 17/6/2026 | The caddy-security plugin 1.1.20 for Caddy allows reflected XSS via a GET request to a URL that contains an XSS payload and begins with either a /admin or /settings/mfa/delete/ substring. | |
| Modificada | Alta (7.5) | 1.3% | — | Crun Project CrunFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux | 4/4/2022 | 17/6/2026 | A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable… | |
| Modificada | Media (5.4) | 0.44% | — | Adremsoft Netcrunch | 16/12/2020 | 17/6/2026 | AdRem NetCrunch 10.6.0.4587 has a Cross-Site Request Forgery (CSRF) vulnerability in the NetCrunch web client. Successful exploitation requires a logged-in user to open a malicious page and leads to account takeover. | |
| Modificada | Alta (8.8) | 4.2% | — | Adremsoft Netcrunch | 16/12/2020 | 17/6/2026 | AdRem NetCrunch 10.6.0.4587 allows Remote Code Execution. In the NetCrunch web client, a read-only administrator can execute arbitrary code on the server running the NetCrunch server software. | |
| Modificada | Media (5.4) | 0.58% | — | Adremsoft Netcrunch | 16/12/2020 | 17/6/2026 | AdRem NetCrunch 10.6.0.4587 has a stored Cross-Site Scripting (XSS) vulnerability in the NetCrunch web client. The user's input data is not properly encoded when being echoed back to the user. This data can be interpreted as executable code by the browser and allows an attacker to execute JavaScript code in the… | |
| Modificada | Media (6.5) | 0.84% | — | Adremsoft Netcrunch | 16/12/2020 | 17/6/2026 | AdRem NetCrunch 10.6.0.4587 has a Server-Side Request Forgery (SSRF) vulnerability in the NetCrunch server. Every user can trick the server into performing SMB requests to other systems. | |
| Modificada | Alta (8.8) | 1.8% | — | Adremsoft Netcrunch | 16/12/2020 | 17/6/2026 | AdRem NetCrunch 10.6.0.4587 allows Credentials Disclosure. Every user can read the BSD, Linux, MacOS and Solaris private keys, private keys' passwords, and root passwords stored in the credential manager. Every administrator can read the ESX and Windows passwords stored in the credential manager. | |
| Modificada | Crítica (9.8) | 1.8% | — | Adremsoft Netcrunch | 16/12/2020 | 17/6/2026 | AdRem NetCrunch 10.6.0.4587 has a hardcoded SSL private key vulnerability in the NetCrunch web client. The same hardcoded SSL private key is used across different customers' installations when no other SSL certificate is installed, which allows remote attackers to defeat cryptographic protection mechanisms by… | |
| Modificada | Crítica (9.8) | 1.1% | — | Adremsoft Netcrunch | 16/12/2020 | 17/6/2026 | AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication bypass or escalation of privileges. | |
| Modificada | Media (5.5) | 0.28% | — | Adremsoft Netcrunch | 16/12/2020 | 17/6/2026 | AdRem NetCrunch 10.6.0.4587 has Improper Credential Storage since the internal user database is readable by low-privileged users and passwords in the database are weakly encoded or encrypted. |