Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.32% | — | Follet School Solutions DestinyAI | 28/5/2026 | 17/6/2026 | Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a remote attacker to run arbitrary client-side code via the site parameter of handleloginform.do. | |
| Aplazada | Media (5.1) | 0.32% | — | Follet School Solutions DestinyAI | 28/5/2026 | 17/6/2026 | Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a remote attacker to run arbitrary client-side code via the showSupportExpiredMessage parameter of handleloginform.do. | |
| Pendiente de análisis | Alta (7.5) | 0.71% | — | Follett Software Destiny Library ManagerAI | 22/5/2026 | 23/7/2026 | Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 allows remote attackers to read arbitrary system and application files via the image parameter | |
| Aplazada | Alta (7.7) | 0.20% | — | Cyberdigm DestinyecmAI | 7/4/2025 | 17/6/2026 | Permissive Cross-domain Policy with Untrusted Domains vulnerability in local API server of DestinyECM solution(versions described below) which is developed and maintained by Cyberdigm may allow Cross-Site Request Forgery (CSRF) attack, which probabilistically enables JSON Hijacking (aka JavaScript Hijacking) via… | |
| Aplazada | Media (5.1) | 0.54% | — | Follet School Solutions DestinyAI | 8/10/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a remote attacker to run arbitrary client-side code via the expiredSupportMessage parameter of handleloginform.do. | |
| Modificada | Media (6.1) | 0.43% | — | Follettlearning Solutions Destiny | 9/1/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Follet School Solutions Destiny v.20_0_1_AU4 and later allows a remote attacker to run arbitrary code via presentonesearchresultsform.do. | |
| Modificada | Media (6.1) | 0.39% | — | Follettlearning Solutions Destiny | 25/12/2023 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerability exists in Follet Learning Solutions Destiny through 20.0_1U. via the handlewpesearchform.do. searchString. | |
| Modificada | Alta (8.8) | 0.36% | — | Destiny Chat | 22/12/2022 | 17/6/2026 | A vulnerability was found in destiny.gg chat. It has been rated as problematic. This issue affects the function websocket.Upgrader of the file main.go. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The name of the patch is bebd256fc3063111fb4503ca25e005ebf6e73780. It is… | |
| Modificada | Alta (9.3) | 35% | — | Pirateradio Destiny Media Player | 25/9/2009 | 16/6/2026 | Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code via a long string in a .pls playlist file. |