Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.47% | — | Super-diamond-serverAI | 26/8/2026 | 31/8/2026 | The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. The module parameter is directly concatenated into the SQL IN clause through StringUtils.split() and string concatenation without being parameterized and bound. | |
| Aplazada | Crítica (9.8) | 0.61% | — | Super-diamond-serverAI | 26/8/2026 | 31/8/2026 | The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project (including database passwords, API keys, etc.) by sending a TCP request without any credential. | |
| Aplazada | Alta (7.1) | 0.19% | — | Bit.diamonds DiamondAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GT3themes Diamond diamond allows Reflected XSS.This issue affects Diamond: from n/a through <= 2.4.8. | |
| Analizada | Media (6.1) | 0.21% | — | IBM Storage Ts4500 Library FirmwareIBM Diamondback Tape Library Firmware | 27/9/2025 | 17/6/2026 | IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Alta (8.8) | 0.17% | — | IBM Storage Ts4500 Library FirmwareIBM Diamondback Tape Library Firmware | 27/9/2025 | 17/6/2026 | IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. | |
| Analizada | Media (5.4) | 0.18% | — | IBM Storage Ts4500 Library FirmwareIBM Diamondback Tape Library Firmware | 15/8/2025 | 17/6/2026 | IBM TS4500 1.11.0.0-D00, 1.11.0.1-C00, 1.11.0.2-C00, and 1.10.00-F00 web GUI is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted… | |
| Modificada | Crítica (9.3) | 1.5% | — | CMU Opendiamond | 11/7/2022 | 17/6/2026 | The cmusatyalab/opendiamond repository through 10.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Alta (7.5) | 1.3% | — | Bit.diamonds Diamond | 5/11/2019 | 17/6/2026 | Diamond through 3.0.1.2 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by an attacker who acquires even a small amount of stake/coins in the system. The attacker sends invalid headers/blocks, which are stored on the victim's disk. | |
| Modificada | Media (5.4) | 0.27% | — | Playscape Jewels & Diamonds | 9/9/2014 | 17/6/2026 | The Jewels & Diamonds (aka mominis.Generic_Android.Jewels_and_Diamonds) application 1.1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.8) | 4.1% | — | Lattice Semiconductor Lattice Diamond Programmer | 12/7/2012 | 16/6/2026 | Buffer overflow in programmer.exe in Lattice Diamond Programmer 1.4.2 allows user-assisted remote attackers to cause a denial of service (application crash) and execute arbitrary code via a long string in a version attribute of an ispXCF element in an .xcf file. | |
| Modificada | Baja (3.6) | 0.31% | — | Artsoft Rocks'n'diamonds | 15/12/2011 | 16/6/2026 | Artsoft Entertainment Rocks'n'Diamonds (aka rocksndiamonds) 3.3.0.1 allows local users to overwrite arbitrary files via a symlink attack on .rocksndiamonds/cache/artworkinfo.cache under a user's home directory. | |
| Modificada | Media (6.8) | 1.4% | — | Hulihanapplications Diamondlist | 16/8/2010 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in user/main/update_user in DiamondList 0.1.6, and possibly earlier, allow remote attackers to hijack the authentication of administrators for requests that (1) change the administrative password or (2) change the site's configuration. | |
| Modificada | Media (4.3) | 2.6% | — | Hulihanapplications Diamondlist | 16/8/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in DiamondList 0.1.6, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) category[description] parameter to user/main/update_category, which is not properly handled by _app/views/categories/index.html.erb; and the (2)… | |
| Modificada | Media (4.4) | 0.28% | — | Diamondcs Processguard | 19/9/2007 | 16/6/2026 | ProcessGuard 3.410 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via kernel SSDT hooks for Windows Native API functions including (1) NtCreateFile, (2) NtCreateKey,… | |
| Modificada | Baja (2.1) | 0.44% | — | Diamondcs Process Guard Free | 31/12/2004 | 16/6/2026 | DiamondCS Process Guard Free 2.000 allows local users to disable the process guard protection system by overwriting the current Service Descriptor Table (SDT) in \device\physicalmemory with the original SDT found in ntoskrnl.exe. | |
| Modificada | Alta (7.5) | 1.9% | — | Logicode QuicktelDiamond SupraUS Robotics | 27/9/1998 | 16/6/2026 | Various modems that do not implement a guard time, or are configured with a guard time of 0, can allow remote attackers to execute arbitrary modem commands such as ATH, ATH0, etc., via a "+++" sequence that appears in ICMP packets, the subject of an e-mail message, IRC commands, and others. |