Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2532▼ 361 respecto a la semana anterior
Críticas / altas1338▲ 69 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.48% | — | Nasa Earthdata-searchAI | 31/8/2026 | 1/9/2026 | A flaw has been found in NASA earthdata-search 1.0.0. Affected by this issue is the function OpenSearchGranuleSearchLambda of the file serverless/src/openSearchGranuleSearch/handler.js of the component granules Endpoint. Executing a manipulation of the argument openSearchOsdd can lead to server-side request forgery.… | |
| Aplazada | Media (5.5) | 0.47% | — | Nasa Earthdata-searchAI | 31/8/2026 | 1/9/2026 | A vulnerability was detected in NASA earthdata-search 1.0.0. Affected by this vulnerability is the function scaleImage of the file serverless/src/scaleImage/handler.js of the component scale Endpoint. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit is… | |
| Aplazada | Alta (7.2) | 0.59% | — | Frostming UnearthAI | 10/8/2026 | 24/9/2026 | unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers can supply malicious tar archives with symlink members or traversal… | |
| Aplazada | Alta (8.7) | 0.47% | — | GX Earth 2022 ONTAI | 4/6/2026 | 22/7/2026 | This vulnerability exists in GX Earth 2022 ONT models due to the presence of hardcoded RSA private key within the device firmware. A remote attacker could exploit this vulnerability by extracting the cryptographic private key from the firmware, which could lead to decryption of HTTPS traffic and Man-in-the-Middle… | |
| Aplazada | Alta (8.7) | 0.41% | — | GX Earth ONTAI | 4/6/2026 | 22/7/2026 | This vulnerability exists in GX Earth ONT models due to the transmission of user credentials in plaintext over HTTP in its web management interface. A remote attacker could exploit this vulnerability by intercepting network traffic to obtain sensitive authentication information, which could lead to unauthorized access… | |
| Aplazada | Alta (8.7) | 0.62% | — | GX Earth ONTAI | 4/6/2026 | 22/7/2026 | This vulnerability exists in GX Earth ONT models due to improper handling of user-supplied input in multiple diagnostic functions in its web management interface. An authenticated remote attacker could exploit this vulnerability by injecting arbitrary and executing OS commands on the targeted device. Successful… | |
| Aplazada | Media (6.5) | 0.28% | — | Andrew Norcross Google Earth EmbedAI | 7/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andrew Norcross Google Earth Embed google-earth-tours allows Stored XSS.This issue affects Google Earth Embed: from n/a through <= 1.0. | |
| Aplazada | Media (6.5) | 0.21% | — | Codegearthemes DesignerAI | 31/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codegearthemes Designer designer allows DOM-Based XSS.This issue affects Designer: from n/a through <= 1.6.4. | |
| Aplazada | Alta (7.5) | 0.79% | — | Codegearthemes DesignerAI | 9/12/2024 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in codegearthemes Designer designer allows PHP Local File Inclusion.This issue affects Designer: from n/a through <= 1.4.1. | |
| Aplazada | Media (6.5) | 0.39% | — | Meini Utech Utech Spinning EarthAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Meini Utech Spinning Earth utech-spinning-earth allows DOM-Based XSS.This issue affects Utech Spinning Earth: from n/a through <= 1.2. | |
| Modificada | Alta (7.8) | 0.51% | — | Frostming PDMFrostming Unearth | 20/10/2023 | 17/6/2026 | pdm is a Python package and dependency manager supporting the latest PEP standards. It's possible to craft a malicious `pdm.lock` file that could allow e.g. an insider or a malicious open source project to appear to depend on a trusted PyPI project, but actually install another project. A project `foo` can be targeted… | |
| Modificada | Media (6.1) | 0.41% | — | Bearthemes Sermon'e - Sermons Online | 27/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Beplus Sermon'e – Sermons Online plugin <= 1.0.0 versions. | |
| Modificada | Media (6.5) | 0.45% | — | Earthgarden Waiting Project Earthgarden Waiting | 20/9/2023 | 17/6/2026 | An information leak in Earthgarden_waiting 13.6.1 allows attackers to obtain the channel access token and send crafted messages. | |
| Modificada | Alta (7.8) | 1.1% | — | Esri Arcgis Earth | 5/5/2021 | 17/6/2026 | A path traversal vulnerability exists in Esri ArcGIS Earth versions 1.11.0 and below which allows arbitrary file creation on an affected system through crafted input. An attacker could exploit this vulnerability to gain arbitrary code execution under security context of the user running ArcGIS Earth by inducing the… | |
| Modificada | Media (5.9) | 0.40% | — | Google Earth | 4/5/2020 | 17/6/2026 | A Buffer Overflow vulnerability in the khcrypt implementation in Google Earth Pro versions up to and including 7.3.2 allows an attacker to perform a Man-in-the-Middle attack using a specially crafted key to read data past the end of the buffer used to hold it. Mitigation: Update to Google Earth Pro 7.3.3. | |
| Modificada | Alta (7.8) | 0.19% | — | Google Earth | 21/4/2020 | 17/6/2026 | Untrusted Search Path vulnerability in the windows installer of Google Earth Pro versions prior to 7.3.3 allows an attacker to insert malicious local files to execute unauthenticated remote code on the targeted system. | |
| Modificada | Alta (9.3) | 3.8% | — | Google Earth | 26/8/2010 | 16/6/2026 | Untrusted search path vulnerability in Google Earth 5.1.3535.3218 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse quserex.dll that is located in the same folder as a .kmz file. | |
| Modificada | Alta (7.5) | 4.3% | — | Newearthpt Imgupload | 4/6/2009 | 16/6/2026 | Unrestricted file upload vulnerability in uploadp.php in New Earth Programming Team (NEPT) imgupload (aka Image Uploader) 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension and a modified content type, then accessing this file via a direct request, as demonstrated by… | |
| Modificada | Alta (7.1) | 7.5% | — | Google Earth | 7/3/2007 | 16/6/2026 | Buffer overflow in Google Earth v4.0.2091 (beta) allows remote user-assisted attackers to cause a denial of service (crash) via a KML or KMZ file with a long href element. | |
| Modificada | Media (6.8) | 1.2% | — | Earthlink Total Access | 31/1/2007 | 16/6/2026 | The SpamBlocker.dll ActiveX control in Earthlink TotalAccess is marked "safe for scripting," which allows remote attackers to add arbitrary e-mail addresses and domains to the spam blocker whitelist via the (1) AddSenderToWhitelist and (2) AddDomainToWhitelist functions. | |
| Modificada | Alta (7.8) | 3.7% | — | Trend Micro Serverprotect Earthagent | 14/12/2005 | 16/6/2026 | Trend Micro ServerProtect EarthAgent for Windows Management Console 5.58 and possibly earlier versions, when running with Trend Micro Control Manager 2.5 and 3.0, and Damage Cleanup Server 1.1, allows remote attackers to cause a denial of service (CPU consumption) via a flood of crafted packets with a certain "magic… |