Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3072▲ 552 respecto a la semana anterior
Críticas / altas1458▲ 273 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
103 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.43% | — | EchoAI | 26/6/2026 | 26/6/2026 | Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass… | |
| Pendiente de análisis | Baja (2.3) | 0.38% | — | Wikimedia EchoAI | 11/5/2026 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Echo. This vulnerability is associated with program files includes/Api/ApiEchoNotifications.Php. This issue affects Echo: from * before 1.43.7, 1.44.4, 1.45.2. | |
| Aplazada | Media (5.5) | 0.47% | — | TypechoAI | 26/4/2026 | 17/6/2026 | A vulnerability was found in Typecho up to 1.3.0. This vulnerability affects the function Service::sendPingHandle of the file var/Widget/Service.php of the component Ping Back Service Endpoint. The manipulation of the argument X-Pingback/link results in server-side request forgery. The attack may be launched remotely.… | |
| Analizada | Alta (8.6) | 0.21% | — | Interference-security Echo Mirage | 12/4/2026 | 17/6/2026 | Echo Mirage 3.1 contains a stack buffer overflow vulnerability that allows local attackers to crash the application or execute arbitrary code by supplying an oversized string in the Rules action field. Attackers can create a malicious text file with a crafted payload exceeding buffer boundaries and paste it into the… | |
| Aplazada | Media (5.3) | 0.32% | — | Kutethemes TechoneAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in kutethemes TechOne techone allows Code Injection.This issue affects TechOne: from n/a through <= 3.0.3. | |
| Aplazada | Media (6.4) | 0.14% | — | No-chicken Echo-mateAI | 24/3/2026 | 17/6/2026 | Use After Free vulnerability in No-Chicken Echo-Mate.This issue affects Echo-Mate: before V250329. | |
| Aplazada | Alta (7.3) | 0.12% | — | No-chicken Echo-mateAI | 24/3/2026 | 17/6/2026 | Use After Free vulnerability in No-Chicken Echo-Mate (SDK/rv1106-sdk/sysdrv/source/kernel/mm modules). This vulnerability is associated with program files rmap.C. This issue affects Echo-Mate: before V250329. | |
| Aplazada | Alta (7.3) | 0.12% | — | No-chicken Echo-mateAI | 24/3/2026 | 17/6/2026 | Improper Handling of Values vulnerability in No-Chicken Echo-Mate (SDK/rv1106-sdk/sysdrv/source/kernel/include/net/netfilter modules). This vulnerability is associated with program files nf_tables.H, nft_byteorder.C, nft_meta.C. This issue affects Echo-Mate: before V250329. | |
| Analizada | Media (5.3) | 0.45% | — | Labstack Echo | 19/2/2026 | 17/6/2026 | Echo is a Go web framework. In versions 5.0.0 through 5.0.2 on Windows, Echo’s `middleware.Static` using the default filesystem allows path traversal via backslashes, enabling unauthenticated remote file read outside the static root. In `middleware/static.go`, the requested path is unescaped and normalized with… | |
| Aplazada | Media (4.3) | 0.19% | — | Echoplugins Knowledge Base FOR Documentation Faqs With AI AssistanceAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in echoplugins Knowledge Base for Documentation, FAQs with AI Assistance echo-knowledge-base allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Knowledge Base for Documentation, FAQs with AI Assistance: from n/a through <= 16.011.0. | |
| Aplazada | Alta (8.8) | 0.34% | — | Echo Call Center Services Trade AND Industry INC Specto CMAI | 24/12/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Echo Call Center Services Trade and Industry Inc. Specto CM allows Remote Code Inclusion. This issue affects Specto CM: before 17032025. | |
| Aplazada | Media (5.4) | 0.17% | — | Echo Call Center Services Trade AND Industry INC Specto CMAI | 24/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Echo Call Center Services Trade and Industry Inc. Specto CM allows Stored XSS. This issue affects Specto CM: before 17032025. | |
| Aplazada | Alta (8.1) | 0.53% | — | Ancorathemes EchoAI | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Echo echo allows PHP Local File Inclusion.This issue affects Echo: from n/a through <= 1.15.0. | |
| Modificada | Alta (7.5) | 0.35% | — | Interviewx Echo | 25/11/2025 | 5/7/2026 | An issue was discovered in Veal98 Echo Open-Source Community System 2.2 thru 2.3 allowing an unauthenticated attacker to cause the server to send email verification messages to arbitrary users via the /sendEmailCodeForResetPwd endpoint potentially causing a denial of service to the server or the downstream users. | |
| Aplazada | Alta (7.1) | 0.33% | — | Coderevolution Echo RSS Feed Post GeneratorAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeRevolution Echo RSS Feed Post Generator Plugin for WordPress rss-feed-post-generator-echo allows Reflected XSS.This issue affects Echo RSS Feed Post Generator Plugin for WordPress: from n/a through <= 5.4.8.1. | |
| Aplazada | Crítica (9.8) | 0.74% | — | Coderevolution Echo RSS Feed Post GeneratorAI | 17/5/2025 | 17/6/2026 | The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the echo_generate_featured_image() function in all versions up to, and including, 5.4.8.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected… | |
| Aplazada | Media (5.3) | 0.33% | — | Veal98 Xiaoniurou EchoAI | 14/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in veal98 小牛肉 Echo 开源社区系统 4.2. Affected is the function preHandle of the file src/main/java/com/greate/community/controller/interceptor/LoginTicketInterceptor.java of the component Ticket Handler. The manipulation leads to improper authorization. It is… | |
| Aplazada | Media (6.9) | 0.44% | — | Veal98 Xiaoniurou EchoAI | 14/4/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in veal98 小牛肉 Echo 开源社区系统 4.2. This issue affects the function uploadMdPic of the file /discuss/uploadMdPic. The manipulation of the argument editormd-image-file leads to unrestricted upload. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (5.4) | 0.26% | — | Typecho | 7/4/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Typecho v1.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into Name parameter under a comment for an Article. | |
| Analizada | Media (6.4) | 0.35% | — | Typecho | 17/1/2025 | 17/6/2026 | Clickjacking vulnerability in typecho v1.2.1. | |
| Aplazada | Media (6.5) | 0.40% | — | Think201 EchozaAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Think201 Echoza echoza allows Stored XSS.This issue affects Echoza: from n/a through <= 0.1.1. | |
| Analizada | Alta (8.7) | 0.55% | — | Rockwellautomation Controllogix 5580 FirmwareRockwellautomation Controllogix 5580 Process FirmwareRockwellautomation Guardlogix 5580 FirmwareRockwellautomation Compactlogix 5380 Firmware+4 | 14/10/2024 | 17/6/2026 | CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and send a specially crafted CIP message to the device. If exploited, a threat actor could help prevent access to the legitimate user and end connections to connected devices including the workstation. To… | |
| Analizada | Crítica (9.8) | 0.62% | — | Coderevolution Echo RSS Feed Post Generator | 1/10/2024 | 17/6/2026 | The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.4.6. This is due to the plugin not properly restricting the roles that can set during registration through the echo_check_post_header_sent() function. This makes it possible for… | |
| Analizada | Crítica (9.8) | 0.79% | — | Endress Echo Curve ViewerEndress Fieldcare Sfe500 PackageEndress Field Xpert Smt79 FirmwareEndress Field Xpert Smt77 Firmware+2 | 10/9/2024 | 17/6/2026 | An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context. | |
| Analizada | Alta (7.1) | 0.30% | — | Echostar Fusion | 5/9/2024 | 17/6/2026 | Credentials to access device configuration were transmitted using an unencrypted protocol. These credentials would allow read-only access to network configuration information and terminal configuration data. |