Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3019▲ 545 respecto a la semana anterior
Críticas / altas1439▲ 265 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.6) | — | — | GratisfactionAI | 1/10/2026 | 1/10/2026 | Subscriber Broken Access Control in Gratisfaction <= 4.6.3 versions. | |
| Aplazada | Alta (8.7) | 0.37% | — | Owasp FactionAI | 26/5/2026 | 24/7/2026 | FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in assessment file preview flows. User-supplied filename values are persisted and later rendered into HTML/attribute contexts without output… | |
| Aplazada | Crítica (9.8) | 0.66% | — | Apache Struts2AIOwasp FactionAI | 26/5/2026 | 20/7/2026 | FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, AccessControlInterceptor, the authentication gate for all Struts2 actions, unconditionally calls invocation.invoke() without checking for a valid session. Four action methods in BoilerPlateConfig perform no local session check… | |
| Aplazada | Alta (8.7) | 0.37% | — | Owasp FactionAI | 26/5/2026 | 24/7/2026 | FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in remediation verification file preview flows. User-supplied filename values are persisted and then rendered into HTML and attribute contexts… | |
| Analizada | Crítica (9.8) | 0.68% | — | Owasp Faction | 26/11/2025 | 17/6/2026 | FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to version 1.7.1, an extension execution path in Faction’s extension framework permits untrusted extension code to execute arbitrary system commands on the server when a lifecycle hook is invoked, resulting in remote code execution (RCE) on… | |
| Aplazada | Alta (7.5) | 0.43% | — | Owasp FactionAI | 3/3/2025 | 17/6/2026 | FACTION is a PenTesting Report Generation and Collaboration Framework. Authentication is bypassed when an attacker registers a new user with admin privileges. This is possible at any time without any authorization. The request must follow the validation rules (no missing information, secure password, etc) but there… | |
| Aplazada | Media (6.5) | 0.35% | — | Appsmav GratisfactionAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Appsmav Gratisfaction allows Stored XSS.This issue affects Gratisfaction: from n/a through 4.3.4. | |
| Modificada | Media (5.4) | 0.27% | — | Creatingahaven Compassion Satisfaction | 19/10/2014 | 17/6/2026 | The Compassion Satisfaction (aka com.wCompassionSatisfactionWorkshopPresentation) application 0.75.13440.35155 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (10) | 6.0% | — | Volition RED Faction | 23/11/2004 | 16/6/2026 | Buffer overflow in Red Faction client 1.20 and earlier allows remote servers to execute arbitrary code via a long server name. | |
| Modificada | Media (5) | 3.2% | — | Volition RED Faction | 7/12/2001 | 16/6/2026 | THQ Volition Red Faction Game allows remote attackers to cause a denial of service (hang) of a client or server via packets to UDP port 7755. |