Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 6 respecto a la semana anterior
Críticas / altas1451▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

13 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.6)0.50%—Ninjateam FastdupAI15/6/202617/6/2026
Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.
AplazadaMedia (5.5)0.41%—Perfree Go-fastdfs-webAI6/6/202623/7/2026
A flaw has been found in perfree go-fastdfs-web up to 1.3.7. Affected is the function checkServer of the file /install/checkServer of the component Installation Endpoint. Executing a manipulation can lead to server-side request forgery. The attack can be executed remotely. The exploit has been published and may be…
AplazadaBaja (2)0.07%—Paddlepaddle FastdeployAI4/6/202622/7/2026
A weakness has been identified in PaddlePaddle FastDeploy up to 2.4.1. Affected by this issue is the function hash_features of the file fastdeploy/multimodal/hasher.py of the component MultimodalHasher. Executing a manipulation can lead to use of weak hash. The attack requires local access. A high complexity level is…
AplazadaMedia (5.5)0.51%—Perfree Go-fastdfs-webAI11/4/202617/6/2026
A security vulnerability has been detected in perfree go-fastdfs-web up to 1.3.7. This affects an unknown part of the file src/main/java/com/perfree/controller/InstallController.java of the component doInstall Interface. The manipulation leads to improper authorization. The attack may be initiated remotely. The…
AplazadaBaja (2.9)0.46%—Perfree Go-fastdfs-webAIApache ShiroAI11/3/202617/6/2026
A security flaw has been discovered in perfree go-fastdfs-web up to 1.3.7. This affects the function rememberMeManager of the file src/main/java/com/perfree/config/ShiroConfig.java of the component Apache Shiro RememberMe. Performing a manipulation results in use of hard-coded cryptographic key . The attack can be…
AplazadaAlta (8.8)0.28%—Ninjateam FastdupAI12/2/202617/6/2026
The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to unauthorized backup creation and download due to a missing capability check on REST API endpoints in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with Contributor-level access…
AplazadaMedia (6.5)0.38%—Ninjateam FastdupAI6/1/202617/6/2026
The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.7 via the 'dir_path' parameter in the 'njt-fastdup/v1/template/directory-tree' REST API endpoint. This makes it possible for authenticated attackers, with…
AnalizadaMedia (6.9)0.68%—Fastd Project Fastd27/1/202517/6/2026
fastd is a VPN daemon which tunnels IP packets and Ethernet frames over UDP. When receiving a data packet from an unknown IP address/port combination, fastd will assume that one of its connected peers has moved to a new address and initiate a reconnect by sending a handshake packet. This "fast reconnect" avoids having…
AplazadaAlta (7.5)0.62%—Eprosima FastddsAI19/3/202417/6/2026
An issue in the HistoryQosPolicy component of FastDDS v2.12.x, v2.11.x, v2.10.x, and v2.6.x leads to a SIGABRT (signal abort) upon receiving DataWriter's data.
ModificadaMedia (5.3)0.91%—Ninjateam Fastdup16/1/202417/6/2026
The FastDup WordPress plugin before 2.2 does not prevent directory listing in sensitive directories containing export files.
ModificadaAlta (7.5)0.48%—Ninjateam Fastdup8/1/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team FastDup – Fastest WordPress Migration & Duplicator.This issue affects FastDup – Fastest WordPress Migration & Duplicator: from n/a through 2.1.7.
ModificadaCrítica (9.8)3.6%—Go-fastdfs Project Go-fastdfs2/4/202317/6/2026
A vulnerability, which was classified as critical, has been found in sjqzhang go-fastdfs up to 1.4.3. Affected by this issue is the function upload of the file /group1/uploa of the component File Upload Handler. The manipulation leads to path traversal: '../filedir'. The attack may be launched remotely. The exploit…
ModificadaAlta (7.5)2.4%—Fastd Project FastdDebian LinuxFedoraproject Fedora22/10/202017/6/2026
receive.c in fastd before v21 allows denial of service (assertion failure) when receiving packets with an invalid type code.