Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 6 respecto a la semana anterior
Críticas / altas1451▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.6) | 0.50% | — | Ninjateam FastdupAI | 15/6/2026 | 17/6/2026 | Unauthenticated Path Traversal in FastDup <= 2.7.2 versions. | |
| Aplazada | Media (5.5) | 0.41% | — | Perfree Go-fastdfs-webAI | 6/6/2026 | 23/7/2026 | A flaw has been found in perfree go-fastdfs-web up to 1.3.7. Affected is the function checkServer of the file /install/checkServer of the component Installation Endpoint. Executing a manipulation can lead to server-side request forgery. The attack can be executed remotely. The exploit has been published and may be… | |
| Aplazada | Baja (2) | 0.07% | — | Paddlepaddle FastdeployAI | 4/6/2026 | 22/7/2026 | A weakness has been identified in PaddlePaddle FastDeploy up to 2.4.1. Affected by this issue is the function hash_features of the file fastdeploy/multimodal/hasher.py of the component MultimodalHasher. Executing a manipulation can lead to use of weak hash. The attack requires local access. A high complexity level is… | |
| Aplazada | Media (5.5) | 0.51% | — | Perfree Go-fastdfs-webAI | 11/4/2026 | 17/6/2026 | A security vulnerability has been detected in perfree go-fastdfs-web up to 1.3.7. This affects an unknown part of the file src/main/java/com/perfree/controller/InstallController.java of the component doInstall Interface. The manipulation leads to improper authorization. The attack may be initiated remotely. The… | |
| Aplazada | Baja (2.9) | 0.46% | — | Perfree Go-fastdfs-webAIApache ShiroAI | 11/3/2026 | 17/6/2026 | A security flaw has been discovered in perfree go-fastdfs-web up to 1.3.7. This affects the function rememberMeManager of the file src/main/java/com/perfree/config/ShiroConfig.java of the component Apache Shiro RememberMe. Performing a manipulation results in use of hard-coded cryptographic key . The attack can be… | |
| Aplazada | Alta (8.8) | 0.28% | — | Ninjateam FastdupAI | 12/2/2026 | 17/6/2026 | The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to unauthorized backup creation and download due to a missing capability check on REST API endpoints in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Aplazada | Media (6.5) | 0.38% | — | Ninjateam FastdupAI | 6/1/2026 | 17/6/2026 | The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.7 via the 'dir_path' parameter in the 'njt-fastdup/v1/template/directory-tree' REST API endpoint. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.9) | 0.68% | — | Fastd Project Fastd | 27/1/2025 | 17/6/2026 | fastd is a VPN daemon which tunnels IP packets and Ethernet frames over UDP. When receiving a data packet from an unknown IP address/port combination, fastd will assume that one of its connected peers has moved to a new address and initiate a reconnect by sending a handshake packet. This "fast reconnect" avoids having… | |
| Aplazada | Alta (7.5) | 0.62% | — | Eprosima FastddsAI | 19/3/2024 | 17/6/2026 | An issue in the HistoryQosPolicy component of FastDDS v2.12.x, v2.11.x, v2.10.x, and v2.6.x leads to a SIGABRT (signal abort) upon receiving DataWriter's data. | |
| Modificada | Media (5.3) | 0.91% | — | Ninjateam Fastdup | 16/1/2024 | 17/6/2026 | The FastDup WordPress plugin before 2.2 does not prevent directory listing in sensitive directories containing export files. | |
| Modificada | Alta (7.5) | 0.48% | — | Ninjateam Fastdup | 8/1/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team FastDup – Fastest WordPress Migration & Duplicator.This issue affects FastDup – Fastest WordPress Migration & Duplicator: from n/a through 2.1.7. | |
| Modificada | Crítica (9.8) | 3.6% | — | Go-fastdfs Project Go-fastdfs | 2/4/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in sjqzhang go-fastdfs up to 1.4.3. Affected by this issue is the function upload of the file /group1/uploa of the component File Upload Handler. The manipulation leads to path traversal: '../filedir'. The attack may be launched remotely. The exploit… | |
| Modificada | Alta (7.5) | 2.4% | — | Fastd Project FastdDebian LinuxFedoraproject Fedora | 22/10/2020 | 17/6/2026 | receive.c in fastd before v21 allows denial of service (assertion failure) when receiving packets with an invalid type code. |