Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2544▼ 345 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 1.2% | — | Gluestack UIAITailwind CSSAINativewindAI | 1/7/2025 | 17/6/2026 | gluestack-ui is a library of copy-pasteable components & patterns crafted with Tailwind CSS (NativeWind). Prior to commit e6b4271, a command injection vulnerability was discovered in the discussion-to-slack.yml GitHub Actions workflow. Untrusted discussion fields (title, body, etc.) were directly interpolated into… | |
| Modificada | Media (5.5) | 0.23% | — | Clusterlabs Cluster GlueClusterlabs Pacemaker | 18/10/2021 | 16/6/2026 | stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gain access to passwords of the HA stack and potentially influence its operations. This is fixed in cluster-glue 1.0.6 and newer, and pacemaker 1.1.3 and newer. | |
| Modificada | Alta (7.5) | 1.0% | — | Gluehome Glue Smart Lock Firmware | 15/10/2019 | 17/6/2026 | Glue Smart Lock 2.7.8 devices do not properly block guest access in certain situations where the network connection is unavailable. | |
| Modificada | Media (6.2) | 0.44% | — | Umich LibgssglueUmich Libgssapi | 21/6/2012 | 16/6/2026 | libgssapi and libgssglue before 0.4 do not properly check privileges, which allows local users to load untrusted configuration files and execute arbitrary code via the GSSAPI_MECH_CONF environment variable, as demonstrated using mount.nfs. | |
| Modificada | Media (6.9) | 0.36% | — | Iglues Bulmages-servers | 5/11/2008 | 16/6/2026 | bulmages-servers 0.11.1 allows local users to overwrite arbitrary files via a symlink attack on the (a) /tmp/error.txt, (b) /tmp/errores.txt, and possibly other temporary files, related to the (1) creabulmafact, (2) creabulmacont, and possibly (3) actualizabulmacont, (4) installbulmages-db, and (5) actualizabulmafact… | |
| Modificada | Media (5) | 3.8% | — | Webmethods Glue | 16/4/2007 | 16/6/2026 | Directory traversal vulnerability in /console in the Management Console in webMethods Glue 6.5.1 and earlier allows remote attackers to read arbitrary system files via a .. (dot dot) in the resource parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Glue Software Newsglue | 22/3/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the RSS reader in Glue Software NewsGlue before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via a feed. |