Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.9) | 0.20% | — | Holloway Chew Kean HO ActualizerAI | 4/9/2026 | 8/9/2026 | (Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerability in the Alpha user and root user password loops of Shell/debian-minbase-install.sh. The installer invokes mkpasswd to generate yescrypt password hashes but does not check the command's return value and… | |
| Analizada | Alta (7.5) | 0.53% | — | Fedify Hollo | 9/2/2026 | 17/6/2026 | Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Prior to 0.6.20 and 0.7.2, there is a security vulnerability where DMs and followers-only posts were exposed through the ActivityPub outbox endpoint without authorization. This vulnerability is fixed in 0.6.20 and… | |
| Aplazada | Media (6.1) | 0.24% | — | Fedify HolloAI | 17/7/2025 | 17/6/2026 | Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Versions prior to 0.6.5 allow HTML form elements to be submitted, making the software vulnerable to HTML injection. Version 0.6.5 fixes the issue. | |
| Modificada | Crítica (9.1) | 0.36% | — | Hollowaykeanho Automataci | 22/9/2023 | 17/6/2026 | AutomataCI is a template git repository equipped with a native built-in semi-autonomous CI tools. An issue in versions 1.4.1 and below can let a release job reset the git root repository to the first commit. Version 1.5.0 has a patch for this issue. As a workaround, make sure the `PROJECT_PATH_RELEASE` (e.g.… | |
| Modificada | Media (4.4) | 0.24% | — | Netflix Hollow | 23/3/2021 | 17/6/2026 | In Netflix OSS Hollow, since the Files.exists(parent) is run before creating the directories, an attacker can pre-create these directories with wide permissions. Additionally, since an insecure source of randomness is used, the file names to be created can be deterministically calculated. | |
| Modificada | Alta (10) | 3.7% | — | Typemoon Fate/hollow AtaraxiaTypemoon Fate/stay NightTypemoon Fate/stay Night + Hollow Ataraxia SETTypemoon Witch ON THE Holy Night | 6/11/2015 | 17/6/2026 | TYPE-MOON Fate/stay night, Fate/hollow ataraxia, Witch on the Holy Night, and Fate/stay night + hollow ataraxia set allow remote attackers to execute arbitrary OS commands via crafted saved data. | |
| Modificada | Media (5.4) | 0.30% | — | Playscape Bouncy Bill Holloween | 9/9/2014 | 17/6/2026 | The Bouncy Bill Halloween (aka mominis.Generic_Android.Bouncy_Bill_Halloween) application 1.0.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.9) | 0.36% | — | Holloway Docvert | 18/11/2008 | 16/6/2026 | test-pipe-to-pyodconverter.org.sh in docvert 2.4 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/outer.odt temporary file. |