Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.47% | — | HydroAI | 15/9/2026 | 30/9/2026 | Hydro is a next-generation high-performance online judge platform. From 4.10.4 until 5.0.2, the session recreation logic in packages/hydrooj/src/service/layers/base.ts creates a replacement session token without deleting the previous token from the server-side session token store, so an old sid cookie can remain valid… | |
| Modificada | Media (6.9) | 0.40% | — | Hydrosystem.poznan Control System | 9/4/2026 | 13/8/2026 | AlanWeb SCADA saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker to obtain further authorized access into the system. Combined with vulnerability CVE-2026-34184, these sensitive information could be accessed by an unauthorized user. This issue was fixed in… | |
| Modificada | Alta (8.7) | 0.47% | — | Hydrosystem.poznan Control System | 9/4/2026 | 13/8/2026 | AlanWeb SCADA is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in place, an authenticated attacker can inject arbitrary SQL commands, potentially gaining full control over the database. This issue was fixed in AlanWeb SCADA version 9.8.5 | |
| Modificada | Alta (8.8) | 0.46% | — | Hydrosystem.poznan Control System | 9/4/2026 | 13/8/2026 | AlanWeb SCADA does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and even execute some of them. Critically the attacker could run PHP scripts directly on the connected database. This issue was fixed in AlanWeb SCADA version 9.8.5 | |
| Aplazada | Alta (7.1) | 0.25% | — | Buddhathemes HydroAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddhaThemes HYDRO hydro allows Reflected XSS.This issue affects HYDRO: from n/a through <= 2.8. | |
| Modificada | Media (5.4) | 0.82% | — | Shopify Hydrogen | 18/5/2022 | 17/6/2026 | Hydrogen is a React-based framework for building dynamic, Shopify-powered custom storefronts. There is a potential Cross-Site Scripting (XSS) vulnerability where an arbitrary user is able to execute scripts on pages that are built with Hydrogen. This affects all versions of Hydrogen starting from version 0.10.0 to… | |
| Modificada | Media (5.4) | 0.27% | — | Misterpark Hydrogen Water | 16/10/2014 | 17/6/2026 | The Hydrogen Water (aka com.appzone628) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.9% | — | Hydrobb | 31/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in HydroBB 1.0.0 Beta 2 allow remote attackers to inject arbitrary web script or HTML via the s parameter to (1) search.php, (2) members.php, (3) stats.php, (4) viewforum.php, (5) register.php, (6) usercp.php, (7) groups.php, (8) pms.php, and (9) calendar.php. |