Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.55% | — | Morelitea Initiative | 26/2/2026 | 17/6/2026 | Initiative is a self-hosted project management platform. An access control vulnerability exists in Initiative versions prior to 0.32.2 where uploaded documents are served from a publicly accessible /uploads/ directory without any authentication or authorization checks. Any uploaded file can be accessed directly via… | |
| Analizada | Alta (8.1) | 0.39% | — | Morelitea Initiative | 26/2/2026 | 17/6/2026 | Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 do not invalidate previously issued JWT access tokens after a user changes their password. As a result, older tokens remain valid until expiration and can still be used to access protected API endpoints. This behavior… | |
| Analizada | Alta (8.7) | 0.56% | — | Morelitea Initiative | 26/2/2026 | 17/6/2026 | Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 are vulnerable to Stored Cross-Site Scripting (XSS) in the document upload functionality. Any user with upload permissions within the "Initiatives" section can upload a malicious `.html` or `.htm` file as a document.… | |
| Aplazada | Media (5.1) | 0.32% | — | Influx Initiative OnboardliteAI | 20/8/2025 | 17/6/2026 | OnboardLite is the result of the Influx Initiative, our vision for an improved student organization lifecycle at the University of Central Florida. An attacker can craft a link to the trusted application that, when visited, redirects the user to a malicious external site. This enables phishing, credential theft,… | |
| Aplazada | Alta (8.8) | 0.47% | — | Xiaomi Security CenterAITrendmicro Zero DAY InitiativeAI | 28/8/2024 | 17/6/2026 | The Xiaomi Security Center expresses heartfelt thanks to Ken Gannon and Ilyes Beghdadi of NCC Group working with Trend Micro Zero Day Initiative! At the same time, we also welcome more outstanding and professional security experts and security teams to join the Mi Security Center (MiSRC) to jointly ensure the safe… | |
| Modificada | Media (5) | 2.2% | — | Linuxfoundation Open Container Initiative Distribution SpecificationLinuxfoundation Open Container Initiative Image Format SpecificationFedoraproject Fedora | 17/11/2021 | 17/6/2026 | The OCI Distribution Spec project defines an API protocol to facilitate and standardize the distribution of content. In the OCI Distribution Specification version 1.0.0 and prior, the Content-Type header alone was used to determine the type of document during push and pull operations. Documents that contain both… |