Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2578▼ 368 respecto a la semana anterior
Críticas / altas1326▲ 36 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
–

16 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.49%—Karmada DashboardAI24/10/202517/6/2026
Karmada Dashboard is a general-purpose, web-based control panel for Karmada which is a multi-cluster management project. Prior to version 0.2.0, there is an authentication bypass vulnerability in the Karmada Dashboard API. The backend API endpoints (e.g., /api/v1/secret, /api/v1/service) did not enforce…
AplazadaMedia (4.9)0.21%—Ankur Vishwakarma WP Avcl Automation HelperAI24/4/202517/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Ankur Vishwakarma WP AVCL Automation Helper (formerly WPFlyLeads) woozap allows Server Side Request Forgery.This issue affects WP AVCL Automation Helper (formerly WPFlyLeads): from n/a through <= 3.4.
AplazadaMedia (5.3)0.72%—KarmadaAIKarmadactlAIKarmada-operatorAI3/1/202517/6/2026
Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to version 1.12.0, both in karmadactl and karmada-operator, it is possible to supply a filesystem path, or an HTTP(s) URL to retrieve the custom resource definitions(CRDs)…
AplazadaAlta (8.7)0.49%—KarmadaAI3/1/202517/6/2026
Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to version 1.12.0, the PULL mode clusters registered with the `karmadactl register` command have excessive privileges to access control plane resources. By abusing these…
AplazadaAlta (8.4)0.18%—Karmada-io KarmadaAI2/5/202417/6/2026
An issue in karmada-io karmada v1.9.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.
ModificadaAlta (7.5)0.61%—Karmasis Infraskope Siem+18/11/202217/6/2026
Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to damage the page where the agents are listed.
ModificadaAlta (7.5)0.78%—Karmasis Infraskope Siem+18/11/202217/6/2026
Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to obtain critical information.
ModificadaMedia (5.3)0.53%—Karmasis Infraskope Siem+16/11/202217/6/2026
Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to modificate logs.
ModificadaCrítica (9.8)1.8%—Grunt-karma Project Grunt-karma14/10/202217/6/2026
Prototype pollution vulnerability in karma-runner grunt-karma 4.0.1 via the key variable in grunt-karma.js.
ModificadaMedia (6.1)0.88%—Karma Project Karma25/2/202217/6/2026
The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parameter.
ModificadaMedia (6.1)15%—Karma Project Karma5/2/202217/6/2026
Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14.
ModificadaCrítica (9.8)4.3%—Karma-mojo Project Karma-mojo2/4/202017/6/2026
karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument.
ModificadaCrítica (9.8)2.8%—JCO Karma20/12/201817/6/2026
SQL injection vulnerability in the "ContentPlaceHolder1_uxTitle" component in ArchiveNews.aspx in jco.ir KARMA 6.0.0 allows a remote attacker to execute arbitrary SQL commands via the "id" parameter.
ModificadaMedia (6.5)0.93%—Drupal User Karma Module25/2/200916/6/2026
Multiple SQL injection vulnerabilities in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allow remote authenticated administrators to execute arbitrary SQL commands via (1) a content type or (2) a voting API value.
ModificadaMedia (4.3)1.1%—Drupal User Karma Module25/2/200916/6/2026
Cross-site scripting (XSS) vulnerability in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified messages.
ModificadaAlta (7.5)1.00%—Fizzmedia Negativekarma Fizzmedia30/7/200816/6/2026
SQL injection vulnerability in comment.php in Fizzmedia 1.51.2 allows remote attackers to execute arbitrary SQL commands via the mid parameter.