Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2578▼ 368 respecto a la semana anterior
Críticas / altas1326▲ 36 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.49% | — | Karmada DashboardAI | 24/10/2025 | 17/6/2026 | Karmada Dashboard is a general-purpose, web-based control panel for Karmada which is a multi-cluster management project. Prior to version 0.2.0, there is an authentication bypass vulnerability in the Karmada Dashboard API. The backend API endpoints (e.g., /api/v1/secret, /api/v1/service) did not enforce… | |
| Aplazada | Media (4.9) | 0.21% | — | Ankur Vishwakarma WP Avcl Automation HelperAI | 24/4/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Ankur Vishwakarma WP AVCL Automation Helper (formerly WPFlyLeads) woozap allows Server Side Request Forgery.This issue affects WP AVCL Automation Helper (formerly WPFlyLeads): from n/a through <= 3.4. | |
| Aplazada | Media (5.3) | 0.72% | — | KarmadaAIKarmadactlAIKarmada-operatorAI | 3/1/2025 | 17/6/2026 | Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to version 1.12.0, both in karmadactl and karmada-operator, it is possible to supply a filesystem path, or an HTTP(s) URL to retrieve the custom resource definitions(CRDs)… | |
| Aplazada | Alta (8.7) | 0.49% | — | KarmadaAI | 3/1/2025 | 17/6/2026 | Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to version 1.12.0, the PULL mode clusters registered with the `karmadactl register` command have excessive privileges to access control plane resources. By abusing these… | |
| Aplazada | Alta (8.4) | 0.18% | — | Karmada-io KarmadaAI | 2/5/2024 | 17/6/2026 | An issue in karmada-io karmada v1.9.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component. | |
| Modificada | Alta (7.5) | 0.61% | — | Karmasis Infraskope Siem+ | 18/11/2022 | 17/6/2026 | Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to damage the page where the agents are listed. | |
| Modificada | Alta (7.5) | 0.78% | — | Karmasis Infraskope Siem+ | 18/11/2022 | 17/6/2026 | Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to obtain critical information. | |
| Modificada | Media (5.3) | 0.53% | — | Karmasis Infraskope Siem+ | 16/11/2022 | 17/6/2026 | Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to modificate logs. | |
| Modificada | Crítica (9.8) | 1.8% | — | Grunt-karma Project Grunt-karma | 14/10/2022 | 17/6/2026 | Prototype pollution vulnerability in karma-runner grunt-karma 4.0.1 via the key variable in grunt-karma.js. | |
| Modificada | Media (6.1) | 0.88% | — | Karma Project Karma | 25/2/2022 | 17/6/2026 | The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parameter. | |
| Modificada | Media (6.1) | 15% | — | Karma Project Karma | 5/2/2022 | 17/6/2026 | Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14. | |
| Modificada | Crítica (9.8) | 4.3% | — | Karma-mojo Project Karma-mojo | 2/4/2020 | 17/6/2026 | karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument. | |
| Modificada | Crítica (9.8) | 2.8% | — | JCO Karma | 20/12/2018 | 17/6/2026 | SQL injection vulnerability in the "ContentPlaceHolder1_uxTitle" component in ArchiveNews.aspx in jco.ir KARMA 6.0.0 allows a remote attacker to execute arbitrary SQL commands via the "id" parameter. | |
| Modificada | Media (6.5) | 0.93% | — | Drupal User Karma Module | 25/2/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allow remote authenticated administrators to execute arbitrary SQL commands via (1) a content type or (2) a voting API value. | |
| Modificada | Media (4.3) | 1.1% | — | Drupal User Karma Module | 25/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified messages. | |
| Modificada | Alta (7.5) | 1.00% | — | Fizzmedia Negativekarma Fizzmedia | 30/7/2008 | 16/6/2026 | SQL injection vulnerability in comment.php in Fizzmedia 1.51.2 allows remote attackers to execute arbitrary SQL commands via the mid parameter. |