Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.4) | 1.1% | — | Sakura Editor Development Community Sakura EditorAI | 24/8/2026 | 28/8/2026 | Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes "Open Terminal". | |
| Analizada | Alta (8.8) | 0.28% | — | Eclipse Kura | 14/7/2026 | 18/8/2026 | Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log entries. The org.eclipse.kura.web2 (Web Console) and org.eclipse.kura.rest.provider (REST API) components use this header as the primary IP source when… | |
| Aplazada | Crítica (9.1) | 0.27% | — | EPG INC Kura Sushi Official APPAI | 12/5/2026 | 17/6/2026 | "Kura Sushi Official App" provided by EPG, Inc. is vulnerable to improper certificate validation. A man-in-the-middle attack may allow eavesdropping on, or altering, the communication on push notifications between the affected application and the relevant server. | |
| Aplazada | Alta (8.4) | 0.14% | — | NEC Corporation Rakurakumusen Start EXAI | 19/11/2025 | 17/6/2026 | DLL Loading vulnerability in NEC Corporation RakurakuMusen Start EX All Verisons allows a attacker to manipulate the PC environment to cause unintended operations on the user's device. | |
| Aplazada | Media (5.9) | 0.29% | — | Sakurapixel Lunar Lunar-sell-photos-onlineAI | 11/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sakurapixel Lunar lunar-sell-photos-online allows Stored XSS.This issue affects Lunar: from n/a through <= 1.3.0. | |
| Aplazada | Media (4) | 0.15% | — | Epark Kura Sushi Official APPAI | 20/11/2024 | 17/6/2026 | Use of hard-coded cryptographic key issue exists in "Kura Sushi Official App Produced by EPARK" for Android versions prior to 3.8.5. If this vulnerability is exploited, a local attacker may obtain the login ID and password for the affected product. | |
| Analizada | Alta (7.5) | 0.58% | — | Eclipse Kura | 9/4/2024 | 17/6/2026 | In Eclipse Kura LogServlet component included in versions 5.0.0 to 5.4.1, a specifically crafted request to the servlet can allow an unauthenticated user to retrieve the device logs. Also, downloaded logs may be used by an attacker to perform privilege escalation by using the session id of an authenticated user… | |
| Modificada | Alta (8.8) | 0.30% | — | TS Webfonts FOR Sakura | 9/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SAKURA Internet Inc. TS Webfonts for さくらのレンタルサーバ plugin <= 3.1.2 versions. | |
| Analizada | Media (4.3) | 0.31% | — | TS Webfonts FOR Sakura | 21/7/2023 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in TS Webfonts for SAKURA 3.1.2 and earlier allows a remote unauthenticated attacker to hijack the authentication of a user and to change settings by having a user view a malicious page. | |
| Analizada | Media (6.1) | 0.60% | — | TS Webfonts FOR Sakura | 21/7/2023 | 17/6/2026 | Cross-site scripting vulnerability in TS Webfonts for SAKURA 3.1.0 and earlier allows a remote unauthenticated attacker to inject an arbitrary script. | |
| Modificada | Crítica (9.8) | 0.86% | — | Dos-osaka Rakuraku PC Cloud AgentDos-osaka SS1 | 6/3/2023 | 17/6/2026 | Use of hard-coded credentials vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to obtain the password of the debug tool and execute it. As a result of exploiting this vulnerability with CVE-2023-22335 and CVE-2023-22336 vulnerabilities together,… | |
| Modificada | Crítica (9.8) | 1.1% | — | Dos-osaka Rakuraku PC Cloud AgentDos-osaka SS1 | 6/3/2023 | 17/6/2026 | Path traversal vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to upload a specially crafted file to an arbitrary directory. As a result of exploiting this vulnerability with CVE-2023-22335 and CVE-2023-22344 vulnerabilities together, it may… | |
| Modificada | Alta (7.5) | 0.74% | — | Dos-osaka Rakuraku PC Cloud AgentDos-osaka SS1 | 6/3/2023 | 17/6/2026 | Improper access control vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to bypass access restriction and download an arbitrary file of the directory where the product runs. As a result of exploiting this vulnerability with CVE-2023-22336 and… | |
| Modificada | Media (6.1) | 0.64% | — | Zerodream Sakurapanel | 2/12/2021 | 17/6/2026 | SakuraPanel v1.0.1.1 is affected by a Cross Site Scripting (XSS) vulnerability in /master/core/PostHandler.php. The exit function will terminate the script and print the message $data['proxy_name']. | |
| Modificada | Alta (7.5) | 1.8% | — | Eclipse Kura | 9/4/2019 | 17/6/2026 | In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service (not part of the device distribution) could potentially be target of XXE attack due to an improper factory and parser initialisation. | |
| Modificada | Media (5.3) | 1.3% | — | Eclipse Kura | 9/4/2019 | 17/6/2026 | In Eclipse Kura versions up to 4.0.0, Kura exposes the underlying Ui Web server version in its replies. This can be used as a hint by an attacker to specifically craft attacks to the web server run by Kura. | |
| Modificada | Media (5.3) | 2.0% | — | Eclipse Kura | 9/4/2019 | 17/6/2026 | In Eclipse Kura versions up to 4.0.0, the SkinServlet did not checked the path passed during servlet call, potentially allowing path traversal in get requests for a limited number of file types. | |
| Modificada | Crítica (9.8) | 1.6% | — | Eclipse Kura | 11/9/2017 | 17/6/2026 | The network enabled distribution of Kura before 2.1.0 takes control over the device's firewall setup but does not allow IPv6 firewall rules to be configured. Still the Equinox console port 5002 is left open, allowing to log into Kura without any user credentials over unencrypted telnet and executing commands using the… | |
| Modificada | Media (5.4) | 0.27% | — | Kuran'in Bilimsel Mucizeleri Project Kuran'in Bilimsel Mucizeleri | 21/10/2014 | 17/6/2026 | The Kuran'in Bilimsel Mucizeleri (aka com.wKurannBilimselMucizeleri) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Buronya DIL Bilgisi Kurallari | 19/10/2014 | 17/6/2026 | The Dil Bilgisi Kurallari (aka com.buronya.dilbilgisi) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |