Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2556▼ 314 respecto a la semana anterior
Críticas / altas1340▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.4) | 2.9% | — | Tenda CP3AIApache KylinAI | 5/9/2026 | 8/9/2026 | A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely. | |
| Modificada | Media (4.3) | 0.45% | — | Apache Kylin | 14/7/2026 | 15/7/2026 | Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to unauthorized jobs in other projects. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version… | |
| Modificada | Crítica (9.8) | 2.5% | — | Apache Kylin | 14/7/2026 | 15/7/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes the issue. | |
| Modificada | Crítica (9.8) | 0.69% | — | Apache Kylin | 14/7/2026 | 14/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the injection to the generated SQL. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes… | |
| Aplazada | Media (4.3) | 0.12% | — | Extendthemes Skyline WPAI | 17/6/2026 | 1/10/2026 | Cross-Site request forgery (CSRF) vulnerability in Extend Themes Skyline WP allows Cross Site Request Forgery. This issue affects Skyline WP: from n/a through 1.0.10. | |
| Pendiente de análisis | Media (5.4) | 0.30% | — | Openstack SkylineAI | 10/4/2026 | 17/6/2026 | OpenStack Skyline before 5.0.1, 6.0.0, and 7.0.0 has a DOM-based Cross-Site Scripting (XSS) vulnerability in the console because document.write is used unsafely, which is relevant in scenarios where administrators use the console web interface to view instance console logs. | |
| Modificada | Alta (7.3) | 0.53% | — | Apache Kylin | 2/10/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. You are fine as long as the Kylin's system and project admin access is well protected. Users are recommended to upgrade to version 5.0.3, which fixes the issue. | |
| Modificada | Alta (7.5) | 20% | — | Apache Kylin | 2/10/2025 | 17/6/2026 | Files or Directories Accessible to External Parties vulnerability in Apache Kylin. You are fine as long as the Kylin's system and project admin access is well protected. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. Users are recommended to upgrade to version 5.0.3, which fixes the issue. | |
| Modificada | Alta (7.5) | 1.3% | — | Apache Kylin | 2/10/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. Users are recommended to upgrade to version 5.0.3, which fixes the issue. | |
| Analizada | Alta (7.2) | 0.93% | — | Apache Kylin | 27/3/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Kylin. If an attacker gets access to Kylin's system or project admin permission, the JDBC connection configuration maybe altered to execute arbitrary code from the remote. You are fine as long as the Kylin's system and project admin… | |
| Analizada | Media (6.5) | 0.63% | — | Apache Kylin | 27/3/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. Through a kylin server, an attacker may forge a request to invoke "/kylin/api/xxx/diag" api on another internal host and possibly get leaked information. There are two preconditions: 1) The attacker has got admin access to a kylin server; 2) Another… | |
| Analizada | Crítica (9.1) | 0.67% | — | Apache Kylin | 4/11/2024 | 17/6/2026 | Session Fixation vulnerability in Apache Kylin. This issue affects Apache Kylin: from 2.0.0 through 4.x. Users are recommended to upgrade to version 5.0.0 or above, which fixes the issue. | |
| Modificada | Alta (7.5) | 1.1% | — | Apache Kylin | 29/1/2024 | 17/6/2026 | In Apache Kylin version 2.0.0 to 4.0.3, there is a Server Config web interface that displays the content of file 'kylin.properties', that may contain serverside credentials. When the kylin service runs over HTTP (or other plain text protocol), it is possible for network sniffers to hijack the HTTP payload and get… | |
| Modificada | Alta (7.8) | 0.95% | — | Kylinos Kylin-system-updater | 25/12/2023 | 17/6/2026 | A vulnerability classified as critical has been found in KylinSoft kylin-system-updater up to 2.0.5.16-0k2.33. Affected is an unknown function of the file /usr/share/kylin-system-updater/SystemUpdater/UpgradeStrategiesDbus.py of the component com.kylin.systemupgrade Service. The manipulation of the argument… | |
| Modificada | Alta (7.8) | 0.21% | — | Kylinos Hedron-domain-hook | 21/12/2023 | 17/6/2026 | A vulnerability was found in KylinSoft hedron-domain-hook up to 3.8.0.12-0k0.5. It has been declared as critical. This vulnerability affects the function init_kcm of the component DBus Handler. The manipulation leads to improper access controls. Attacking locally is a requirement. The exploit has been disclosed to the… | |
| Modificada | Alta (7.1) | 0.31% | — | Ubuntukylin Youker-assistant | 5/6/2023 | 17/6/2026 | A vulnerability classified as critical was found in KylinSoft youker-assistant on KylinOS. Affected by this vulnerability is the function delete_file in the library dbus.SystemBus of the component Arbitrary File Handler. The manipulation leads to improper access controls. It is possible to launch the attack on the… | |
| Modificada | Alta (7.8) | 0.68% | — | Ubuntukylin Youker-assistant | 5/6/2023 | 17/6/2026 | A vulnerability classified as critical has been found in KylinSoft youker-assistant on KylinOS. Affected is the function restore_all_sound_file. The manipulation leads to path traversal: '../filedir'. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. Upgrading to version… | |
| Modificada | Alta (7.8) | 2.1% | — | Kylinos Kylin-software-properties | 5/6/2023 | 17/6/2026 | A vulnerability was found in KylinSoft kylin-software-properties on KylinOS. It has been rated as critical. This issue affects the function setMainSource. The manipulation leads to os command injection. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Alta (7.8) | 0.33% | — | Kylinos Kylin-software-properties | 5/6/2023 | 17/6/2026 | A vulnerability was found in KylinSoft kylin-software-properties on KylinOS. It has been declared as critical. This vulnerability affects the function changedSource. The manipulation leads to improper access controls. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Alta (7.8) | 1.5% | — | Kylinos Youker-assistant | 15/4/2023 | 17/6/2026 | A vulnerability classified as critical was found in KylinSoft youker-assistant on KylinOS. Affected by this vulnerability is the function adjust_cpufreq_scaling_governer. The manipulation leads to os command injection. It is possible to launch the attack on the local host. The exploit has been disclosed to the public… | |
| Modificada | Alta (7.8) | 1.8% | — | Ubuntukylin Kylin-system-updater | 8/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in kylin-system-updater up to 1.4.20kord on Ubuntu Kylin. Affected is the function InstallSnap of the component Update Handler. The manipulation leads to command injection. The attack needs to be approached locally. The exploit has been disclosed to the… | |
| Modificada | Alta (7.8) | 0.38% | — | Kylinos Kylin OS | 3/3/2023 | 17/6/2026 | A vulnerability was found in KylinSoft kylin-activation on KylinOS and classified as critical. Affected by this issue is some unknown functionality of the component File Import. The manipulation leads to improper authorization. The attack needs to be approached locally. The exploit has been disclosed to the public and… | |
| Modificada | Crítica (9.8) | 3.0% | — | Apache Kylin | 30/12/2022 | 17/6/2026 | Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request. | |
| Modificada | Alta (8.8) | 55% | — | Apache Kylin | 30/12/2022 | 17/6/2026 | In the fix for CVE-2022-24697, a blacklist is used to filter user input commands. But there is a risk of being bypassed. The user can control the command by controlling the kylin.engine.spark-cmd parameter of conf. | |
| Modificada | Crítica (9.8) | 85% | — | Apache Kylin | 13/10/2022 | 17/6/2026 | Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can be implemented by closing the single quotation marks around the parameter value of “-- conf=” to inject any operating system command into the command line parameters.… |