Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.9) | 0.16% | — | Ilya Zlobintsev LactAI | 25/8/2026 | 28/9/2026 | UNIX symbolic link (symlink) following vulnerability in ilya-zlobintsev/LACT allows for local denial-of-service. This issue affects LACT: through 0.10.0. | |
| Pendiente de análisis | Alta (7.3) | 0.16% | — | LactAI | 25/8/2026 | 28/9/2026 | Polkit Authentication Based on UnixProcessSubject / Peer PID in LACT on Linux allows an Authentication Bypass. This issue affects LACT through 0.10.0. Fixed by commit d0478fe42c2219454e272f96b1cbd29ab37ee566. | |
| Modificada | Alta (7.5) | 1.0% | — | Galacticx Project Galacticx | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for GalacticX, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.5) | 5.1% | 💥 Exploit | Galacticomm Technologies WorldgroupGalacticomm Technologies Worldgroup Lite Personal Server | 25/6/2002 | 16/6/2026 | Buffer overflow in Galacticomm Worldgroup FTP server 3.20 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a LIST command containing a large number of / (slash), * (wildcard), and .. characters. | |
| Modificada | Alta (10) | 7.8% | 💥 Exploit | Galacticomm Technologies WorldgroupGalacticomm Technologies Worldgroup Lite Personal Server | 25/6/2002 | 16/6/2026 | Buffer overflow in Galacticomm Worldgroup web server 3.20 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long HTTP GET request. |