Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

25 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.1)0.23%—TMT Machine Industry AND Trade Ltd. CO Talassoft Industrial Management SoftwareAI1/9/20261/9/2026
Use of Hard-coded Credentials vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Retrieve Embedded Sensitive Data. This issue affects Talassoft Industrial Management Software: from V.4 before V.16.
AplazadaAlta (7.1)0.12%—TMT Machine Industry AND Trade Talassoft Industrial Management SoftwareAI1/9/20261/9/2026
Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Cross Site Request Forgery. This issue affects Talassoft Industrial Management Software: from V.4 before V.16.
AplazadaAlta (7.5)0.40%—TMT Machine Industry AND Trade LTD CO Talassoft Industrial Management SoftwareAI1/9/20261/9/2026
Missing authentication for critical function vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Authentication Bypass. This issue affects Talassoft Industrial Management Software: from V4 before V.16.
AplazadaAlta (8.8)0.29%—TMT Machine Industry AND Trade Talassoft Industrial Management SoftwareAI1/9/20261/9/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows SQL Injection. This issue affects Talassoft Industrial Management Software: from V.4 before V.16.
AplazadaAlta (7.1)0.25%—DO LassoAI13/8/202614/8/2026
Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 versions.
AplazadaAlta (7.5)0.41%—DO LassoAI13/8/202614/8/2026
Subscriber Path Traversal in Do Lasso <= 358 versions.
AplazadaAlta (8.5)0.36%—Entrouvert LassoAI13/8/202614/8/2026
Subscriber SQL Injection in Do Lasso <= 358 versions.
AplazadaMedia (6.5)0.33%—DO LassoAI13/8/202614/8/2026
Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions.
AplazadaMedia (5.9)0.24%—Getlasso Simple UrlsAI2/7/20262/7/2026
Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions.
AnalizadaCrítica (9.8)1.1%—Entrouvert Lasso5/11/202517/6/2026
A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr&#39;ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML response can lead to an arbitrary code execution. An attacker can send a malformed SAML response to trigger this vulnerability.
AnalizadaAlta (7.5)0.59%—Entrouvert Lasso5/11/202517/6/2026
A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr&#39;ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a memory depletion, resulting in denial of service. An attacker can send a malformed SAML response to trigger this vulnerability.
AnalizadaAlta (7.5)0.57%—Entrouvert Lasso5/11/202517/6/2026
A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr&#39;ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML assertion response can lead to a denial of service. An attacker can send a malformed SAML response to trigger this vulnerability.
AnalizadaAlta (7.5)0.59%—Entrouvert Lasso5/11/202517/6/2026
A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr&#39;ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a denial of service. An attacker can send a malformed SAML response to trigger this vulnerability.
AplazadaMedia (5.4)0.54%—Getlasso Simple UrlsAI13/12/202417/6/2026
Missing Authorization vulnerability in Andrew Fiebert Simple URLs simple-urls allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple URLs: from n/a through <= 117.
ModificadaMedia (5.4)0.45%—Getlasso Simple Urls30/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lasso Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management allows Stored XSS.This issue affects Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management: from n/a through…
ModificadaAlta (8.8)0.21%—Getlasso Simple Urls16/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Lasso Simple URLs plugin <= 120 versions.
ModificadaMedia (6.1)0.40%—Getlasso Simple Urls27/9/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Lasso Simple URLs plugin <= 117 versions.
ModificadaMedia (6.1)1.7%—Getlasso Simple Urls13/2/202317/6/2026
The Simple URLs WordPress plugin before 115 does not sanitise and escape some parameters before outputting them back in some pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
ModificadaAlta (8.8)0.94%—Getlasso Simple Urls13/2/202317/6/2026
The Simple URLs WordPress plugin before 115 does not escape some parameters before using them in various SQL statements used by AJAX actions available by any authenticated users, leading to a SQL injection exploitable by low privilege users such as subscriber.
ModificadaAlta (7.5)1.3%—Entrouvert LassoDebian LinuxFedoraproject Fedora4/6/202117/6/2026
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
ModificadaAlta (7.5)3.5%—Fedoraproject FedoraEntrouvert Lasso11/8/201717/6/2026
The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers to cause a denial of service (uninitialized memory access and application crash) via unspecified vectors.
ModificadaMedia (4.3)1.3%—Entrouvert Lasso7/1/200916/6/2026
Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
ModificadaMedia (6.4)1.3%—Omnipilot Software Lasso Professional Server17/8/200516/6/2026
Unknown vulnerability in Lasso Professional Server8.0.4 and 8.0.5 allows attackers to bypass authentication, related to [Auth] tags.
ModificadaMedia (5)1.9%—Blue World Communications Lasso WEB Data Engine31/12/200216/6/2026
Buffer overflow in Blue World Lasso Web Data Engine 3.6.5 allows remote attackers to cause a denial of service via a long URL.
ModificadaMedia (5)1.3%—Blue World Communications Lasso CGI19/8/199716/6/2026
Vulnerability in CGI program in the Lasso application by Blue World, as used on WebSTAR and other servers, allows remote attackers to read arbitrary files.