Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 82 respecto a la semana anterior
Críticas / altas1416▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)100▼ 400 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5) | 0.20% | — | Okta Privileged Access ClientAIOkta ScaleftAI | 8/9/2026 | 10/9/2026 | The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments. When a scaleft:// protocol handler link contains a value beginning with a hyphen, the underlying CLI framework interprets it as a command-line flag, causing unintended… | |
| Modificada | Alta (7.7) | 0.34% | — | Bitwiseshiftleft Stanford Javascript Crypto Library | 17/3/2026 | 28/7/2026 | Versions of the package sjcl before 1.0.9 are vulnerable to Improper Verification of Cryptographic Signature due to missing point-on-curve validation in sjcl.ecc.basicKey.publicKey(). An attacker can recover a victim's ECDH private key by sending crafted off-curve public keys and observing ECDH outputs. The dhJavaEc()… | |
| Aplazada | Media (6.5) | 0.16% | — | Wpfactory Free Shipping BAR Amount Left FOR Free Shipping FOR WoocommerceAI | 24/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Free Shipping Bar: Amount Left for Free Shipping for WooCommerce amount-left-free-shipping-woocommerce allows Stored XSS.This issue affects Free Shipping Bar: Amount Left for Free Shipping for WooCommerce:… | |
| Modificada | Media (6.5) | 0.79% | — | Gopiplus Left Right Image Slideshow Gallery | 31/10/2023 | 17/6/2026 | The Left right image slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 12.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Modificada | Media (6.1) | 0.45% | — | Left Project Left | 20/1/2023 | 17/6/2026 | Cross site scripting (XSS) vulnerability in Hundredrabbits Left 7.1.5 for MacOS allows attackers to execute arbitrary code via the meta tag. | |
| Modificada | Media (6.1) | 0.45% | — | Left Project Left | 20/1/2023 | 17/6/2026 | Cross site scripting (XSS) vulnerability in Hundredrabbits Left 7.1.5 for MacOS allows attackers to execute arbitrary code via file names. | |
| Modificada | Alta (7.6) | 3.6% | — | HP Lefthand | 15/2/2018 | 17/6/2026 | A Remote Arbitrary Command Execution vulnerability in HPE StoreVirtual 4000 Storage and StoreVirtual VSA Software running LeftHand OS version v12.5 and earlier was found. The problem was resolved in LeftHand OS v12.6 or any subsequent version. | |
| Modificada | Alta (10) | 10% | — | HP LefthandHP Storevirtual Virtual Storage ApplianceHP Storevirtual 4000 | 26/2/2014 | 16/6/2026 | Unspecified vulnerability in dbd_manager in LeftHand OS before 11.0 in HP StoreVirtual 4000 and StoreVirtual VSA Software (formerly LeftHand Virtual SAN Appliance) allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1509. | |
| Modificada | Alta (10) | 62% | — | HP Lefthand P4000 Virtual SAN ApplianceHP Lefthand Virtual SAN Appliance HydraHP Lefthand Virtual SAN Appliance Hydra Software | 2/7/2013 | 16/6/2026 | Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1510. | |
| Modificada | Alta (10) | 8.7% | — | HP San/iqHP Lefthand P4000 Virtual SAN Appliance | 6/2/2013 | 16/6/2026 | Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1513. | |
| Modificada | Alta (10) | 8.7% | — | HP San/iqHP Lefthand P4000 Virtual SAN Appliance | 6/2/2013 | 16/6/2026 | Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1512. | |
| Modificada | Alta (10) | 10% | — | HP San/iqHP Lefthand P4000 Virtual SAN Appliance | 6/2/2013 | 16/6/2026 | Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1511. | |
| Modificada | Alta (10) | 17% | — | HP San/iqHP Lefthand P4000 Virtual SAN Appliance | 6/2/2013 | 16/6/2026 | Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1468. | |
| Modificada | Baja (3.5) | 1.0% | — | Thinkleft Submenu Tree | 19/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Submenu Tree module before 6.x-1.5 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (9.3) | 5.8% | — | Andres Garcia Getleft | 5/8/2009 | 16/6/2026 | Multiple buffer overflows in Getleft.exe in Andres Garcia Getleft 1.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) "a" HTML tag; a long src attribute in (2) embed, (3) img, or (4) script tags; (5) a long background attribute in a body tag; and other… |