Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 82 respecto a la semana anterior
Críticas / altas1416▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)100▼ 400 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5)0.20%—Okta Privileged Access ClientAIOkta ScaleftAI8/9/202610/9/2026
The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments. When a scaleft:// protocol handler link contains a value beginning with a hyphen, the underlying CLI framework interprets it as a command-line flag, causing unintended…
ModificadaAlta (7.7)0.34%—Bitwiseshiftleft Stanford Javascript Crypto Library17/3/202628/7/2026
Versions of the package sjcl before 1.0.9 are vulnerable to Improper Verification of Cryptographic Signature due to missing point-on-curve validation in sjcl.ecc.basicKey.publicKey(). An attacker can recover a victim's ECDH private key by sending crafted off-curve public keys and observing ECDH outputs. The dhJavaEc()…
AplazadaMedia (6.5)0.16%—Wpfactory Free Shipping BAR Amount Left FOR Free Shipping FOR WoocommerceAI24/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Free Shipping Bar: Amount Left for Free Shipping for WooCommerce amount-left-free-shipping-woocommerce allows Stored XSS.This issue affects Free Shipping Bar: Amount Left for Free Shipping for WooCommerce:…
ModificadaMedia (6.5)0.79%—Gopiplus Left Right Image Slideshow Gallery31/10/202317/6/2026
The Left right image slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 12.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated…
ModificadaMedia (6.1)0.45%—Left Project Left20/1/202317/6/2026
Cross site scripting (XSS) vulnerability in Hundredrabbits Left 7.1.5 for MacOS allows attackers to execute arbitrary code via the meta tag.
ModificadaMedia (6.1)0.45%—Left Project Left20/1/202317/6/2026
Cross site scripting (XSS) vulnerability in Hundredrabbits Left 7.1.5 for MacOS allows attackers to execute arbitrary code via file names.
ModificadaAlta (7.6)3.6%—HP Lefthand15/2/201817/6/2026
A Remote Arbitrary Command Execution vulnerability in HPE StoreVirtual 4000 Storage and StoreVirtual VSA Software running LeftHand OS version v12.5 and earlier was found. The problem was resolved in LeftHand OS v12.6 or any subsequent version.
ModificadaAlta (10)10%—HP LefthandHP Storevirtual Virtual Storage ApplianceHP Storevirtual 400026/2/201416/6/2026
Unspecified vulnerability in dbd_manager in LeftHand OS before 11.0 in HP StoreVirtual 4000 and StoreVirtual VSA Software (formerly LeftHand Virtual SAN Appliance) allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1509.
ModificadaAlta (10)62%—HP Lefthand P4000 Virtual SAN ApplianceHP Lefthand Virtual SAN Appliance HydraHP Lefthand Virtual SAN Appliance Hydra Software2/7/201316/6/2026
Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1510.
ModificadaAlta (10)8.7%—HP San/iqHP Lefthand P4000 Virtual SAN Appliance6/2/201316/6/2026
Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1513.
ModificadaAlta (10)8.7%—HP San/iqHP Lefthand P4000 Virtual SAN Appliance6/2/201316/6/2026
Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1512.
ModificadaAlta (10)10%—HP San/iqHP Lefthand P4000 Virtual SAN Appliance6/2/201316/6/2026
Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1511.
ModificadaAlta (10)17%—HP San/iqHP Lefthand P4000 Virtual SAN Appliance6/2/201316/6/2026
Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1468.
ModificadaBaja (3.5)1.0%—Thinkleft Submenu Tree19/9/201216/6/2026
Cross-site scripting (XSS) vulnerability in the Submenu Tree module before 6.x-1.5 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (9.3)5.8%—Andres Garcia Getleft5/8/200916/6/2026
Multiple buffer overflows in Getleft.exe in Andres Garcia Getleft 1.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) "a" HTML tag; a long src attribute in (2) embed, (3) img, or (4) script tags; (5) a long background attribute in a body tag; and other…