Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2750▲ 27 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 0.33% | — | Esri LercAI | 25/9/2026 | 30/9/2026 | Esri LERC is an open-source image or raster format which supports rapid encoding and decoding for any pixel type. A Heap based Out-of-Bounds Write via Integer Overflow in LERC versions 4.1.0 and earlier may allow a remote, unauthenticated attacker who can pass specifically crafted attacker controlled imagery to an… | |
| Analizada | Alta (8.1) | 0.38% | — | Coolercontrold | 8/4/2026 | 24/7/2026 | CORS misconfiguration in CoolerControl/coolercontrold <4.0.0 allows unauthenticated remote attackers to read data and send commands to the service via malicious websites | |
| Analizada | Media (6.1) | 0.37% | — | Coolercontrold | 8/4/2026 | 24/7/2026 | Stored XSS in log viewer in CoolerControl/coolercontrol-ui <4.0.0 allows unauthenticated attackers to take over the service via malicious JavaScript in poisoned log entries | |
| Analizada | Crítica (9.1) | 0.28% | — | Coolercontrold | 8/4/2026 | 24/7/2026 | Unauthenticated functionality in CoolerControl/coolercontrold <4.0.0 allows unauthenticated attackers to view and modify potentially sensitive data via HTTP requests | |
| Analizada | Alta (7.2) | 1.5% | — | Coolercontrold | 8/4/2026 | 24/7/2026 | Command injection in alerts in CoolerControl/coolercontrold <4.0.0 allows authenticated attackers to execute arbitrary code as root via injected bash commands in alert names | |
| Aplazada | Media (5.3) | 0.32% | — | Mailercloud-integrate-webforms-synchronize-contactsAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in mailercloud Mailercloud – Integrate webforms and synchronize website contacts mailercloud-integrate-webforms-synchronize-contacts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mailercloud – Integrate webforms and synchronize website… | |
| Aplazada | Media (6.1) | 0.14% | — | PackageinstallercnAI | 7/5/2025 | 17/6/2026 | Improper handling of insufficient permission in PackageInstallerCN prior to version 15.0.11.0 allows local attacker to bypass user interaction for requested installation. | |
| Modificada | Alta (8.8) | 0.25% | — | Remileclercq Hide Admin Notices - Admin Notification Center Plugin | 9/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rémi Leclercq Hide admin notices – Admin Notification Center plugin <= 2.3.2 versions. | |
| Modificada | Media (5.5) | 0.20% | — | Samsung Packageinstallerchn | 6/9/2023 | 17/6/2026 | Intent redirection vulnerability in PackageInstallerCHN prior to version 13.1.03.00 allows local attacker to access arbitrary file. This vulnerability requires user interaction. | |
| Modificada | Media (5.8) | 2.0% | — | Vincent Leclercq News | 6/7/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in divers.php in Vincent Leclercq News 5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) id and (2) disabled parameters. | |
| Modificada | Media (5.1) | 1.3% | — | Vincent Leclercq News | 6/7/2006 | 16/6/2026 | SQL injection vulnerability in divers.php in Vincent Leclercq News 5.2 allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) texte parameters. | |
| Modificada | Media (5) | 1.5% | — | Vincent Leclercq News | 6/7/2006 | 16/6/2026 | index.php in Vincent Leclercq News 5.2 allows remote attackers to obtain sensitive information, such as the installation path, via a mail[] parameter with invalid values. |