Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 211 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.4) | 0.17% | — | Ashlar ArgonAshlar CobaltAshlar Cobalt ShareAshlar Lithium+1 | 12/5/2026 | 17/6/2026 | An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information or execute arbitrary code when a specially crafted VC6 file is being parsed. | |
| Analizada | Alta (8.4) | 0.17% | — | Ashlar ArgonAshlar CobaltAshlar Cobalt ShareAshlar Lithium+1 | 12/5/2026 | 17/6/2026 | An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information or execute arbitrary code when a specially crafted VC6 file is being parsed. | |
| Analizada | Alta (8.4) | 0.17% | — | Ashlar ArgonAshlar CobaltAshlar Cobalt ShareAshlar Lithium+1 | 12/5/2026 | 17/6/2026 | An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to execute arbitrary code when a specially crafted VC6 file is being parsed. | |
| Modificada | Alta (8.4) | 0.42% | — | Ashlar ArgonAshlar CobaltAshlar Cobalt ShareAshlar Lithium+1 | 25/11/2025 | 17/6/2026 | A Heap-based Buffer Overflow vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information or execute arbitrary code. | |
| Modificada | Alta (8.4) | 0.34% | — | Ashlar ArgonAshlar CobaltAshlar Cobalt ShareAshlar Lithium+1 | 25/11/2025 | 17/6/2026 | An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information or execute arbitrary code. | |
| Analizada | Alta (8.4) | 0.17% | — | Ashlar ArgonAshlar CobaltAshlar Cobalt ShareAshlar Lithium+1 | 18/8/2025 | 17/6/2026 | In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing XE files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the… | |
| Analizada | Alta (8.4) | 0.17% | — | Ashlar ArgonAshlar CobaltAshlar Cobalt ShareAshlar Lithium+1 | 18/8/2025 | 17/6/2026 | In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing VC6 files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in… | |
| Analizada | Alta (8.4) | 0.16% | — | Ashlar ArgonAshlar CobaltAshlar Cobalt ShareAshlar Lithium+1 | 18/8/2025 | 17/6/2026 | In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing CO files. This could lead to an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the… | |
| Analizada | Alta (8.4) | 0.16% | — | Ashlar ArgonAshlar CobaltAshlar Cobalt ShareAshlar Lithium+1 | 18/8/2025 | 17/6/2026 | In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing AR files. This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to execute arbitrary code in the… | |
| Analizada | Alta (8.8) | 0.83% | — | Ashlar Lithium | 3/5/2024 | 17/6/2026 | Ashlar-Vellum Lithium Uncontrolled Search Path Element Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Lithium. User interaction is required to exploit this vulnerability in that the target must visit a malicious page… | |
| Analizada | Alta (7.8) | 0.20% | — | Ashlar CobaltAshlar GraphiteAshlar XenonAshlar Argon+1 | 26/10/2023 | 17/6/2026 | In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share v12 SP0 Build (1204.77), the affected applications lack proper validation of user-supplied data when parsing XE files. This could lead to an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of… | |
| Modificada | Media (4.4) | 0.33% | — | Khoros Lithium Forum | 28/6/2022 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Lithium Forum 2017 Q1. This issue affects some unknown processing of the component Compose Message Handler. The manipulation of the argument upload_url leads to server-side request forgery. The attack needs to be approached locally. The exploit has… | |
| Modificada | Media (6.4) | 2.4% | — | Lithium CMS | 6/11/2006 | 16/6/2026 | Directory traversal vulnerability in classes/index.php in Lithium CMS 4.04c and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the siteconf[curl] parameter, as demonstrated by a POST to news/comment.php containing PHP code, which is stored under db/comments/news/ and… | |
| Modificada | Media (5) | 2.8% | — | Lithium Software Lithium II MOD | 2/9/2005 | 16/6/2026 | Format string vulnerability in Lithium II mod 1.24 for Quake 2 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in the nickname. |