Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
29 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.35% | — | Pocketmine-mpAIJsonmapperAI | 9/9/2026 | 30/9/2026 | PocketMine-MP versions before 4.20.5 contain a denial of service vulnerability in LoginPacket JSON parsing due to improper validation in the JsonMapper dependency. Attackers can send malformed JSON structures in LoginPacket to crash the server. | |
| Aplazada | Alta (8.1) | 0.28% | — | Max-mapper Extract-zipAI | 17/8/2026 | 9/9/2026 | extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file - writes through the planted symlink and… | |
| Analizada | Alta (8.3) | 0.14% | — | Thermofisher ABI Prism 310 Data Collection SoftwareThermofisher ABI Prism 3100/3100-avant Data Collection SoftwareThermofisher Applied Biosystems 3130 Series Data Collection SoftwareThermofisher Applied Biosystems 3500/3500xl Series Data Collection Software+4 | 5/8/2026 | 26/8/2026 | The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes. | |
| Analizada | Alta (8.6) | 0.53% | — | Max-mapper Extract-zip | 26/6/2026 | 6/7/2026 | extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip will extract the symlink without validation, allowing it to point outside the extraction directory. Depending on how… | |
| Analizada | Alta (7.5) | 0.66% | — | Luckypennysoftware Automapper | 20/3/2026 | 17/6/2026 | AutoMapper is a convention-based object-object mapper in .NET. Versions prior to 15.1.1 and 16.1.1 are vulnerable to a Denial of Service (DoS) attack. When mapping deeply nested object graphs, the library uses recursive method calls without enforcing a default maximum depth limit. This allows an attacker to provide a… | |
| Aplazada | Media (6.7) | 0.18% | — | InputmapperAI | 11/3/2026 | 17/6/2026 | InputMapper 1.6.10 contains a buffer overflow vulnerability in the username field that allows local attackers to crash the application by entering an excessively long string. Attackers can trigger a denial of service by copying a large payload into the username field and double-clicking to process it, causing the… | |
| Aplazada | Alta (7.1) | 0.28% | — | Mrsaucier GooglemapperAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mrsaucier GoogleMapper googlemapper-2 allows Reflected XSS.This issue affects GoogleMapper: from n/a through <= 2.0.3. | |
| Aplazada | Media (5.9) | 0.35% | — | Teplitsa ShmapperAI | 24/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Denis Cherniatev ShMapper by Teplitsa shmapper-by-teplitsa allows Stored XSS.This issue affects ShMapper by Teplitsa: from n/a through <= 1.5.0. | |
| Aplazada | Media (6.4) | 0.28% | — | Teplitsa ShmapperAI | 24/12/2024 | 17/6/2026 | The ShMapper by Teplitsa plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shmMap' shortcode in all versions up to, and including, 1.4.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.1) | 0.33% | — | Maartenhemmes Image MapperAI | 18/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in maartenhemmes Image Mapper image-mapper allows Reflected XSS.This issue affects Image Mapper: from n/a through <= 0.2.5.3. | |
| Modificada | Media (4.3) | 0.31% | — | Imagemapper Project Imagemapper | 7/11/2023 | 17/6/2026 | The ImageMapper plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.6. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to update the plugin settings via a forged request, granted they can… | |
| Modificada | Media (4.3) | 0.21% | — | Imagemapper Project Imagemapper | 7/11/2023 | 17/6/2026 | The ImageMapper plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.6. This is due to missing or incorrect nonce validation on the 'imgmap_save_area_title' function. This makes it possible for unauthenticated attackers to update the post title and inject malicious… | |
| Modificada | Media (5.4) | 0.43% | — | Imagemapper Project Imagemapper | 7/11/2023 | 17/6/2026 | The ImageMapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'imagemap' shortcode in versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above… | |
| Modificada | Media (4.3) | 0.40% | — | Imagemapper Project Imagemapper | 7/11/2023 | 17/6/2026 | The ImageMapper plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'imgmap_delete_area_ajax' function in versions up to, and including, 1.2.6. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete arbitrary posts… | |
| Modificada | Alta (7.8) | 0.22% | — | Redhat Device-mapper-multipathRedhat Enterprise Linux | 29/3/2023 | 17/6/2026 | A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in conjunction with CVE-2022-41973. Local users that are able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This issue… | |
| Modificada | Alta (8.1) | 0.74% | — | Tradr-project TF Remapper | 4/1/2023 | 17/6/2026 | The tf_remapper_node component 1.1.1 for Robot Operating System (ROS) allows attackers, who control the source code of a different node in the same ROS application, to change a robot's behavior. This occurs because a topic name depends on the attacker-controlled old_tf_topic_name and/or new_tf_topic_name parameter.… | |
| Modificada | Crítica (9.8) | 0.90% | — | Mybatis Mapper | 2/9/2022 | 17/6/2026 | Mapper v4.0.0 to v4.2.0 was discovered to contain a SQL injection vulnerability via the ids parameter at the selectByIds function. | |
| Modificada | Media (5.3) | 0.53% | — | B4after Osmapper | 28/3/2022 | 17/6/2026 | The OSMapper WordPress plugin through 2.1.5 contains an AJAX action to delete a plugin related post type named 'map' and is registered with the wp_ajax_nopriv prefix, making it available to unauthenticated users. There is no authorisation, CSRF and checks in place to ensure that the post to delete is a map one. As a… | |
| Modificada | Media (5.3) | 1.3% | — | Philips Dreammapper | 21/8/2020 | 17/6/2026 | Philips DreamMapper, Version 2.24 and prior. Information written to log files can give guidance to a potential attacker. | |
| Modificada | Alta (7.5) | 17% | — | Fasterxml Jackson-mapper-aslRedhat Jboss Enterprise Application PlatformRedhat Jboss FuseDebian Linux+1 | 18/11/2019 | 17/6/2026 | A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes. | |
| Modificada | Crítica (10) | 3.0% | — | SAS XML MapperBase SAS | 14/11/2019 | 17/6/2026 | SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This vulnerability also affects the XMLV2 LIBNAME… | |
| Modificada | Alta (7.8) | 0.38% | — | Zend-cacheDebian LinuxDoctrine-project Object Relational MapperDoctrine-project Doctrinemongodbbundle+6 | 7/6/2016 | 17/6/2026 | Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB ODM Bundle before 3.0.1 use world-writable permissions for cache directories, which allows local users to execute… | |
| Modificada | Baja (2.1) | 0.73% | — | Feed Element Mapper Project Feed Element Mapper | 13/5/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Feed Element Mapper module for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via vectors related to options. | |
| Modificada | Media (6.9) | 0.42% | — | Bluemarblegeo Global Mapper | 26/4/2013 | 16/6/2026 | Multiple untrusted search path vulnerabilities in Global Mapper 14.1.0 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll or (2) ibfs32.dll file in the current working directory, as demonstrated by a directory that contains a .gmc, .gmg, .gmp, .gms, .gmw, or .opt file. | |
| Modificada | Media (4.3) | 1.3% | — | Alex Barth Feed Element Mapper | 1/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Feed Element Mapper module 5.x before 5.x-1.3, 6.x before 6.x-1.3, and 6.x-2.0-alpha before 6.x-2.0-alpha4 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |