Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3019▲ 545 respecto a la semana anterior
Críticas / altas1439▲ 265 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.4) | 0.27% | — | Openjsf MarkoOpenjsf Marko/runtime-tags | 8/5/2026 | 26/8/2026 | Marko is a declarative, HTML-based language for building web apps. Prior to marko version 5.38.36 and prior to @marko/runtime-tags 6.0.164, when dynamic text is interpolated into a <script> or <style> tag the Marko runtime failed to prevent tag breakout when the closing tag used non-lowercase casing. An attacker able… | |
| Aplazada | Media (6.5) | 0.17% | — | Maksym Marko MX Time Zone ClocksAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maksym Marko MX Time Zone Clocks mx-time-zone-clocks allows Stored XSS.This issue affects MX Time Zone Clocks: from n/a through <= 5.1.1. | |
| Aplazada | Media (6.5) | 0.35% | — | Maksym Marko MX Time Zone ClocksAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maksym Marko MX Time Zone Clocks mx-time-zone-clocks allows Reflected XSS.This issue affects MX Time Zone Clocks: from n/a through <= 5.1.1. | |
| Aplazada | Crítica (9.8) | 0.73% | — | Marko-m Quick CountAI | 22/1/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Marko-M Quick Count quick-count allows Object Injection.This issue affects Quick Count: from n/a through <= 3.00. | |
| Aplazada | Alta (8.5) | 0.40% | — | Maksym Marko Website Price CalculatorAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Maksym Marko Website price calculator price-calculator-to-your-website allows SQL Injection.This issue affects Website price calculator: from n/a through <= 4.1. | |
| Modificada | Crítica (9.3) | 0.47% | — | Markoni-d (compact) FirmwareMarkoni-dh (exciter+amplifiers) Firmware | 27/6/2024 | 17/6/2026 | TELSAT marKoni FM Transmitters are vulnerable to users gaining unauthorized access to sensitive information or performing actions beyond their designated permissions. | |
| Modificada | Crítica (9.3) | 0.57% | — | Markoni-d (compact) FirmwareMarkoni-dh (exciter+amplifiers) Firmware | 27/6/2024 | 17/6/2026 | TELSAT marKoni FM Transmitters are vulnerable to an attacker bypassing authentication and gaining administrator privileges. | |
| Modificada | Crítica (9.3) | 0.52% | — | Markoni-d (compact) FirmwareMarkoni-dh (exciter+amplifiers) Firmware | 27/6/2024 | 17/6/2026 | TELSAT marKoni FM Transmitters are vulnerable to an attacker exploiting a hidden admin account that can be accessed through the use of hard-coded credentials. | |
| Modificada | Crítica (9.3) | 1.2% | — | Markoni-d (compact) FirmwareMarkoni-dh (exciter+amplifiers) Firmware | 27/6/2024 | 17/6/2026 | TELSAT marKoni FM Transmitters are vulnerable to a command injection vulnerability through the manipulation of settings and could allow an attacker to gain unauthorized access to the system with administrative privileges. | |
| Modificada | Alta (7.5) | 2.1% | — | Stavros Markou Atmelwlandriver | 31/12/2006 | 16/6/2026 | Buffer overflow in the Get_Wep function in cofvnet.c for ATMEL Linux PCI PCMCIA USB Drivers drivers 3.4.1.1 corruption allows attackers to execute arbitrary code via a long name argument. |