Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.64% | — | M1k1o Neko | 21/4/2026 | 17/6/2026 | Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1, any authenticated user can immediately obtain full administrative control of the entire Neko instance (member management, room settings, broadcast control, session termination, etc.).… | |
| Modificada | Alta (7.5) | 2.1% | — | Cyberneko Html Project Cyberneko HtmlHtmlunitAntisamy Project Antisamy | 21/4/2022 | 17/6/2026 | Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes excessive heap memory consumption. In particular, this issue exists in HtmlUnit-Neko through 2.26, and is fixed in 2.27. This issue also exists in CyberNeko HTML through 1.9.22 (also affecting OWASP… | |
| Modificada | Alta (7.5) | 2.1% | — | Nekohtml Project NekohtmlOracle Weblogic Server | 11/4/2022 | 17/6/2026 | org.cyberneko.html is an html parser written in Java. The fork of `org.cyberneko.html` used by Nokogiri (Rubygem) raises a `java.lang.OutOfMemoryError` exception when parsing ill-formed HTML markup. Users are advised to upgrade to `>= 1.9.22.noko2`. Note: The upstream library `org.cyberneko.html` is no longer… | |
| Modificada | Alta (7.5) | 8.8% | — | Geneko Gwr352 3G Router FirmwareGeneko Gwr352wv Wide Voltage 3G Router FirmwareGeneko Gwr252 Edge Router FirmwareGeneko Gwr202 Gprs Router Firmware | 19/7/2017 | 17/6/2026 | Geneko GWR routers allow directory traversal sequences starting with a /../ substring, as demonstrated by unauthenticated read access to the configuration file. | |
| Modificada | Alta (7.5) | 3.4% | — | Isamu Kaneko Winny | 25/8/2010 | 16/6/2026 | Multiple buffer overflows in Winny 2.0b7.1 and earlier might allow remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2006-2007. |