Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.46% | — | Getgrav GravAINeos FormAI | 15/7/2026 | 15/7/2026 | Grav before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename parameter, which is validated against path traversal before Twig processing but never re-validated after rendering. Attackers can submit form data containing path traversal sequences that are processed through… | |
| Aplazada | Baja (2.2) | 0.12% | — | GrapheneosAI | 9/5/2026 | 24/7/2026 | GrapheneOS before 2026050400 allows attackers to discover the real IP address of a VPN user as a consequence of a registerQuicConnectionClosePayload optimization, because an application can let system_server transmit UDP traffic on its behalf. This occurs when the "Block connections without VPN" and "Always-on VPN"… | |
| Aplazada | Media (4.3) | 0.19% | — | Neos Connector FOR FakturamaAI | 21/3/2026 | 17/6/2026 | The Neos Connector for Fakturama plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.0.14. This is due to missing nonce validation in the ncff_add_plugin_page() function which handles settings updates. This makes it possible for unauthenticated attackers to modify… | |
| Aplazada | Alta (8.6) | 0.78% | — | Neoslab Database ToolsetAI | 11/4/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in neoslab Database Toolset database-toolset allows Path Traversal.This issue affects Database Toolset: from n/a through <= 1.8.4. | |
| Modificada | Media (5.4) | 0.71% | — | Neos CMS | 18/9/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Neos CMS 8.3.3 allows a remote authenticated attacker to execute arbitrary code via a crafted SVG file to the neos/management/media component. | |
| Modificada | Media (6.1) | 0.48% | — | Ualberta Neosdiscovery | 5/3/2023 | 17/6/2026 | A vulnerability was found in ualbertalib NEOSDiscovery 1.0.70 and classified as problematic. This issue affects some unknown processing of the file app/views/bookmarks/_refworks.html.erb. The manipulation leads to use of web link to untrusted target with window.opener access. The attack may be initiated remotely.… | |
| Modificada | Media (5.4) | 0.59% | — | Neos CMS | 2/6/2022 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Neos CMS allow attackers with the editor role or higher to inject arbitrary script or HTML code using the editor function, the deletion of assets, or a workspace title. The vulnerabilities were found in versions 3.3.29 and 8.0.1 and could also be present in all… | |
| Modificada | Media (5.3) | 1.1% | — | Neos Form | 21/6/2021 | 17/6/2026 | neos/forms is an open source framework to build web forms. By crafting a special `GET` request containing a valid form state, a form can be submitted without invoking any validators. Form state is secured with an HMAC that is still verified. That means that this issue can only be exploited if Form Finishers cause side… | |
| Modificada | Crítica (9.8) | 2.2% | — | Dynamicpress Neosense | 13/9/2019 | 17/6/2026 | The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload. | |
| Modificada | Media (6.5) | 0.89% | — | Typo3 Neos | 1/4/2015 | 17/6/2026 | TYPO3 Neos 1.1.x before 1.1.3 and 1.2.x before 1.2.3 allows remote editors to access, create, and modify content nodes in the workspace of other editors via unspecified vectors. | |
| Modificada | Alta (7.8) | 9.7% | 💥 Exploit | TP Neostrada Livebox Adsl Router | 20/3/2009 | 16/6/2026 | The Neostrada Livebox ADSL Router allows remote attackers to cause a denial of service (network outage) via multiple HTTP requests for the /- URI. | |
| Modificada | Media (4.9) | 0.81% | — | Neoscale Systems Cryptostor Tape 700 | 19/12/2006 | 16/6/2026 | The NeoScale Systems CryptoStor 700 series appliance before 2.6 relies on client-side ActiveX code for smartcard authentication, which allows remote attackers to bypass smartcard authentication, and gain access if able to present a valid username and password, by disabling ActiveX. | |
| Modificada | Media (5) | 8.1% | 💥 Exploit | Neosys Neon Webmail | 23/9/2006 | 16/6/2026 | Directory traversal vulnerability in the downloadfile servlet in Neon WebMail for Java before 5.08 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the (1) savefolder and (2) savefilename parameters. | |
| Modificada | Alta (7.5) | 8.0% | 💥 Exploit | Neosys Neon Webmail | 23/9/2006 | 16/6/2026 | The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote attackers to modify information of arbitrary users, as demonstrated by modifying (1) passwords and (2) permissions, (3) viewing profile settings, and (4) creating and (5) deleting users. | |
| Modificada | Alta (7.5) | 3.8% | 💥 Exploit | Neosys Neon Webmail | 23/9/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Neon WebMail for Java before 5.08 allow remote attackers to execute arbitrary SQL commands via the (1) adr_sortkey and (2) adr_sortkey_desc parameters in the (a) addrlist servlet, and the (3) sortkey and (4) sortkey_desc parameters in the (b) maillist servlet. | |
| Modificada | Media (6.8) | 4.8% | 💥 Exploit | Neosys Neon Webmail | 23/9/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the updateuser servlet in Neon WebMail for Java before 5.08 allows remote attackers to inject arbitrary web script or HTML via the in_name parameter, as used by the Name field. | |
| Modificada | Alta (7.5) | 8.0% | 💥 Exploit | Neosys Neon Webmail | 23/9/2006 | 16/6/2026 | The updatemail servlet in Neon WebMail for Java before 5.08 allows remote attackers to move e-mail messages of arbitrary users between different mail folders, specified by the folderid and tofolderid parameters, via the ID parameter. | |
| Modificada | Alta (7.5) | 2.6% | — | Neosys Neon Webmail | 23/9/2006 | 16/6/2026 | Neon WebMail for Java before 5.08 allows remote attackers to execute arbitrary Java (JSP) code by sending an e-mail message with a JSP file attachment, which is stored under the web root with a predictable filename. | |
| Modificada | Media (5.8) | 1.1% | — | Neosoft Neobook | 31/12/2002 | 16/6/2026 | The NBActiveX.ocx ActiveX control in NeoBook 4 allows remote attackers to install and execute arbitrary programs. |