Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

19 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.46%—Getgrav GravAINeos FormAI15/7/202615/7/2026
Grav before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename parameter, which is validated against path traversal before Twig processing but never re-validated after rendering. Attackers can submit form data containing path traversal sequences that are processed through…
AplazadaBaja (2.2)0.12%—GrapheneosAI9/5/202624/7/2026
GrapheneOS before 2026050400 allows attackers to discover the real IP address of a VPN user as a consequence of a registerQuicConnectionClosePayload optimization, because an application can let system_server transmit UDP traffic on its behalf. This occurs when the "Block connections without VPN" and "Always-on VPN"…
AplazadaMedia (4.3)0.19%—Neos Connector FOR FakturamaAI21/3/202617/6/2026
The Neos Connector for Fakturama plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.0.14. This is due to missing nonce validation in the ncff_add_plugin_page() function which handles settings updates. This makes it possible for unauthenticated attackers to modify…
AplazadaAlta (8.6)0.78%—Neoslab Database ToolsetAI11/4/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in neoslab Database Toolset database-toolset allows Path Traversal.This issue affects Database Toolset: from n/a through <= 1.8.4.
ModificadaMedia (5.4)0.71%—Neos CMS18/9/202317/6/2026
Cross Site Scripting (XSS) vulnerability in Neos CMS 8.3.3 allows a remote authenticated attacker to execute arbitrary code via a crafted SVG file to the neos/management/media component.
ModificadaMedia (6.1)0.48%—Ualberta Neosdiscovery5/3/202317/6/2026
A vulnerability was found in ualbertalib NEOSDiscovery 1.0.70 and classified as problematic. This issue affects some unknown processing of the file app/views/bookmarks/_refworks.html.erb. The manipulation leads to use of web link to untrusted target with window.opener access. The attack may be initiated remotely.…
ModificadaMedia (5.4)0.59%—Neos CMS2/6/202217/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Neos CMS allow attackers with the editor role or higher to inject arbitrary script or HTML code using the editor function, the deletion of assets, or a workspace title. The vulnerabilities were found in versions 3.3.29 and 8.0.1 and could also be present in all…
ModificadaMedia (5.3)1.1%—Neos Form21/6/202117/6/2026
neos/forms is an open source framework to build web forms. By crafting a special `GET` request containing a valid form state, a form can be submitted without invoking any validators. Form state is secured with an HMAC that is still verified. That means that this issue can only be exploited if Form Finishers cause side…
ModificadaCrítica (9.8)2.2%—Dynamicpress Neosense13/9/201917/6/2026
The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload.
ModificadaMedia (6.5)0.89%—Typo3 Neos1/4/201517/6/2026
TYPO3 Neos 1.1.x before 1.1.3 and 1.2.x before 1.2.3 allows remote editors to access, create, and modify content nodes in the workspace of other editors via unspecified vectors.
ModificadaAlta (7.8)9.7%💥 ExploitTP Neostrada Livebox Adsl Router20/3/200916/6/2026
The Neostrada Livebox ADSL Router allows remote attackers to cause a denial of service (network outage) via multiple HTTP requests for the /- URI.
ModificadaMedia (4.9)0.81%—Neoscale Systems Cryptostor Tape 70019/12/200616/6/2026
The NeoScale Systems CryptoStor 700 series appliance before 2.6 relies on client-side ActiveX code for smartcard authentication, which allows remote attackers to bypass smartcard authentication, and gain access if able to present a valid username and password, by disabling ActiveX.
ModificadaMedia (5)8.1%💥 ExploitNeosys Neon Webmail23/9/200616/6/2026
Directory traversal vulnerability in the downloadfile servlet in Neon WebMail for Java before 5.08 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the (1) savefolder and (2) savefilename parameters.
ModificadaAlta (7.5)8.0%💥 ExploitNeosys Neon Webmail23/9/200616/6/2026
The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote attackers to modify information of arbitrary users, as demonstrated by modifying (1) passwords and (2) permissions, (3) viewing profile settings, and (4) creating and (5) deleting users.
ModificadaAlta (7.5)3.8%💥 ExploitNeosys Neon Webmail23/9/200616/6/2026
Multiple SQL injection vulnerabilities in Neon WebMail for Java before 5.08 allow remote attackers to execute arbitrary SQL commands via the (1) adr_sortkey and (2) adr_sortkey_desc parameters in the (a) addrlist servlet, and the (3) sortkey and (4) sortkey_desc parameters in the (b) maillist servlet.
ModificadaMedia (6.8)4.8%💥 ExploitNeosys Neon Webmail23/9/200616/6/2026
Cross-site scripting (XSS) vulnerability in the updateuser servlet in Neon WebMail for Java before 5.08 allows remote attackers to inject arbitrary web script or HTML via the in_name parameter, as used by the Name field.
ModificadaAlta (7.5)8.0%💥 ExploitNeosys Neon Webmail23/9/200616/6/2026
The updatemail servlet in Neon WebMail for Java before 5.08 allows remote attackers to move e-mail messages of arbitrary users between different mail folders, specified by the folderid and tofolderid parameters, via the ID parameter.
ModificadaAlta (7.5)2.6%—Neosys Neon Webmail23/9/200616/6/2026
Neon WebMail for Java before 5.08 allows remote attackers to execute arbitrary Java (JSP) code by sending an e-mail message with a JSP file attachment, which is stored under the web root with a predictable filename.
ModificadaMedia (5.8)1.1%—Neosoft Neobook31/12/200216/6/2026
The NBActiveX.ocx ActiveX control in NeoBook 4 allows remote attackers to install and execute arbitrary programs.
Orbitaley — Vulnerabilidades