Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2818▲ 71 respecto a la semana anterior
Críticas / altas1488▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.46% | — | Monkeysaudio Monkey S AudioAI | 28/10/2025 | 17/6/2026 | An out-of-bounds read vulnerability has been discovered in Monkey's Audio 11.31, specifically in the CAPECharacterHelper::GetUTF16FromUTF8 function. The issue arises from improper handling of the length of the input UTF-8 string, causing the function to read past the memory boundary. This vulnerability may result in a… | |
| Modificada | Alta (7.5) | 0.37% | — | Linuxfoundation Nats-serverNats Nkeys | 31/10/2023 | 17/6/2026 | NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The cryptographic key handling library, nkeys, recently gained support for encryption, not just for signing/authentication. This is used in nats-server 2.10 (Sep 2023) and… | |
| Modificada | Crítica (9.8) | 1.1% | — | Twelvemonkeys Project Twelvemonkeys | 6/5/2022 | 17/6/2026 | The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 are vulnerable to XML External Entity (XXE) Injection due to an insecurely initialized XML parser for reading XMP Metadata. An attacker can exploit this vulnerability if they are able to supply a file (e.g. when an online profile picture is processed)… | |
| Modificada | Media (4.3) | 0.98% | — | Monkeysaudio Monkey's Audio | 20/5/2011 | 16/6/2026 | Monkey's Audio before 4.02 allows remote attackers to cause a denial of service (application crash) via a malformed APE file. | |
| Modificada | Media (4.3) | 0.98% | — | Monkeysaudio Monkey's Audio | 20/5/2011 | 16/6/2026 | Monkey's Audio before 4.01b2 allows remote attackers to cause a denial of service (application crash) via an APX file that lacks NULL termination. | |
| Modificada | Media (4.6) | 0.48% | — | Monkeysphere Project Monkeysphere | 27/10/2010 | 16/6/2026 | share/ma/keys_for_user in Monkeysphere 0.31 and 0.32 allows local users to execute arbitrary code via unknown manipulations related to the "monkeysphere-authentication keys-for-user" command. | |
| Modificada | Media (4.3) | 1.4% | — | Veridis Openkeyserver | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the lookup script in Veridis OpenKeyServer (OKS) 1.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter. |