Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2760▲ 27 respecto a la semana anterior
Críticas / altas1467▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 441 respecto a la semana anterior
–

23 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.35%—Pocketmine-mpAIJsonmapperAI9/9/202630/9/2026
PocketMine-MP versions before 4.20.5 contain a denial of service vulnerability in LoginPacket JSON parsing due to improper validation in the JsonMapper dependency. Attackers can send malformed JSON structures in LoginPacket to crash the server.
AplazadaAlta (8.7)0.46%—ReconmapAI21/8/202624/9/2026
Reconmap's API applies a fallback authorization policy in apps/api/app/Program.cs that requires an authenticated user holding the administrator role, so controllers without their own attribute reject anonymous callers. The report preview action in apps/api/app/Controllers/ReportsController.cs carries [AllowAnonymous]…
Pendiente de análisisMedia (6.6)0.43%—Splunk Nmap ScannerAI19/8/202620/8/2026
In Nmap Scanner versions below 3.0.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could run the scan network action in a Safe Mode playbook while that action is listed as read-only, which could allow for command execution or other changes on a target system through Nmap Scripting…
Pendiente de análisisMedia (6.9)0.50%—NmapAI11/8/202624/9/2026
Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash the application by sending a crafted packet containing a zero-length TCP option. The malformed packet forces the Packet:parse_options() function in nselib/packet.lua to allocate objects in an…
Pendiente de análisisMedia (4.8)0.13%—Nmap NpcapAI11/8/202628/8/2026
The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to administrators only. A local user without administrative privileges could use the Npcap driver to capture the traffic…
AnalizadaMedia (6.9)1.5%—Nmap28/6/202630/6/2026
Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the pointer advances past the buffer and the remaining-length computation underflows to a large value. A scanned target or on-path attacker returning a crafted IPv6 response…
AplazadaMedia (6.9)0.12%—NmapAIZenmapAI26/4/202617/6/2026
Nmap 7.70 contains a denial of service vulnerability that allows local attackers to crash the application by processing malicious XML files with exponential entity expansion. Attackers can create a crafted XML file with nested entity definitions and open it through ZenMap's scan import functionality to cause the…
AnalizadaMedia (5.3)4.5%—Phialsbasement MCP Nmap Server3/3/202617/6/2026
A vulnerability was detected in PhialsBasement nmap-mcp-server up to bee6d23547d57ae02460022f7c78ac0893092e38. Affected by this issue is the function child_process.exec of the file src/index.ts of the component Nmap CLI Command Handler. The manipulation results in command injection. The attack may be performed from…
AplazadaCrítica (10)1.9%—Snort ReportAINmapAINbtscanAI13/8/202516/6/2026
Snort Report versions < 1.3.2 contains a remote command execution vulnerability in the nmap.php and nbtscan.php scripts. These scripts fail to properly sanitize user input passed via the target GET parameter, allowing attackers to inject arbitrary shell commands. Exploitation requires no authentication and can result…
AplazadaMedia (6.6)0.28%—Nmap ImporterAIMicrosoft Windows RegistryAI8/4/202417/6/2026
The NMAP Importer service​ may expose data store credentials to authorized users of the Windows Registry.
ModificadaCrítica (9.8)5.5%—Python-libnmap Project Python-libnmap4/5/202217/6/2026
In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client application that does not validate arguments). NOTE: the vendor believes it would be unrealistic for an application to call NmapProcess with arguments taken from input data that arrived over an untrusted…
ModificadaAlta (7.5)3.2%—Nmap29/8/201917/6/2026
nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading \n character to ssh-brute.nse or ssh-auth-methods.nse.
ModificadaAlta (7.5)1.6%—Libnmap15/7/201917/6/2026
libnmap < v0.6.3 is affected by: XML Injection. The impact is: Denial of service (DoS) by consuming resources. The component is: XML Parsing. The attack vector is: Specially crafted XML payload.
ModificadaMedia (5.3)1.6%—Dynmap Project Dynmap28/5/201917/6/2026
In Webbukkit Dynmap 3.0-beta-3 or below, due to a missing login check in servlet/MapStorageHandler.java, an attacker can see a map image without login even if victim enables login-required in setting.
ModificadaAlta (7.8)0.71%—Nmap Npcap24/4/201917/6/2026
An issue was discovered in Npcap 0.992. Sending a malformed .pcap file with the loopback adapter using either pcap_sendqueue_queue() or pcap_sendqueue_transmit() results in kernel pool corruption. This could lead to arbitrary code executing inside the Windows kernel and allow escalation of privileges.
ModificadaCrítica (9.8)3.9%—Libnmap Project Libnmap30/10/201817/6/2026
A command injection vulnerability in libnmapp package for versions <0.4.16 allows arbitrary commands to be executed via arguments to the range options.
ModificadaCrítica (9.8)1.6%—Nmap4j Project Nmap4j19/9/201817/6/2026
nmap4j 1.1.0 allows attackers to execute arbitrary commands via shell metacharacters in an includeHosts call.
ModificadaAlta (7.5)6.1%—Nmap8/8/201817/6/2026
Nmap through 7.70, when the -sV option is used, allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted TCP-based service.
ModificadaMedia (5.7)1.0%—Nmap18/4/201817/6/2026
nmap version 6.49BETA6 through 7.60, up to and including SVN revision 37147 contains a Directory Traversal vulnerability in NSE script http-fetch that can result in file overwrite as the user is running it. This attack appears to be exploitable via a victim that runs NSE script http-fetch against a malicious web site.…
ModificadaMedia (6.8)7.2%—NmapOpensuse26/10/201316/6/2026
The http-domino-enum-passwords.nse script in NMap before 6.40, when domino-enum-passwords.idpath is set, allows remote servers to upload "arbitrarily named" files via a crafted FullName parameter in a response, as demonstrated using directory traversal sequences.
ModificadaMedia (6)2.0%—Baconmap27/4/201116/6/2026
Directory traversal vulnerability in admin/updatelist.php in BaconMap 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the filepath parameter.
ModificadaAlta (7.5)1.2%—Baconmap27/4/201116/6/2026
SQL injection vulnerability in doadd.php in BaconMap 1.0 allows remote attackers to execute arbitrary SQL commands via the type parameter.
ModificadaAlta (8.3)1.9%—HP Procurve Access Point SoftwareHP Procurve M110 Access PointHP Procurve Miltope Dual Radio Access PointHP Procurve Msm310-r Access Point+1418/10/201016/6/2026
Unspecified vulnerability on HP ProCurve Access Points, Access Controllers, and Mobility Controllers with software 5.1.x through 5.1.9, 5.2.x through 5.2.7, 5.3.x through 5.3.5, and 5.4.x through 5.4.0 allows remote attackers to execute arbitrary code via unknown vectors.