Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2625▼ 449 respecto a la semana anterior
Críticas / altas1281▼ 64 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.39% | — | Oceanicsoft ValeappAI | 9/7/2026 | 9/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp allows Stored XSS. This issue affects ValeApp: through 09072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Media (4.3) | 0.19% | — | Outtheboxthemes OceanicAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in outtheboxthemes Oceanic oceanic allows Cross Site Request Forgery.This issue affects Oceanic: from n/a through <= 1.0.48. | |
| Modificada | Crítica (9.3) | 0.27% | — | Oceanicsoft Valeapp | 27/9/2024 | 17/6/2026 | Cleartext Storage of Sensitive Information in a Cookie vulnerability in Oceanic Software ValeApp allows Protocol Manipulation, : JSON Hijacking (aka JavaScript Hijacking). This issue affects ValeApp: before v2.0.0. | |
| Modificada | Crítica (9.3) | 0.46% | — | Oceanicsoft Valeapp | 27/9/2024 | 17/6/2026 | Session Fixation vulnerability in Oceanic Software ValeApp allows Brute Force, Session Hijacking. This issue affects ValeApp: before v2.0.0. | |
| Modificada | Alta (8.8) | 0.47% | — | Oceanicsoft Valeapp | 27/9/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Oceanic Software ValeApp allows Query System for Information. This issue affects ValeApp: before v2.0.0. | |
| Modificada | Alta (7.2) | 0.30% | — | Oceanicsoft Valeapp | 27/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Oceanic Software ValeApp allows Stored XSS. This issue affects ValeApp: before v2.0.0. | |
| Modificada | Alta (8.7) | 0.51% | — | Oceanicsoft Valeapp | 27/9/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oceanic Software ValeApp allows SQL Injection. This issue affects ValeApp: before v2.0.0. | |
| Aplazada | Media (6.5) | 0.55% | — | OceanicAI | 14/5/2024 | 17/6/2026 | Oceanic is a NodeJS library for interfacing with Discord. Prior to version 1.10.4, input to functions such as `Client.rest.channels.removeBan` is not url-encoded, resulting in specially crafted input such as `../../../channels/{id}` being normalized into the url `/api/v10/channels/{id}`, and deleting a channel rather… |