Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

94 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.66%—GopacketAI7/8/20269/9/2026
gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-controlled lengths, counts, or offsets before validating them against packet buffers, allowing a crafted packet decoded through DecodingLayerParser or DecodeFromBytes to trigger an unrecovered panic and…
AnalizadaMedia (6.9)0.79%—Gopacket28/7/20265/8/2026
gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data length by subtracting a fixed header size from an attacker-controlled AVP Length field, so a vendor-flagged AVP whose Length is smaller than the 12-byte header underflows the unsigned…
AnalizadaMedia (6.9)0.79%—Gopacket28/7/20265/8/2026
gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow decoder in layers/sflow.go reads an attacker-controlled 32-bit community count and AS path member count and sizes a slice allocation from those counts without bounding them against the bytes remaining…
Pendiente de análisisAlta (7.5)0.60%—Facebook React-server-dom-webpackAIFacebook React-server-dom-parcelAIFacebook React-server-dom-turbopackAI21/7/202621/7/2026
A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.7, 19.1.0…
AnalizadaAlta (7.5)1.5%—Facebook React-server-dom-parcelFacebook React-server-dom-turbopackFacebook React-server-dom-webpack6/5/202612/8/2026
A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel,…
Pendiente de análisisAlta (7.5)1.6%—Facebook React-server-dom-parcelAIFacebook React-server-dom-turbopackAIFacebook React-server-dom-webpackAI8/4/202625/7/2026
A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, and 19.2.0 through 19.2.4). The vulnerability is triggered by sending specially…
AplazadaMedia (5.3)0.31%—NitropackAI8/4/202624/7/2026
Missing Authorization vulnerability in NitroPack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NitroPack: from n/a through 1.19.3.
AplazadaAlta (8.9)4.3%—Topsec TopacmAI16/3/202617/6/2026
A weakness has been identified in Topsec TopACM 3.0. Affected by this vulnerability is an unknown functionality of the file /view/systemConfig/management/nmc_sync.php of the component HTTP Request Handler. Executing a manipulation of the argument template_path can lead to os command injection. The attack can be…
AplazadaMedia (4.3)0.25%—NitropackAI10/9/202517/6/2026
The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the nitropack_set_compression_ajax() function in all versions up to, and including, 1.18.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update…
AplazadaCrítica (9.3)1.1%—Amlib NetopacsAIMicrosoft IISAI21/8/202516/6/2026
Amlib’s NetOpacs webquery.dll contains a stack-based buffer overflow vulnerability triggered by improper handling of HTTP GET parameters. Specifically, the application fails to enforce bounds on input supplied to the app parameter, allowing excessive data to overwrite memory structures including the Structured…
AplazadaMedia (6.5)0.17%—Kylegilman VideopackAI16/7/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kyle Gilman Videopack video-embed-thumbnail-generator allows DOM-Based XSS.This issue affects Videopack: from n/a through <= 4.10.3.
AplazadaAlta (7.5)0.55%—Autolib Software Systems OpacAI28/1/202517/6/2026
AutoLib Software Systems OPAC v20.10 was discovered to have multiple API keys exposed within the source code. Attackers may use these keys to access the backend API or other sensitive information.
AplazadaMedia (4.3)0.28%—NitropackAI15/1/202517/6/2026
The NitroPack plugin for WordPress is vulnerable to unauthorized arbitrary transient update due to a missing capability check on the nitropack_rml_notification function in all versions up to, and including, 1.17.0. This makes it possible for authenticated attackers, with subscriber access or higher, to update…
AplazadaAlta (8.1)0.67%—NitropackAI15/1/202517/6/2026
The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nitropack_dismiss_notice_forever' AJAX action in all versions up to, and including, 1.17.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to…
AnalizadaMedia (5.4)0.29%—Vice Webopac11/11/202417/6/2026
Webopac from Grand Vice info has Stored Cross-site Scripting vulnerability. Remote attackers with regular privileges can inject arbitrary JavaScript code into the server. When users visit the compromised page, the code is automatically executed in their browser.
AnalizadaCrítica (9.8)0.47%—Vice Webopac11/11/202417/6/2026
Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitrary SQL commands to read, modify, and delete database contents.
AnalizadaMedia (6.1)0.33%—Vice Webopac11/11/202417/6/2026
Webopac from Grand Vice info has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript code in the user's browser through phishing techniques.
AnalizadaCrítica (9.8)0.83%—Vice Webopac11/11/202417/6/2026
Webopac from Grand Vice info does not properly validate uploaded file types, allowing unauthenticated remote attackers to upload and execute webshells, which could lead to arbitrary code execution on the server.
AnalizadaAlta (8.8)0.77%—Vice Webopac11/11/202417/6/2026
Webopac from Grand Vice info does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells, which could lead to arbitrary code execution on the server.
AnalizadaCrítica (9.8)0.56%—Vice Webopac11/11/202417/6/2026
Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitrary SQL commands to read, modify, and delete database contents.
AnalizadaCrítica (9.8)0.35%—Nitropack29/8/202417/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in NitroPack Inc. NitroPack allows Code Injection.This issue affects NitroPack: from n/a through 1.16.7.
ModificadaMedia (5.3)0.76%—Sokrates Sowa Opac1/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation vulnerability in SOKRATES-software SOWA OPAC allows a Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. This issue affects SOWA OPAC software in versions…
AplazadaAlta (8.4)0.29%—Gehealthcare EchopacAI14/5/202417/6/2026
Elevation of privilege vulnerability in GE HealthCare EchoPAC products
AplazadaAlta (7.6)0.34%—Gehealthcare EchopacAI14/5/202417/6/2026
Insufficiently protected credentials in GE HealthCare EchoPAC products
AplazadaMedia (6.8)0.34%—Gehealthcare EchopacAI14/5/202417/6/2026
Non privileged access to critical file vulnerability in GE HealthCare EchoPAC products