Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
94 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.66% | — | GopacketAI | 7/8/2026 | 9/9/2026 | gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-controlled lengths, counts, or offsets before validating them against packet buffers, allowing a crafted packet decoded through DecodingLayerParser or DecodeFromBytes to trigger an unrecovered panic and… | |
| Analizada | Media (6.9) | 0.79% | — | Gopacket | 28/7/2026 | 5/8/2026 | gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data length by subtracting a fixed header size from an attacker-controlled AVP Length field, so a vendor-flagged AVP whose Length is smaller than the 12-byte header underflows the unsigned… | |
| Analizada | Media (6.9) | 0.79% | — | Gopacket | 28/7/2026 | 5/8/2026 | gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow decoder in layers/sflow.go reads an attacker-controlled 32-bit community count and AS path member count and sizes a slice allocation from those counts without bounding them against the bytes remaining… | |
| Pendiente de análisis | Alta (7.5) | 0.60% | — | Facebook React-server-dom-webpackAIFacebook React-server-dom-parcelAIFacebook React-server-dom-turbopackAI | 21/7/2026 | 21/7/2026 | A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.7, 19.1.0… | |
| Analizada | Alta (7.5) | 1.5% | — | Facebook React-server-dom-parcelFacebook React-server-dom-turbopackFacebook React-server-dom-webpack | 6/5/2026 | 12/8/2026 | A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel,… | |
| Pendiente de análisis | Alta (7.5) | 1.6% | — | Facebook React-server-dom-parcelAIFacebook React-server-dom-turbopackAIFacebook React-server-dom-webpackAI | 8/4/2026 | 25/7/2026 | A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, and 19.2.0 through 19.2.4). The vulnerability is triggered by sending specially… | |
| Aplazada | Media (5.3) | 0.31% | — | NitropackAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in NitroPack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NitroPack: from n/a through 1.19.3. | |
| Aplazada | Alta (8.9) | 4.3% | — | Topsec TopacmAI | 16/3/2026 | 17/6/2026 | A weakness has been identified in Topsec TopACM 3.0. Affected by this vulnerability is an unknown functionality of the file /view/systemConfig/management/nmc_sync.php of the component HTTP Request Handler. Executing a manipulation of the argument template_path can lead to os command injection. The attack can be… | |
| Aplazada | Media (4.3) | 0.25% | — | NitropackAI | 10/9/2025 | 17/6/2026 | The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the nitropack_set_compression_ajax() function in all versions up to, and including, 1.18.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update… | |
| Aplazada | Crítica (9.3) | 1.1% | — | Amlib NetopacsAIMicrosoft IISAI | 21/8/2025 | 16/6/2026 | Amlib’s NetOpacs webquery.dll contains a stack-based buffer overflow vulnerability triggered by improper handling of HTTP GET parameters. Specifically, the application fails to enforce bounds on input supplied to the app parameter, allowing excessive data to overwrite memory structures including the Structured… | |
| Aplazada | Media (6.5) | 0.17% | — | Kylegilman VideopackAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kyle Gilman Videopack video-embed-thumbnail-generator allows DOM-Based XSS.This issue affects Videopack: from n/a through <= 4.10.3. | |
| Aplazada | Alta (7.5) | 0.55% | — | Autolib Software Systems OpacAI | 28/1/2025 | 17/6/2026 | AutoLib Software Systems OPAC v20.10 was discovered to have multiple API keys exposed within the source code. Attackers may use these keys to access the backend API or other sensitive information. | |
| Aplazada | Media (4.3) | 0.28% | — | NitropackAI | 15/1/2025 | 17/6/2026 | The NitroPack plugin for WordPress is vulnerable to unauthorized arbitrary transient update due to a missing capability check on the nitropack_rml_notification function in all versions up to, and including, 1.17.0. This makes it possible for authenticated attackers, with subscriber access or higher, to update… | |
| Aplazada | Alta (8.1) | 0.67% | — | NitropackAI | 15/1/2025 | 17/6/2026 | The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nitropack_dismiss_notice_forever' AJAX action in all versions up to, and including, 1.17.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Analizada | Media (5.4) | 0.29% | — | Vice Webopac | 11/11/2024 | 17/6/2026 | Webopac from Grand Vice info has Stored Cross-site Scripting vulnerability. Remote attackers with regular privileges can inject arbitrary JavaScript code into the server. When users visit the compromised page, the code is automatically executed in their browser. | |
| Analizada | Crítica (9.8) | 0.47% | — | Vice Webopac | 11/11/2024 | 17/6/2026 | Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Analizada | Media (6.1) | 0.33% | — | Vice Webopac | 11/11/2024 | 17/6/2026 | Webopac from Grand Vice info has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript code in the user's browser through phishing techniques. | |
| Analizada | Crítica (9.8) | 0.83% | — | Vice Webopac | 11/11/2024 | 17/6/2026 | Webopac from Grand Vice info does not properly validate uploaded file types, allowing unauthenticated remote attackers to upload and execute webshells, which could lead to arbitrary code execution on the server. | |
| Analizada | Alta (8.8) | 0.77% | — | Vice Webopac | 11/11/2024 | 17/6/2026 | Webopac from Grand Vice info does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells, which could lead to arbitrary code execution on the server. | |
| Analizada | Crítica (9.8) | 0.56% | — | Vice Webopac | 11/11/2024 | 17/6/2026 | Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Analizada | Crítica (9.8) | 0.35% | — | Nitropack | 29/8/2024 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in NitroPack Inc. NitroPack allows Code Injection.This issue affects NitroPack: from n/a through 1.16.7. | |
| Modificada | Media (5.3) | 0.76% | — | Sokrates Sowa Opac | 1/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation vulnerability in SOKRATES-software SOWA OPAC allows a Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. This issue affects SOWA OPAC software in versions… | |
| Aplazada | Alta (8.4) | 0.29% | — | Gehealthcare EchopacAI | 14/5/2024 | 17/6/2026 | Elevation of privilege vulnerability in GE HealthCare EchoPAC products | |
| Aplazada | Alta (7.6) | 0.34% | — | Gehealthcare EchopacAI | 14/5/2024 | 17/6/2026 | Insufficiently protected credentials in GE HealthCare EchoPAC products | |
| Aplazada | Media (6.8) | 0.34% | — | Gehealthcare EchopacAI | 14/5/2024 | 17/6/2026 | Non privileged access to critical file vulnerability in GE HealthCare EchoPAC products |