Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 296 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
29 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.3) | 0.18% | — | Orca Heat PumpAIOrcaAI | 1/6/2026 | 22/7/2026 | Missing authentication and clear‑text transmission of data from the heat pumps to the control server, combined with the absence of input validation on aggregated data, can lead to stored XSS that enables theft of cookies from the pump’s web control interface. Older Orca heat pump devices communicating with the Orca… | |
| Aplazada | Crítica (9.1) | 0.40% | — | Spinnaker ClouddriverAISpinnaker OrcaAI | 17/3/2026 | 17/6/2026 | ### Impact Spinnaker updated URL Validation logic on user input to provide sanitation on user inputted URLs for clouddriver. However, they missed that Java URL objects do not correctly handle underscores on parsing. This led to a bypass of the previous CVE (CVE-2025-61916) through the use of carefully crafted URLs.… | |
| Analizada | Media (5.3) | 0.19% | — | Algonet Orcastatllm Researcher | 6/2/2026 | 17/6/2026 | OrcaStatLLM Researcher is an LLM Based Research Paper Generator. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Log Message in the Session Page in OrcaStatLLM-Researcher that allows attackers to inject and execute arbitrary JavaScript code in victims' browsers through malicious research topic… | |
| Analizada | Alta (7) | 0.15% | — | Sevencs Ec2007 KernelSevencs Orca G2 | 31/12/2025 | 17/6/2026 | A local privilege escalation vulnerability exists in SevenCs ORCA G2 2.0.1.35 (EC2007 Kernel v5.22). The flaw is a Time-of-Check Time-of-Use (TOCTOU) race condition in the license management logic. The regService process, which runs with SYSTEM privileges, creates a fixed directory and writes files without verifying… | |
| Analizada | Alta (7.8) | 0.15% | — | Sevencs Ec2007 KernelSevencs Orca G2 | 31/12/2025 | 28/9/2026 | An incorrect NULL DACL issue exists in SevenCs ORCA G2 2.0.1.35 (EC2007 Kernel v5.22). The regService process, which runs with SYSTEM privileges, applies a Security Descriptor to a device object with no explicitly configured DACL. This condition could allow an attacker to perform unauthorized raw disk operations,… | |
| Analizada | Alta (8.8) | 0.51% | — | Learningdigital Orca HCM | 17/2/2025 | 17/6/2026 | Orca HCM from Learning Digital has a SQL Injection vulnerability, allowing attackers with regular privileges to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Analizada | Alta (8.8) | 0.52% | — | Learningdigital Orca HCM | 17/2/2025 | 17/6/2026 | Orca HCM from LEARNING DIGITAL has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and run web shells | |
| Analizada | Crítica (9.8) | 0.58% | — | Learningdigital Orca HCM | 17/2/2025 | 17/6/2026 | Orca HCM from LEARNING DIGITAL has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to log in to the system as any user. | |
| Analizada | Media (5.3) | 0.33% | — | Opensuse Mirrorcache | 13/11/2024 | 17/6/2026 | A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in openSUSE Tumbleweed MirrorCache allows the execution of arbitrary JS via reflected XSS in the REGEX and P parameters. This issue affects MirrorCache before 1.083. | |
| Analizada | Media (6.5) | 0.67% | — | Learningdigital Orca HCM | 9/9/2024 | 17/6/2026 | Orca HCM from LEARNING DIGITA does not properly restrict a specific parameter of the file download functionality, allowing a remote attacker with regular privileges to download arbitrary system files. | |
| Modificada | Crítica (9.8) | 0.68% | — | Learningdigital Orca HCM | 9/9/2024 | 17/6/2026 | Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege and subsequently use it to log in. | |
| Modificada | Alta (8.8) | 0.82% | — | Eufylife Solo Indoorcam C24 FirmwareEufylife Solo Indoorcam P24 Firmware | 31/5/2022 | 17/6/2026 | A Buffer Overflow vulnerability in the RSTP server component of Eufy Indoor 2K Indoor Camera allows a local attacker to achieve remote code execution. This issue affects: Eufy Indoor 2K Indoor Camera 2.0.9.3 version and prior versions. | |
| Modificada | Media (4.3) | 1.0% | — | Learningdigital Orca HCM | 19/7/2021 | 17/6/2026 | The directory list page parameter of the Orca HCM digital learning platform fails to filter special characters properly. Remote attackers can access the system directory thru Path Traversal with users’ privileges. | |
| Modificada | Media (5.3) | 1.3% | — | Learningdigital Orca HCM | 19/7/2021 | 17/6/2026 | The directory page parameter of the Orca HCM digital learning platform does not filter special characters. Remote attackers can access the system directory thru Path Traversal without logging in. | |
| Modificada | Media (6.1) | 0.82% | — | Learningdigital Orca HCM | 19/7/2021 | 17/6/2026 | The specific function of the Orca HCM digital learning platform does not filter input parameters properly, which causing the URL can be redirected to any website. Remote attackers can use the vulnerability to execute phishing attacks. | |
| Modificada | Crítica (9.8) | 2.4% | — | Learningdigital Orca HCM | 19/7/2021 | 17/6/2026 | The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the source code of the webpage in plain text, thus remote attackers can obtain administrator’s privilege without logging in. | |
| Modificada | Crítica (9.8) | 1.1% | — | Learningdigital Orca HCM | 19/7/2021 | 17/6/2026 | The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remote attackers to execute the management function without logging in, access members’ information, modify and delete the courses in system, thus causing users fail to access the learning content. | |
| Modificada | Crítica (9.8) | 2.4% | — | Learningdigital Orca HCM | 19/7/2021 | 17/6/2026 | The specific parameter of upload function of the Orca HCM digital learning platform does not filter file format, which allows remote unauthenticated attackers to upload files containing malicious script to execute RCE attacks. | |
| Modificada | Alta (7.5) | 1.3% | — | Spinnaker Orca | 28/8/2020 | 17/6/2026 | The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an attacker to send requests on behalf of Spinnaker potentially leading to sensitive data disclosure. | |
| Modificada | Alta (7.3) | 0.51% | — | Gnome OrcaDebian Linux | 11/12/2019 | 16/6/2026 | Orca has arbitrary code execution due to insecure Python module load | |
| Modificada | Media (6.6) | 0.53% | — | Canonical Ubuntu LinuxOrcamo Online Receipt Computer Advantage | 7/9/2018 | 17/6/2026 | Ubuntu14.04 ORCA (Online Receipt Computer Advantage) 4.8.0 (panda-server) 1:1.4.9+p41-u4jma1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via unspecified vectors. | |
| Modificada | Media (5) | 1.3% | — | Pearson Proctorcache | 23/6/2015 | 17/6/2026 | Pearson ProctorCache before 2015.1.17 uses the same hardcoded password across different customers' installations, which allows remote attackers to modify test metadata or cause a denial of service (test disruption) by leveraging knowledge of this password. | |
| Modificada | Media (4.3) | 1.1% | — | Orcabrowser Orca Browser | 31/8/2009 | 16/6/2026 | Orca Browser 1.2 build 5 does not properly block data: URIs in Refresh and Location headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains JavaScript sequences in a data:text/html URI, (2) entering a… | |
| Modificada | Baja (3.5) | 0.88% | — | Boonex Orca | 21/8/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Boonex Orca 2.0 and 2.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the topic title field. | |
| Modificada | Alta (9.3) | 3.1% | — | Boonex Orca | 19/11/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in layout/default/params.php in Boonex Orca 2.0 and 2.0.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the gConf[dir][layouts] parameter. |