Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2682▼ 88 respecto a la semana anterior
Críticas / altas1443▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.31% | — | Pluto-lang Pluto | 10/9/2024 | 17/6/2026 | Pluto is a superset of Lua 5.4 with a focus on general-purpose programming. Scripts passing user-controlled values to http.request header values are affected. An attacker could use this to send arbitrary requests, potentially leveraging authentication tokens provided in the same headers table. | |
| Aplazada | Media (4.8) | 0.13% | — | PlutoAI | 1/5/2024 | 17/6/2026 | Pluto is a superset of Lua 5.4 with a focus on general-purpose programming. In affected versions an attacker with the ability to actively intercept network traffic would be able to use a specifically-crafted certificate to fool Pluto into trusting it to be the intended remote for the TLS session. This results in the… | |
| Modificada | Crítica (9.8) | 0.83% | — | Sammycage Plutosvg | 14/12/2023 | 17/6/2026 | PlutoSVG commit 336c02997277a1888e6ccbbbe674551a0582e5c4 and before was discovered to contain an integer overflow via the component plutosvg_load_from_memory. | |
| Modificada | Media (6.1) | 2.3% | — | Apache Pluto | 6/1/2022 | 17/6/2026 | The "first name" and "last name" fields of the Apache Pluto 3.1.0 MVCBean JSP portlet maven archetype are vulnerable to Cross-Site Scripting (XSS) attacks. | |
| Modificada | Media (6.1) | 2.3% | — | Apache Pluto | 6/1/2022 | 17/6/2026 | The input fields in the JSP version of the Apache Pluto Applicant MVCBean CDI portlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of the applicant-mvcbean-cdi-jsp-portlet.war artifact | |
| Modificada | Media (6.1) | 2.3% | — | Apache Pluto | 6/1/2022 | 17/6/2026 | The input fields of the Apache Pluto UrlTestPortlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of the v3-demo-portlet.war artifact | |
| Modificada | Media (5.5) | 1.7% | — | Junit4Debian LinuxApache PlutoOracle Communications Cloud Native Core Policy | 12/10/2020 | 17/6/2026 | In JUnit4 from version 4.7 and before 4.13.1, the test rule TemporaryFolder contains a local information disclosure vulnerability. On Unix like systems, the system's temporary directory is shared between all users on that system. Because of this, when files and directories are written into this directory they are, by… | |
| Modificada | Media (6.1) | 21% | — | Apache Pluto | 26/4/2019 | 17/6/2026 | The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XSS) attacks. Mitigation: * Uninstall the ChatRoomDemo war file - or - * migrate to version 3.1.0 of the chat-room-demo war file | |
| Modificada | Crítica (9.8) | 1.9% | — | Marel Pluto1203Marel Pluto2 | 27/3/2019 | 17/6/2026 | Systems using the Marel Food Processing Systems Pluto platform do not restrict remote access. Marel has created an update for Pluto-based applications. This update will restrict remote access by implementing SSH authentication. | |
| Modificada | Alta (7.5) | 1.1% | — | Plutocracy Krown | 9/7/2018 | 17/6/2026 | The mintlvlToken function of a smart contract implementation for Krown, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.5) | 43% | — | Apache Pluto | 27/6/2018 | 17/6/2026 | The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to restrict path information provided during a file upload. An attacker could exploit this vulnerability to obtain configuration data… | |
| Modificada | Baja (3.6) | 2.3% | — | Plutostatus Locator | 19/2/2008 | 16/6/2026 | Directory traversal vulnerability in index.php in PlutoStatus Locator 1.0 pre alpha allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. |