Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.50% | — | Punk Plugin TotpAI | 25/8/2026 | 26/8/2026 | Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts failures in the session. The POST handler on challenge_path keeps the failure count as tries inside the totp_pending record in the session,… | |
| Aplazada | Crítica (9.8) | 0.62% | — | Punk Plugin TotpAI | 25/8/2026 | 26/8/2026 | Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically. The helper searches the recovery model for the submitted code's digest alone, across every user's rows, so the ownership test that follows… | |
| Aplazada | Crítica (9.1) | 0.50% | — | Perl PunkAI | 22/8/2026 | 26/8/2026 | Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared without a secret. The session keyword freezes its options onto the application as given: it does not require a secret, warn, or refuse to start when one is absent. The cookie read and the write-back… | |
| Aplazada | Crítica (9.1) | 0.50% | — | Punk Oauth2 ServerAI | 22/8/2026 | 26/8/2026 | Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them. Punk::OAuth2::Server::Store registers scopes and grant_types per client and documents both as client registration. token dispatches on the grant_type in… | |
| Aplazada | Media (5.7) | 0.50% | — | Punk Oauth2AI | 20/8/2026 | 28/8/2026 | Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_path accepts a backslash or tab in the return parameter. oauth2_login reads the return parameter from the initiation request, runs same_origin_path over it, and stores the survivor in the session flow… | |
| Analizada | Alta (7.1) | 0.27% | — | Tiefpunkt Meintopf | 20/3/2025 | 17/6/2026 | The mEintopf WordPress plugin through 0.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Alta (7.1) | 0.15% | — | Tiefpunkt ADD Linked Images TO GalleryAI | 24/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in tiefpunkt Add Linked Images To Gallery add-linked-images-to-gallery-v01 allows Cross Site Request Forgery.This issue affects Add Linked Images To Gallery: from n/a through <= 1.4. | |
| Aplazada | Alta (7.6) | 0.92% | — | Punkbuster Pbsv.d64AI | 22/7/2024 | 17/6/2026 | Directory Traversal vulnerability in Punkbuster pbsv.d64 2.351, allows remote attackers to execute arbitrary code. | |
| Modificada | Crítica (9.8) | 2.2% | — | Evenbalance Punkbuster | 16/8/2023 | 9/7/2026 | Directory Traversal vulnerability in Server functionalty in Even Balance Punkbuster version 1.902 before 1.905 allows remote attackers to execute arbitrary code. | |
| Modificada | Media (6.1) | 1.2% | — | Punkave Sanitize-html | 4/6/2018 | 17/6/2026 | sanitize-html is a library for scrubbing html input for malicious values Versions 1.2.2 and below have a cross site scripting vulnerability. | |
| Modificada | Media (6.1) | 1.4% | — | Punkave Sanitize-html | 4/6/2018 | 17/6/2026 | Sanitize-html is a library for scrubbing html input of malicious values. Versions 1.11.1 and below are vulnerable to cross site scripting (XSS) in certain scenarios: If allowed at least one nonTextTags, the result is a potential XSS vulnerability. | |
| Modificada | Crítica (9.8) | 7.0% | — | Cypherpunks Pidgin-otr | 12/4/2016 | 17/6/2026 | Use-after-free vulnerability in the create_smp_dialog function in gtk-dialog.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 4.0.2 for Pidgin allows remote attackers to execute arbitrary code via vectors related to the "Authenticate buddy" menu item. | |
| Modificada | Crítica (9.8) | 25% | — | Debian LinuxOpensuse LeapOpensuseCypherpunks Libotr | 7/4/2016 | 17/6/2026 | Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a series of large OTR messages, which triggers a heap-based buffer overflow. | |
| Modificada | Media (4.3) | 3.4% | — | Cypherpunks Libotr | 20/8/2012 | 16/6/2026 | The (1) otrl_base64_otr_decode function in src/b64.c; (2) otrl_proto_data_read_flags and (3) otrl_proto_accept_data functions in src/proto.c; and (4) decode function in toolkit/parse.c in libotr before 3.2.1 allocates a zero-length buffer when decoding a base64 string, which allows remote attackers to cause a denial… | |
| Modificada | Alta (7.5) | 3.5% | — | Cypherpunks Pidgin-otr | 23/5/2012 | 16/6/2026 | Format string vulnerability in the log_message_cb function in otr-plugin.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 3.2.1 for Pidgin might allow remote attackers to execute arbitrary code via format string specifiers in data that generates a log message. | |
| Modificada | Alta (9.3) | 4.0% | — | Raven Software Soldier OF Fortune 2Punkbuster | 10/11/2009 | 16/6/2026 | Buffer overflow in pbsv.dll, as used in Soldier of Fortune II and possibly other applications when Even Balance PunkBuster 1.728 or earlier is enabled, allows remote attackers to cause a denial of service (application server crash) and possibly execute arbitrary code via a long restart packet. | |
| Modificada | Media (4.3) | 1.1% | — | Fixpunkt Gmbh Admin.tool CMS 3 | 6/11/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in admin.tool CMS 3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) fSid or (2) fSrcBegriffe parameters in unspecified vectors. | |
| Modificada | Media (5) | 5.1% | — | Even Balance Punkbuster | 25/5/2006 | 16/6/2026 | Buffer overflow in the WebTool HTTP server component in (1) PunkBuster before 1.229, as used by multiple products including (2) America's Army 1.228 and earlier, (3) Battlefield 1942 1.158 and earlier, (4) Battlefield 2 1.184 and earlier, (5) Battlefield Vietnam 1.150 and earlier, (6) Call of Duty 1.173 and earlier,… | |
| Modificada | Media (6.4) | 3.1% | — | Even Balance Punkbuster | 18/2/2006 | 16/6/2026 | Format string vulnerability in PunkBuster 1.180 and earlier, as used by Soldier of Fortune II and possibly other games, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in invalid cvar values, which are not properly handled when the… | |
| Modificada | Alta (7.5) | 1.3% | — | Even Balance Punkbuster Database | 31/12/2004 | 16/6/2026 | ** UNVERIFIABLE ** SQL injection vulnerability in PunkBuster Screenshot Database (PB-DB) Alpha 6 allows remote attackers to execute arbitrary SQL commands via the username and password fields of the login form. NOTE: the original vulnerability report contains several significant inconsistencies that make it unclear… |