Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3040▲ 560 respecto a la semana anterior
Críticas / altas1452▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Baja (3.1) | 0.15% | — | HCL IreflectionAI | 2/6/2026 | 22/7/2026 | HCL iReflection Third party vulnerable and outdated components issue was detected in the web application | |
| Modificada | Alta (8.9) | 0.99% | — | Webreflection Flatted | 20/3/2026 | 4/9/2026 | flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the internal input buffer is a JavaScript Array, accessing it with the key "__proto__"… | |
| Modificada | Alta (7.5) | 0.99% | — | Webreflection Flatted | 12/3/2026 | 4/9/2026 | flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve circular references in deserialized JSON. When given a crafted payload with deeply nested or self-referential $ indices, the recursion depth is unbounded, causing a stack overflow that crashes the… | |
| Modificada | Media (6.5) | 2.2% | — | Microfocus Host Access Management AND Security ServerMicrofocus Reflection FOR THE WEBMicrofocus Reflection Security GatewayMicrofocus Reflection ZFE | 29/11/2016 | 17/6/2026 | Administrative Server in Micro Focus Host Access Management and Security Server (MSS) and Reflection for the Web (RWeb) and Reflection Security Gateway (RSG) and Reflection ZFE (ZFE) allows remote unauthenticated attackers to read arbitrary files via a specially crafted URL that allows limited directory traversal.… | |
| Modificada | Alta (10) | 7.7% | — | Attachmate Reflection FTP Client | 6/2/2015 | 17/6/2026 | Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to execute arbitrary code via unspecified vectors to the SaveSettings method. | |
| Modificada | Alta (10) | 6.3% | — | Attachmate Reflection FTP Client | 6/2/2015 | 17/6/2026 | Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to execute arbitrary code via unspecified vectors to the StartLog method. | |
| Modificada | Alta (10) | 5.7% | — | Attachmate Reflection FTP Client | 6/2/2015 | 17/6/2026 | The rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to cause a denial of service (memory corruption) and execute arbitrary code via vectors related to the (1) GetGlobalSettings or (2) GetSiteProperties3 methods, which triggers a dereference of an arbitrary memory… | |
| Modificada | Media (6.8) | 2.8% | — | Attachmate Reflection FTP Client | 27/1/2015 | 17/6/2026 | Stack-based buffer overflow in the Attachmate Reflection FTP Client before 14.1.433 allows remote FTP servers to execute arbitrary code via a large PWD response. | |
| Modificada | Media (6.9) | 0.40% | — | Attachmate Reflection FOR HPAttachmate Reflection FOR IBMAttachmate Reflection FOR Regis Graphics ServerAttachmate Reflection FOR Unix AND Openvms+1 | 6/9/2012 | 16/6/2026 | Untrusted search path vulnerability in Attachmate Reflection before 14.1 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, a related issue to CVE-2011-0107. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (10) | 7.8% | — | Attachmate ReflectionAttachmate Reflection 2008Attachmate Reflection 2008r1Attachmate Reflection 2008r2+1 | 25/12/2011 | 16/6/2026 | Heap-based buffer overflow in the Reflection FTP Client (rftpcom.dll 7.2.0.106 and possibly other versions), as used in Attachmate Reflection 2008, Reflection 2011 R1 before 15.3.2.569 and R1 SP1 before, Reflection 2011 R2 before 15.4.1.327, Reflection Windows Client 7.2 SP1 before hotfix 7.2.1186, and Reflection 14.1… | |
| Modificada | Media (4.3) | 1.1% | — | Attachmate Reflection FOR THE WEB | 2/11/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Attachmate Reflection for the Web 2008 R2 (builds 10.1.569 and earlier), 2008 R1, and 9.6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (10) | 1.9% | — | Attachmate Reflection FOR Secure IT | 2/2/2009 | 16/6/2026 | Multiple unspecified vulnerabilities in Attachmate Reflection for Secure IT UNIX Client and Server before 7.0 SP1 have unknown impact and attack vectors, aka "security vulnerabilities found by 3rd party analysis." | |
| Modificada | Media (6.5) | 10% | — | Attachmatewrq Reflection FOR Secure IT ServerF-secure SSH Server | 15/2/2006 | 16/6/2026 | Format string vulnerability in a logging function as used by various SFTP servers, including (1) AttachmateWRQ Reflection for Secure IT UNIX Server before 6.0.0.9, (2) Reflection for Secure IT Windows Server before 6.0 build 38, (3) F-Secure SSH Server for Windows before 5.3 build 35, (4) F-Secure SSH Server for UNIX… | |
| Modificada | Alta (7.5) | 3.3% | — | WRQ Reflection FOR Secure IT Windows Server | 2/9/2005 | 16/6/2026 | WRQ Reflection for Secure IT Windows Server 6.0 (formerly known as F-Secure SSH server) does not properly handle when the Windows Administrator or Guest accounts are renamed after SSH key authentication has been configured, which allows remote attackers to use the original names during login. | |
| Modificada | Alta (10) | 4.8% | — | F-secure SSH ServerWRQ Reflection FOR Secure IT Windows Server | 2/9/2005 | 16/6/2026 | WRQ Reflection for Secure IT Windows Server 6.0 (formerly known as F-Secure SSH server) processes access and deny lists in a case-sensitive manner, when previous versions were case-insensitive, which might allow remote attackers to bypass intended restrictions and login to accounts that should be denied. |