Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 331 respecto a la semana anterior
Críticas / altas1352▲ 94 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.8) | 0.18% | — | Rocq ProverAI | 24/8/2026 | 8/9/2026 | Rocq Prover does not restore the universe graph's copy of the universe checking flag when a module that locally disabled the check is closed. Local Unset Universe Checking inside a module is expected to last only until the module ends, and the global flag is restored, but the universe graph keeps its own copy which is… | |
| Aplazada | Media (6.8) | 0.18% | — | Rocq ProverAI | 24/8/2026 | 8/9/2026 | The guard checker in Rocq Prover does not recheck the recursive tree representation of an inductive type parameter after that parameter has been changed by transport. A fixpoint may apply a rewrite along an equality between types to its recursive argument, which the guard checker accepts because the inductive type is… | |
| Aplazada | Media (6.8) | 0.18% | — | Rocq ProverAICOQAI | 24/8/2026 | 8/9/2026 | The guard checker in Rocq Prover treats a parameter of a nested mutual fixpoint as uniform without examining calls between the different bodies of that fixpoint. find_uniform_parameters in kernel/inductive.ml inspects only self-recursive calls, so when no body calls itself the function concludes that every parameter… | |
| Pendiente de análisis | Media (6.2) | 0.11% | — | Ardupilot RoverAIArdupilot AP Inertialsensor Adis1647xAI | 13/5/2026 | 17/6/2026 | Buffer Overflow vulnerability in Ardupilot rover commit v.c56439b045162058df0ff136afea3081fcd06d38 allows a local attacker to cause a denial of service via the AP_InertialSensor_ADIS1647x.cpp, ArduRover, ADIS1647x Sensor component. | |
| Aplazada | Ninguna (0) | 0.52% | — | Leanprover Unicode Input ComponentAI | 16/3/2026 | 17/6/2026 | Lean 4 VS Code Extension is a Visual Studio Code extension for the Lean 4 proof assistant. Projects that use @leanprover/unicode-input-component are vulnerable to an XSS exploit in 0.1.9 of the package and lower. The component re-inserted text in the input element back into the input element as unescaped HTML. The… | |
| Aplazada | Alta (7.5) | 0.38% | — | Apollo FederationAIApollo RouterAIAvirt RoverAI | 13/11/2025 | 17/6/2026 | Apollo Federation is an architecture for declaratively composing APIs into a unified graph. A vulnerability in versions of Apollo Federation's composition logic prior to 2.9.5, 2.10.4, 2.11.5, and 2.12.1 allowed some queries to Apollo Router to improperly bypass access controls on types/fields. Apollo Federation… | |
| Aplazada | Media (6.5) | 0.37% | — | Jd7777 Daily ProverbAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jd7777 Daily Proverb daily-proverb allows Stored XSS.This issue affects Daily Proverb: from n/a through <= 2.0.3. | |
| Analizada | Media (6.3) | 0.44% | — | Roveridx Rover IDX | 22/10/2024 | 17/6/2026 | The Rover IDX plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 3.0.0.2903. This makes it possible for authenticated attackers, with subscriber-level access and above, to add, modify,… | |
| Analizada | Alta (8.8) | 0.56% | — | Roveridx Rover IDX | 22/10/2024 | 17/6/2026 | The Rover IDX plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0.0.2905. This is due to insufficient validation and capability check on the 'rover_idx_refresh_social_callback' function. This makes it possible for authenticated attackers, with subscriber-level permissions… | |
| Modificada | Alta (7.5) | 3.8% | — | Jetbrains AquaJetbrains ClionJetbrains DatagripJetbrains Dataspell+9 | 10/6/2024 | 17/6/2026 | GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell… | |
| Modificada | Media (6.8) | 0.22% | — | Espressif Esp32-d0wd-v3 FirmwareEspressif Esp32-d0wdr2-v3 FirmwareEspressif Esp32-u4wdh FirmwareEspressif Esp32-pico-v3 Firmware+18 | 17/7/2023 | 17/6/2026 | An issue was discovered on Espressif ESP32 3.0 (ESP32_rev300 ROM) devices. An EMFI attack on ECO3 provides the attacker with a capability to influence the PC value at the CPU context level, regardless of Secure Boot and Flash Encryption status. By using this capability, the attacker can exploit another behavior in the… | |
| Modificada | Crítica (9.1) | 0.71% | — | Westerndigital Edgerover | 13/1/2022 | 17/6/2026 | File and directory permissions have been corrected to prevent unintended users from modifying or accessing resources. It would be more difficult for an authenticated attacker to now traverse through the files and directories. This can only be exploited once an attacker has already found a way to get authenticated… | |
| Modificada | Alta (8.8) | 0.97% | — | Westerndigital Edgerover | 11/6/2021 | 17/6/2026 | Western Digital EdgeRover before 0.25 has an escalation of privileges vulnerability where a low privileged user could load malicious content into directories with higher privileges, because of how Node.js is used. An attacker can gain admin privileges and carry out malicious activities such as creating a fake library… | |
| Modificada | Alta (7.5) | 1.9% | — | Logrover | 2/10/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in login.asp (aka the login screen) in LogRover 2.3 and 2.3.3 on Windows allow remote attackers to execute arbitrary SQL commands via the (1) uname and (2) pword parameters. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 0.97% | — | Extrovert Software Thyme | 7/10/2008 | 16/6/2026 | SQL injection vulnerability in pick_users.php in the groups module in eXtrovert Thyme 1.3 allows remote attackers to execute arbitrary SQL commands via the uname_search parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 0.96% | — | Proverbs WEB Calendar | 29/11/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in caladmin.inc.php in Proverbs Web Calendar 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) loginname (aka Username) and (2) loginpass (aka Password) parameters to caladmin.php. | |
| Modificada | Alta (7.5) | 2.5% | — | Extrovert Software Thyme Calndar | 11/5/2007 | 16/6/2026 | SQL injection vulnerability in event_view.php in Thyme Calendar 1.3 allows remote attackers to execute arbitrary SQL commands via the eid parameter. | |
| Modificada | Alta (9.3) | 6.9% | — | Sandh News Rover | 21/2/2007 | 16/6/2026 | Multiple stack-based buffer overflows in S&H Computer Systems News Rover 12.1 Rev 1 allow remote attackers to execute arbitrary code via a .nzb file with a long (1) group or (2) subject string. | |
| Modificada | Media (5) | 7.1% | — | Nelso Software Desktop Rover | 2/5/2005 | 16/6/2026 | Desktop Rover 3.0, and possibly earlier versions, allows remote attackers to cause a denial of service (application crash) via a crafted packet to TCP port 61427, which causes an invalid memory access. | |
| Modificada | Media (5) | 2.7% | — | Avirt Rover | 27/12/1999 | 16/6/2026 | Buffer overflow in aVirt Rover POP3 server 1.1 allows remote attackers to cause a denial of service via a long user name. |