Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 303 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.8) | 0.19% | — | Scipopt ScipAI | 28/4/2025 | 17/6/2026 | A vulnerability has been found in scipopt scip up to 9.2.1 and classified as problematic. Affected by this vulnerability is the function main of the file examples/LOP/src/genRandomLOPInstance.c of the component File Descriptor Handler. The manipulation of the argument File leads to uncontrolled file descriptor… | |
| Modificada | Crítica (9.8) | 0.53% | — | Gmbilisim Multi-disciplinary Design Optimization | 29/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GM Information Technologies MDO allows SQL Injection. This issue affects MDO: through 20231229. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Modificada | Crítica (9.8) | 1.3% | — | Scipy | 6/7/2023 | 17/6/2026 | A use-after-free issue was discovered in Py_FindObjects() function in SciPy versions prior to 1.8.0. NOTE: the vendor and discoverer indicate that this is not a security issue. | |
| Modificada | Media (5.5) | 0.38% | — | Scipy | 5/7/2023 | 17/6/2026 | A refcounting issue which leads to potential memory leak was discovered in scipy commit 8627df31ab in Py_FindObjects() function. Note: This is disputed as a bug and not a vulnerability. SciPy is not designed to be exposed to untrusted users or data directly. | |
| Modificada | Crítica (9.8) | 2.1% | — | Amazon AWS SDK FOR JavasciptAmazon AWS Shared Configuration File Loader | 19/1/2021 | 17/6/2026 | This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0. If an attacker submits a malicious INI file to an application that parses it with loadSharedConfigFiles , they will pollute the prototype on the application. This can be exploited further depending on the… | |
| Modificada | Alta (7.8) | 0.43% | — | ScipyFedoraproject FedoraRedhat Enterprise LinuxDebian Linux | 4/11/2019 | 16/6/2026 | The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories. | |
| Modificada | Alta (7.5) | 2.7% | — | Scipter.ch Gastebuch | 27/2/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in sinagb.php in Sinapis Gastebuch 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the fuss parameter. |