Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2532▼ 361 respecto a la semana anterior
Críticas / altas1338▲ 69 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.36% | — | Catalyst SealAI | 24/9/2026 | 25/9/2026 | Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route a later one past an authorization check via a dispatch memo keyed on the request path alone. Catalyst::Seal replaces the dispatcher's prepare_action with a version that memoises how a path resolved: which dispatch type matched,… | |
| Pendiente de análisis | Media (4.2) | 0.40% | — | Sealed SecretsAI | 15/9/2026 | 18/9/2026 | A security vulnerability exists in the Sealed Secrets controller's unauthenticated POST endpoints. By submitting a modified payload containing custom Go template logic in spec.template.data, an attacker with internal network access can abuse the handler as a decryption oracle to recover the full plaintext of any… | |
| Aplazada | Crítica (9.1) | 0.40% | — | Sealed-envAI | 12/5/2026 | 17/6/2026 | sealed-env is a cross-stack, zero-trust secret management library for Node.js and Java/Spring Boot. In sealed-env enterprise mode, versions 0.1.0-alpha.1 through 0.1.0-alpha.3 embedded the operator's literal TOTP secret in the JWS payload of every minted unseal token. JWS payload is base64-encoded JSON, NOT encrypted.… | |
| Aplazada | Media (4.9) | 0.36% | — | Bitnami Sealed SecretsAI | 26/2/2026 | 17/6/2026 | Bitnami Sealed Secrets is vulnerable to a scope-widening attack during the secret rotation (/v1/rotate) flow. The rotation handler derives the sealing scope for the newly encrypted output from untrusted spec.template.metadata.annotations present in the input SealedSecret. By submitting a victim SealedSecret to the… | |
| Aplazada | Alta (8.2) | 0.21% | — | DocusealAI | 4/12/2024 | 17/6/2026 | User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSeal allows Content Spoofing.Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will render the vulnerability only, not all layers are flattened.… | |
| Modificada | Alta (8.1) | 0.55% | — | Sealos | 3/7/2023 | 17/6/2026 | Sealos is a Cloud Operating System designed for managing cloud-native applications. In version 4.2.0 and prior, there is a permission flaw in the Sealos billing system, which allows users to control the recharge resource account `sealos[.] io/v1/Payment`, resulting in the ability to recharge any amount of 1 renminbi… | |
| Modificada | Crítica (9.8) | 0.71% | — | Sealos Project Sealos | 29/6/2023 | 17/6/2026 | Sealos is an open source cloud operating system distribution based on the Kubernetes kernel. In versions of Sealos prior to 4.2.1-rc4 an improper configuration of role based access control (RBAC) permissions resulted in an attacker being able to obtain cluster control permissions, which could control the entire… | |
| Modificada | Media (5.9) | 0.74% | — | Sealevel Seaconnect 370w Firmware | 14/4/2022 | 17/6/2026 | An out-of-bounds write vulnerability exists in the OTA update task functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted MQTT payload can lead to denial of service. An attacker can perform a man-in-the-middle attack to trigger this vulnerability. | |
| Modificada | Media (5.9) | 0.70% | — | Sealevel Seaconnect 370w Firmware | 4/2/2022 | 17/6/2026 | An out-of-bounds write vulnerability exists in the URL_decode functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted MQTT payload can lead to an out-of-bounds write. An attacker can perform a man-in-the-middle attack to trigger this vulnerability. | |
| Modificada | Alta (8.1) | 0.89% | — | Sealevel Seaconnect 370w Firmware | 4/2/2022 | 17/6/2026 | An out-of-bounds write vulnerability exists in the HandleSeaCloudMessage functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. The HandleIncomingSeaCloudMessage function uses at [3] the json_object_get_string to populate the p_name global variable. The p_name is only 0x80 bytes long, and the total MQTT… | |
| Modificada | Alta (8.1) | 0.89% | — | Sealevel Seaconnect 370w Firmware | 4/2/2022 | 17/6/2026 | An out-of-bounds write vulnerability exists in the HandleSeaCloudMessage functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. The HandleIncomingSeaCloudMessage function uses at [4] the json_object_get_string to populate the p_payload global variable. The p_payload is only 0x100 bytes long, and the total… | |
| Modificada | Alta (8.3) | 0.95% | — | Sealevel Seaconnect 370w Firmware | 4/2/2022 | 17/6/2026 | A file write vulnerability exists in the OTA update task functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted MQTT payload can lead to arbitrary file overwrite. An attacker can perform a man-in-the-middle attack to trigger this vulnerability. | |
| Modificada | Crítica (9.3) | 1.0% | — | Sealevel Seaconnect 370w Firmware | 4/2/2022 | 17/6/2026 | A denial of service vulnerability exists in the SeaMax remote configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-crafted network packets can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Alta (7.4) | 0.71% | — | Sealevel Seaconnect 370w Firmware | 4/2/2022 | 17/6/2026 | A denial of service vulnerability exists in the Modbus configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-crafted network packets can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Media (5.9) | 0.49% | — | Sealevel Seaconnect 370w Firmware | 4/2/2022 | 17/6/2026 | An information disclosure vulnerability exists in the Web Server functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted man-in-the-middle attack can lead to a disclosure of sensitive information. An attacker can perform a man-in-the-middle attack to trigger this vulnerability. | |
| Modificada | Alta (8.1) | 2.0% | — | Sealevel Seaconnect 370w Firmware | 4/2/2022 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in the OTA Update u-download functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A series of specially-crafted MQTT payloads can lead to remote code execution. An attacker must perform a man-in-the-middle attack in order to trigger this vulnerability. | |
| Modificada | Crítica (10) | 2.6% | — | Sealevel Seaconnect 370w Firmware | 4/2/2022 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the NBNS functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted network packet can lead to remote code execution. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Crítica (10) | 2.6% | — | Sealevel Seaconnect 370w Firmware | 4/2/2022 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in both the LLMNR functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted network packet can lead to remote code execution. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Alta (8.1) | 0.84% | — | Sealevel Seaconnect 370w Firmware | 4/2/2022 | 17/6/2026 | A misconfiguration exists in the MQTTS functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. This misconfiguration significantly simplifies a man-in-the-middle attack, which directly leads to control of device functionality. | |
| Modificada | Alta (7.5) | 1.3% | — | Seal Finance Project Seal Finance | 3/1/2021 | 17/6/2026 | The breed function in the smart contract implementation for Farm in Seal Finance (Seal), an Ethereum token, lacks access control and thus allows price manipulation, as exploited in the wild in December 2020 and January 2021. | |
| Modificada | Baja (2.6) | 0.92% | — | Ncipher Dse200 Document Sealing EngineNcipher NcoreNcipher NforceNcipher Securedb+4 | 9/3/2006 | 16/6/2026 | nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document Sealing Engine, (7) Time Source Master Clock (TSMC), and possibly other products, contains certain options that were only intended for testing and not production, which might allow remote… |