Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3045▲ 455 respecto a la semana anterior
Críticas / altas1424▲ 188 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)389▲ 174 respecto a la semana anterior
125 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (8.7) | — | — | Sharp Multifunction PrinterAIToshibatec Multifunction PrinterAI | 1/10/2026 | 1/10/2026 | Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply directory traversal sequences such as… | |
| Aplazada | Alta (8.7) | 0.22% | — | Code16 SharpAI | 24/9/2026 | 29/9/2026 | code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulnerability in `SharpEditorFormField`: attacker-controlled content bearing the `data-html-content` attribute can bypass HTML sanitization and preserve… | |
| Aplazada | Alta (7.3) | 0.21% | — | Code16 SharpAI | 24/9/2026 | 30/9/2026 | code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulnerability in the rich-text editor because the HTML sanitizer permits the `srcdoc` attribute on iframe elements. Although markup inside `srcdoc` is… | |
| Aplazada | Media (5.3) | 0.40% | — | CefsharpAI | 18/8/2026 | 9/9/2026 | CefSharp provides .NET bindings for the Chromium Embedded Framework for Windows Forms and Windows Presentation Foundation applications. Prior to version 148.0.90, CefSharp/SchemeHandler/FolderSchemeHandlerFactory.cs used filePath.StartsWith(rootFolder, StringComparison.OrdinalIgnoreCase) to decide whether a decoded… | |
| Aplazada | Media (6.9) | 0.33% | — | AnglesharpAI | 18/8/2026 | 18/9/2026 | AngleSharp is a .NET library for parsing angle bracket based hyper-texts. Prior to 1.5.0, MathAnnotationXmlElement in AngleSharp/Mathml/Dom/Internal/MathAnnotationXmlElement.cs is not treated as an HTML integration point when its encoding attribute is text/html or application/xhtml+xml, causing Consume in… | |
| Aplazada | Crítica (9.8) | 0.63% | — | IotsharpAI | 5/8/2026 | 26/8/2026 | IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (DevicesController, CustomersController, TenantsController, etc.), and no global authorization FallbackPolicy is configured in Startup.cs, leaving its Upload/Download/List/Modify/Delete endpoints… | |
| Pendiente de análisis | Media (6.9) | 0.43% | — | Sharp MFPAIToshibatec MFPAI | 3/8/2026 | 3/8/2026 | Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in the initial configuration. When used with the initial configuration, the address book editing and a range of features related to Document Filing can be accessed without user… | |
| Pendiente de análisis | Baja (2.4) | 0.22% | — | Sharp MFPAIToshibatec MFPAI | 3/8/2026 | 3/8/2026 | Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They may be accessed later by other users. | |
| Pendiente de análisis | Media (6.9) | 0.64% | — | Sharp Network Scanner ToolAISharp Network Scanner Tool LiteAI | 3/8/2026 | 3/8/2026 | Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, require no authentication and accept files unlimitedly. When the affected products are used with the initial configuration, anyone can connect to them without authentication and upload files unlimitedly.… | |
| Pendiente de análisis | Media (6.9) | 0.40% | — | Sharp MFPAIToshibatec MFPAI | 3/8/2026 | 3/8/2026 | Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image data stored to the affected product. | |
| Aplazada | Media (4.3) | 0.37% | — | SharpAILaravelAI | 10/6/2026 | 23/7/2026 | Sharp is a content management framework built for Laravel as a package. From version 9.0.0 to before version 9.22.3, the create and store endpoints of the Quick Creation Command feature did not enforce any authorization check. An authenticated Sharp user without create permission on a given entity could bypass the… | |
| Aplazada | Alta (7.7) | 0.36% | — | SharpAILaravelAI | 10/6/2026 | 23/7/2026 | Sharp is a content management framework built for Laravel as a package. Prior to version 9.22.0, Sharp exposes a generic download endpoint that authorizes access only to the supplied Sharp entity instance, but then reads the target storage disk and path from request parameters. Because the requested storage object is… | |
| Analizada | Media (6.5) | 0.35% | — | Adamhathcock Sharpcompress | 26/5/2026 | 24/7/2026 | SharpCompress is a fully managed C# library to deal with many compression types and formats. In 0.47.4 and earlier, a path traversal vulnerability in IArchive.WriteToDirectory() allows a malicious archive to create directories outside the intended extraction root. For TAR archives, this can be escalated to arbitrary… | |
| Aplazada | Media (5.3) | 0.45% | — | ParquetsharpAIApache ParquetAI | 7/5/2026 | 17/6/2026 | ParquetSharp is a .NET library for reading and writing Apache Parquet files. From version 18.1.0 to before version 23.0.0.1, DecimalConverter.ReadDecimal makes a stackalloc using what might be an attacker-supplied value. If an attacker declares a decimal column with some unreasonable width, this could lead to a stack… | |
| Aplazada | Alta (8.7) | 0.41% | — | Unisharp Laravel File ManagerAI | 5/4/2026 | 24/7/2026 | UniSharp Laravel File Manager v2.0.0-alpha7 and v2.0 contain an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by sending multipart form data to the upload endpoint. Attackers can upload PHP files with the type parameter set to Files and execute arbitrary code by… | |
| Analizada | Alta (8.8) | 0.69% | — | Code16 Sharp | 26/3/2026 | 17/6/2026 | Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 contain a vulnerability in the file upload endpoint that allows authenticated users to bypass all file type restrictions. The upload endpoint within the `ApiFormUploadController` accepts a client-controlled… | |
| Analizada | Alta (8.8) | 0.57% | — | Code16 Sharp | 26/3/2026 | 17/6/2026 | Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 have a path traversal vulnerability in the FileUtil class. The application fails to sanitize file extensions properly, allowing path separators to be passed into the storage layer. In `src/Utils/FileUtil.php`, the… | |
| Pendiente de análisis | Media (6.9) | 0.30% | — | Sharp RoutersAI | 25/3/2026 | 17/6/2026 | SHARP routers do not perform authentication for some web APIs. The device information may be retrieved without authentication. If the administrative password of the device is left as the initial one, the device may be taken over. | |
| Analizada | Alta (8.8) | 0.42% | — | Pointsharp ID Server | 13/3/2026 | 17/6/2026 | A broken access control may allow an authenticated user to perform a horizontal privilege escalation. The vulnerability only impacts specific configurations. | |
| Analizada | Crítica (9.4) | 0.81% | — | Sharpred Deephas | 29/1/2026 | 17/6/2026 | deepHas provides a test for the existence of a nested object key and optionally returns that key. A prototype pollution vulnerability exists in version 1.0.7 of the deephas npm package that allows an attacker to modify global object behavior. This issue was fixed in version 1.0.8. | |
| Aplazada | Crítica (9.5) | 0.30% | — | Sharp Display Solutions ProjectorAI | 22/12/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sharp Display Solutions projectors allows a attacker may improperly access the HTTP server and execute arbitrary actions. | |
| Aplazada | Crítica (9.5) | 0.30% | — | Sharp Display Solutions ProjectorsAI | 22/12/2025 | 17/6/2026 | Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may create and run unauthorized firmware. | |
| Analizada | Crítica (9.2) | 0.32% | — | Sharp Mp-01 Firmware | 22/12/2025 | 17/6/2026 | Missing Authentication for Critical Function vulnerability in Sharp Display Solutions Media Player MP-01 All Verisons allows a attacker may access to the web interface of the affected product without authentication and change settings or perform other operations, and deliver content from the authoring software to the… | |
| Analizada | Crítica (9.5) | 0.20% | — | Sharp Np-p502h FirmwareSharp Np-p502w FirmwareSharp Np-p452h FirmwareSharp Np-p452w Firmware+22 | 22/12/2025 | 17/6/2026 | Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may create and run unauthorized firmware. | |
| Analizada | Alta (8.4) | 0.41% | — | Sharp Np-p502h FirmwareSharp Np-p502w FirmwareSharp Np-p452h FirmwareSharp Np-p452w Firmware+22 | 22/12/2025 | 17/6/2026 | Stack-based Buffer Overflow vulnerability in Sharp Display Solutions projectors allows a attacker may execute arbitrary commands and programs. |