Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2556▼ 314 respecto a la semana anterior
Críticas / altas1340▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.54% | — | Rawchen SimsAI | 26/4/2026 | 17/6/2026 | A flaw has been found in rawchen sims up to 004f783b1db5ecdfad81c8fdc3b34171211112de. Affected by this issue is some unknown functionality of the file sims-master/src/web/servlet/file/DeleteFileServlet.java of the component deleteFileServlet Endpoint. Executing a manipulation of the argument filename can lead to path… | |
| Analizada | Media (5.5) | 0.43% | — | Simsong Bulk Extractor | 28/1/2026 | 17/6/2026 | `bulk_extractor` is a digital forensics exploitation tool. Starting in version 1.4, `bulk_extractor`’s embedded unrar code has a heap‑buffer‑overflow in the RAR PPM LZ decoding path. A crafted RAR inside a disk image causes an out‑of‑bounds write in `Unpack::CopyString`, leading to a crash under ASAN (and likely a… | |
| Aplazada | Media (6.7) | 0.21% | — | Datasims Avionics Arinc 664-1AI | 23/1/2026 | 17/6/2026 | dataSIMS Avionics ARINC 664-1 version 4.5.3 contains a local buffer overflow vulnerability that allows attackers to overwrite memory by manipulating the milstd1553result.txt file. Attackers can craft a malicious file with carefully constructed payload and alignment sections to potentially execute arbitrary code on the… | |
| Modificada | Media (6.5) | 1.0% | — | Sims Project Sims | 27/7/2022 | 17/6/2026 | Sims v1.0 was discovered to allow path traversal when downloading attachments. | |
| Modificada | Alta (8.8) | 1.4% | — | Sims Project Sims | 27/7/2022 | 17/6/2026 | Sims v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /uploadServlet. This vulnerability allows attackers to escalate privileges and execute arbitrary commands via a crafted file. | |
| Modificada | Media (5) | 1.2% | — | Evan Sims Effingerd | 31/12/2004 | 16/6/2026 | efFingerD 0.2.12 allows remote attackers to cause a denial of service (daemon crash) via a packet with a single byte, which triggers a "Wrong protocol or connection state" error. | |
| Modificada | Media (5) | 1.8% | — | Evan Sims Effingerd | 31/12/2004 | 16/6/2026 | Buffer overflow in the sockFinger_DataArrival function in efFingerD 0.2.12 allows remote attackers to cause a denial of service (daemon crash) via a long finger command. |