Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
–

25 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.45%—SkipperAI16/9/202616/9/2026
Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.27.37, the opaAuthorizeRequestWithBody filter can authorize an oversized request after Skipper truncates the body presented to Open Policy Agent because the input.truncated_body signal is derived from Content-Length rather than the…
AplazadaAlta (8.2)0.46%—SkipperAIOpenpolicyagent Open Policy AgentAI14/9/202616/9/2026
Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass a deny-on-presence Rego policy because ExtractHttpBodyOptionally leaves OPA with…
AplazadaMedia (4.3)0.30%—SkipperAI14/9/202616/9/2026
Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.22, Handler in dataclients/kubernetes/admission/admission.go passes the body of requests to the Kubernetes admission endpoint at :9443/admission directly to io.ReadAll(r.Body) without a size limit. An attacker with in-cluster network…
AplazadaMedia (5.7)0.34%—SkipperAI14/9/202616/9/2026
Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.13, the routesrv component serves cluster-wide control-plane data without application-layer authentication through /routes, /routes/{zone}, /swarm/redis/shards, and /swarm/valkey/shards. The handlers registered in routesrv/routesrv.go,…
AplazadaAlta (8.8)0.39%—Zalando SkipperAIOpenpolicyagent OPAAI23/7/202630/7/2026
Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBodyBytes limit, Skipper forwards the full payload to the upstream service while OPA evaluates against an empty…
AplazadaAlta (7.8)0.55%—Zalando SkipperAI17/7/202623/7/2026
Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.10, zalando/skipper's OpenPolicyAgent integration silently bypasses request-body inspection on HTTP/1.1 Transfer-Encoding: chunked and HTTP/2 requests that omit the content-length pseudo-header, because the opaAuthorizeRequestWithBody…
AnalizadaAlta (8.1)0.31%—Zalando Skipper26/1/202617/6/2026
Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.24.0, when running Skipper as an Ingress controller, users with permissions to create an Ingress and a Service of type ExternalName can create routes that enable them to use Skipper's network access to reach internal services.…
AnalizadaAlta (8.8)0.52%—Zalando Skipper16/1/202617/6/2026
Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was -lua-sources=inline,file. The problem starts if untrusted users can create lua filters, because of -lua-sources=inline , for example through a Kubernetes Ingress resource. The configuration inline…
AplazadaMedia (6.4)0.27%—Skip TO TimestampAI11/11/202517/6/2026
The Skip to Timestamp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'skipto' shortcode in all versions up to, and including, 1.4.4. This is due to insufficient input sanitization and output escaping on the 'time' attribute. This makes it possible for authenticated attackers, with…
AnalizadaMedia (5.3)0.32%—Mindskip Xzs-mysql7/2/202517/6/2026
A vulnerability, which was classified as problematic, has been found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.…
AnalizadaBaja (2.3)0.33%—Mindskip Xzs-mysql6/2/202517/6/2026
A vulnerability classified as problematic was found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected by this vulnerability is an unknown functionality of the component CORS Handler. The manipulation leads to permissive cross-domain policy with untrusted domains. The attack can be launched remotely. The complexity of an…
AnalizadaMedia (5.1)0.39%—Mindskip Xzs-mysql6/2/202517/6/2026
A vulnerability classified as problematic has been found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected is an unknown function of the file /api/admin/question/edit of the component Exam Edit Handler. The manipulation of the argument title/content leads to cross site scripting. It is possible to launch the attack…
AplazadaAlta (7.1)0.21%—Marckocher Skip TOAI19/11/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in marckocher Skip To skip-to allows Stored XSS.This issue affects Skip To: from n/a through <= 2.0.0.
AplazadaAlta (8.8)0.23%—Skipstorm SK WP Settings BackupAI16/11/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in skipstorm SK WP Settings Backup sk-wp-settings-backup allows Object Injection.This issue affects SK WP Settings Backup: from n/a through <= 1.0.
AplazadaAlta (8.8)18%—Vmware Cloud Data FlowAIVmware SkipperAI19/6/202417/6/2026
Spring Cloud Data Flow is a microservices-based Streaming and Batch data processing in Cloud Foundry and Kubernetes. The Skipper server has the ability to receive upload package requests. However, due to improper sanitization for upload path, a malicious user who has access to skipper server api can use a crafted…
AnalizadaCrítica (9.8)0.78%—Mindskip Xzs-mysql26/3/202417/6/2026
xzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the session of a deleted admin to do anything.
ModificadaCrítica (9.8)12%—Zalando Skipper25/10/20229/7/2026
Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).
ModificadaMedia (5.4)0.69%—Mindskip XZS17/10/202217/6/2026
xzs v3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /admin/question/edit. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title text field.
ModificadaAlta (7.5)1.1%—Zalando Skipper23/6/202217/6/2026
In Zalando Skipper before 0.13.218, a query predicate could be bypassed via a prepared request.
ModificadaCrítica (9.8)2.1%—Sailsjs Skipper12/4/20229/7/2026
An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary code via a crafted file.
ModificadaAlta (7.5)0.80%—Mindskip Xzs-mysql25/1/202217/6/2026
xzs-mysql >= t3.4.0 is vulnerable to Insecure Permissions. The front end of this open source system is an online examination system. There is an unsafe vulnerability in the functional method of submitting examination papers. An attacker can use burpuite to modify parameters in the packet to destroy real data.
ModificadaAlta (7.5)1.3%—Openskip Skip4/6/200916/6/2026
SQL injection vulnerability in Skip 1.0.2 and earlier, and 1.1RC2 and earlier 1.1RC versions, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (4.3)1.2%—Openskip Skip4/6/200916/6/2026
Cross-site scripting (XSS) vulnerability in Skip 1.0.2 and earlier, and 1.1RC2 and earlier 1.1RC versions, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5)12%—Skippy.net Wp-db Backup Plugin FOR Wordpress17/8/200616/6/2026
Directory traversal vulnerability in wp-db-backup.php in Skippy WP-DB-Backup plugin for WordPress 1.7 and earlier allows remote authenticated users with administrative privileges to read arbitrary files via a .. (dot dot) in the backup parameter to edit.php.
ModificadaMedia (5)3.5%—Nadeo Game EngineNadeo TrackmaniaNadeo Virtual Skipper8/2/200416/6/2026
Nadeo Game Engine for Nadeo TrackMania and Nadeo Virtual Skipper 3 allows remote attackers to cause a denial of service (server crash) via malformed data to TCP port 2350, possibly due to long values or incorrect size fields.