Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2584▼ 301 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 0.16% | — | Solhsa SoloudAI | 12/3/2026 | 17/6/2026 | A vulnerability has been found in jarikomppa soloud up to 20200207. Impacted is the function drwav_read_pcm_frames_s16__msadpcm in the library src/audiosource/wav/dr_wav.h of the component WAV File Parser. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The exploit has been… | |
| Analizada | Baja (1.9) | 0.20% | — | Solhsa Soloud | 1/3/2026 | 17/6/2026 | A vulnerability was detected in jarikomppa soloud up to 20200207. This affects the function SoLoud::Wav::loadwav of the file src/audiosource/wav/soloud_wav.cpp of the component WAV File Parser. Performing a manipulation results in memory corruption. The attack must be initiated from a local position. The exploit is… | |
| Analizada | Baja (1.9) | 0.23% | — | Solhsa Soloud | 1/3/2026 | 17/6/2026 | A security vulnerability has been detected in jarikomppa soloud up to 20200207. The impacted element is the function SoLoud::Wav::loadflac of the file src/audiosource/wav/soloud_wav.cpp of the component Audio File Handler. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally.… | |
| Analizada | Alta (7.8) | 1.0% | — | Coding-solo Godot MCP | 4/2/2026 | 17/6/2026 | Godot MCP is a Model Context Protocol (MCP) server for interacting with the Godot game engine. Prior to version 0.1.1, a command injection vulnerability in godot-mcp allows remote code execution. The executeOperation function passed user-controlled input (e.g., projectPath) directly to exec(), which spawns a shell. An… | |
| Analizada | Baja (2.1) | 0.38% | — | Adlered Bolo-solo | 4/2/2026 | 17/6/2026 | A vulnerability was found in bolo-blog bolo-solo up to 2.6.4. Affected is an unknown function of the file src/main/java/org/b3log/solo/bolo/pic/PicUploadProcessor.java of the component FreeMarker Template Handler. The manipulation of the argument File results in unrestricted upload. It is possible to launch the attack… | |
| Analizada | Baja (2.1) | 0.48% | — | Adlered Bolo-solo | 3/2/2026 | 17/6/2026 | A vulnerability has been found in bolo-blog bolo-solo up to 2.6.4. This impacts the function importFromCnblogs of the file src/main/java/org/b3log/solo/bolo/prop/BackupService.java of the component Filename Handler. The manipulation of the argument File leads to path traversal. It is possible to initiate the attack… | |
| Analizada | Baja (2.1) | 0.52% | — | Adlered Bolo-solo | 3/2/2026 | 17/6/2026 | A flaw has been found in bolo-blog bolo-solo up to 2.6.4. This affects the function importFromMarkdown of the file src/main/java/org/b3log/solo/bolo/prop/BackupService.java of the component Filename Handler. Executing a manipulation of the argument File can lead to path traversal. The attack may be performed from… | |
| Analizada | Baja (2.1) | 0.46% | — | Adlered Bolo-solo | 3/2/2026 | 17/6/2026 | A vulnerability was detected in bolo-blog bolo-solo up to 2.6.4. The impacted element is the function unpackFilteredZip of the file src/main/java/org/b3log/solo/bolo/prop/BackupService.java of the component ZIP File Handler. Performing a manipulation of the argument File results in path traversal. The attack is… | |
| Analizada | Baja (2.1) | 0.57% | — | Adlered Bolo-solo | 30/1/2026 | 17/6/2026 | A vulnerability has been found in bolo-solo up to 2.6.4. This impacts the function importMarkdownsSync of the file src/main/java/org/b3log/solo/bolo/prop/BackupService.java of the component SnakeYAML. Such manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Aplazada | Crítica (9.3) | 0.96% | — | Burk Technology ARC SoloAI | 8/8/2025 | 17/6/2026 | Burk Technology ARC Solo's password change mechanism can be utilized without proper authentication procedures, allowing an attacker to take over the device. A password change request can be sent directly to the device's HTTP endpoint without providing valid credentials. The system does not enforce proper… | |
| Analizada | Media (6.1) | 0.50% | — | Noear Solon | 13/6/2025 | 17/6/2026 | Directory Traversal vulnerability in solon v.3.1.2 allows a remote attacker to conduct XSS attacks via the solon-faas-luffy component | |
| Aplazada | Media (5.3) | 0.46% | — | OpensolonAI | 30/3/2025 | 17/6/2026 | A vulnerability classified as problematic was found in opensolon up to 3.1.0. This vulnerability affects the function render_mav of the file /aa of the component org.noear.solon.core.handle.RenderManager. The manipulation of the argument template with the input ../org/example/HelloApp.class leads to path traversal:… | |
| Aplazada | Media (5.3) | 0.57% | — | Opensolon SolonAI | 23/2/2025 | 17/6/2026 | A vulnerability classified as problematic was found in opensolon Solon up to 3.0.8. This vulnerability affects unknown code of the file solon-projects/solon-web/solon-web-staticfiles/src/main/java/org/noear/solon/web/staticfiles/StaticMappings.java. The manipulation leads to path traversal: '../filedir'. The attack… | |
| Modificada | Crítica (9.8) | 0.92% | — | Noear Solon | 4/12/2023 | 17/6/2026 | Ssolon <= 2.6.0 and <=2.5.12 is vulnerable to Deserialization of Untrusted Data. | |
| Modificada | Crítica (9.8) | 1.7% | — | Adlered Bolo-solo | 5/9/2023 | 9/7/2026 | File Upload vulnerability in adlered bolo-solo v.2.6 allows a remote attacker to execute arbitrary code via a crafted script to the authorization field in the header. | |
| Modificada | Crítica (9.8) | 1.1% | — | Solon | 19/6/2023 | 17/6/2026 | A bypass in the component sofa-hessian of Solon before v2.3.3 allows attackers to execute arbitrary code via providing crafted payload. | |
| Modificada | Media (6.1) | 0.51% | — | Linuxfoundation Fossology | 4/1/2023 | 17/6/2026 | A vulnerability has been found in fossology and classified as problematic. This vulnerability affects unknown code. The manipulation of the argument sql/VarValue leads to cross site scripting. The attack can be initiated remotely. The patch is identified as 8e0eba001662c7eb35f045b70dd458a4643b4553. It is recommended… | |
| Modificada | Media (4.6) | 0.59% | — | NXP I.mx 6 FirmwareNXP I.mx 6dual FirmwareNXP I.mx 6duallite FirmwareNXP I.mx 6dualplus Firmware+19 | 18/11/2022 | 17/6/2026 | An information-disclosure vulnerability exists on select NXP devices when configured in Serial Download Protocol (SDP) mode: i.MX RT 1010, i.MX RT 1015, i.MX RT 1020, i.MX RT 1050, i.MX RT 1060, i.MX 6 Family, i.MX 7Dual/Solo, i.MX 7ULP, i.MX 8M Quad, i.MX 8M Mini, and Vybrid. In a device security-enabled… | |
| Modificada | Media (6.1) | 1.6% | — | Nuuo Nvrsolo Firmware | 21/6/2022 | 17/6/2026 | NUUO Network Video Recorder NVRsolo v03.06.02 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via login.php. | |
| Modificada | Alta (8.8) | 0.82% | — | Eufylife Solo Indoorcam C24 FirmwareEufylife Solo Indoorcam P24 Firmware | 31/5/2022 | 17/6/2026 | A Buffer Overflow vulnerability in the RSTP server component of Eufy Indoor 2K Indoor Camera allows a local attacker to achieve remote code execution. This issue affects: Eufy Indoor 2K Indoor Camera 2.0.9.3 version and prior versions. | |
| Modificada | Media (6.1) | 0.80% | — | Nuuo Nvrsolo Firmware | 28/12/2021 | 17/6/2026 | NUUO Network Video Recorder NVRsolo 3.9.1 is affected by a Cross Site Scripting (XSS) vulnerability. An attacker can steal the user's session by injecting malicious JavaScript codes which leads to session hijacking. | |
| Modificada | Media (6.8) | 0.33% | — | Solokeys Solo FirmwareSolokeys Somu FirmwareNitrokey Fido2 Firmware | 21/5/2021 | 17/6/2026 | The flash read-out protection (RDP) level is not enforced during the device initialization phase of the SoloKeys Solo 4.0.0 & Somu and the Nitrokey FIDO2 token. This allows an adversary to downgrade the RDP level and access secrets such as private ECC keys from SRAM via the debug interface. | |
| Modificada | Media (6.1) | 1.00% | — | B3log Solo | 20/6/2019 | 17/6/2026 | b3log Solo 2.9.3 has XSS in the Input page under the "Publish Articles" menu with an ID of "articleTags" stored in the "tag" JSON field, which allows remote attackers to inject arbitrary Web scripts or HTML via a carefully crafted site name in an admin-authenticated HTTP request. | |
| Modificada | Alta (7.8) | 0.33% | — | Hidglobal Easylobby Solo | 21/3/2019 | 17/6/2026 | EasyLobby Solo contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application. | |
| Modificada | Alta (7.8) | 0.34% | — | Hidglobal Easylobby Solo | 21/3/2019 | 17/6/2026 | EasyLobby Solo could allow a local attacker to gain elevated privileges on the system. By visiting the kiosk and typing "esc" to exit the program, an attacker could exploit this vulnerability to perform unauthorized actions on the computer. |