Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

94 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (1.9)0.19%—Squirrel-lang Squirrel26/5/202623/7/2026
A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqobject.cpp of the component Cnut File Handler. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access. The exploit has been released to the…
AplazadaBaja (2)0.21%—Squirrel-lang SquirrelAI11/5/202623/7/2026
A vulnerability was determined in Squirrel up to 3.2. This affects the function SQFunctionProto::Load of the file squirrel/sqobject.cpp. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. The project was…
AplazadaBaja (1.9)0.17%—Squirrel-lang SquirrelAI11/5/202623/7/2026
A flaw has been found in Squirrel up to 3.2. Impacted is the function validate_format in the library sqstdlib/sqstdstring.cpp. Executing a manipulation can lead to stack-based buffer overflow. The attack can only be executed locally. The exploit has been published and may be used. The project was informed of the…
AnalizadaBaja (1.9)0.19%—Squirrel-lang Squirrel1/3/202617/6/2026
A vulnerability was determined in Squirrel up to 3.2. This vulnerability affects the function sqstd_rex_newnode in the library sqstdlib/sqstdrex.cpp. Executing a manipulation can lead to null pointer dereference. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The…
AnalizadaBaja (1.9)0.19%—Squirrel-lang Squirrel1/3/202617/6/2026
A vulnerability was found in Squirrel up to 3.2. This affects the function SQCompiler::Factor/SQCompiler::UnaryOP of the file squirrel/sqcompiler.cpp. Performing a manipulation results in uncontrolled recursion. The attack needs to be approached locally. The exploit has been made public and could be used. The project…
AnalizadaBaja (1.9)0.23%—Squirrel-lang Squirrel18/2/202617/6/2026
A security flaw has been discovered in Squirrel up to 3.2. This affects the function SQObjectPtr::operator in the library squirrel/sqobject.h. The manipulation results in heap-based buffer overflow. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. The…
AnalizadaBaja (1.9)0.21%—Squirrel-lang Squirrel18/2/202617/6/2026
A vulnerability was determined in Squirrel up to 3.2. Affected by this vulnerability is the function SQFuncState::PopTarget of the file src/squirrel/squirrel/sqfuncstate.cpp. Executing a manipulation of the argument _target_stack can lead to out-of-bounds read. It is possible to launch the attack on the local host.…
AplazadaMedia (4.4)0.19%—Squirrels Auto InventoryAI11/11/202517/6/2026
The Squirrels Auto Inventory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,…
AplazadaAlta (7.2)0.27%—SquirrelmailAI2/4/202517/6/2026
mime.php in SquirrelMail through 1.4.23-svn-20250401 and 1.5.x through 1.5.2-svn-20250401 allows XSS via e-mail headers, because JavaScript payloads are mishandled after $encoded has been set to true.
ModificadaCrítica (9.8)1.1%—Squirrelly21/8/202417/6/2026
squirrellyjs squirrelly v9.0.0 and fixed in v.9.0.1 was discovered to contain a code injection vulnerability via the component options.varName.
ModificadaAlta (7.8)0.41%—Squirrel.windows Project Squirrel.windows21/12/202217/6/2026
Squirrel.Windows is both a toolset and a library that provides installation and update functionality for Windows desktop applications. Installers generated by Squirrel.Windows 2.0.1 and earlier contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result,…
ModificadaCrítica (10)2.8%—Squirrel-lang SquirrelFedoraproject Fedora28/7/202217/6/2026
sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that can lead to Code Execution. If a victim executes an attacker-controlled squirrel script, it is possible for the attacker to break out of the squirrel script sandbox even if all dangerous functionality…
ModificadaCrítica (10)3.6%—Squirrel-lang SquirrelFedoraproject Fedora4/5/202217/6/2026
Heap-based buffer overflow in sqbaselib.cpp in SQUIRREL 3.2 due to lack of a certain sq_reservestack call.
ModificadaAlta (8.8)58%—Squirrelly14/5/202117/6/2026
Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration options remote code execution may be triggered in downstream applications. This…
ModificadaAlta (8.8)1.4%—Squirrelmail20/6/202017/6/2026
compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request. NOTE: the vendor disputes this because these two conditions for PHP object injection are not satisfied: existence of a PHP magic method (such as __wakeup or __destruct), and any attack-relevant…
ModificadaCrítica (9.8)1.4%—Squirrelmail20/6/202017/6/2026
compose.php in SquirrelMail 1.4.22 calls unserialize for the $mailtodata value, which originates from an HTTP GET request. This is related to mailto.php.
ModificadaAlta (7.5)0.67%—Squirrelmail Change Passwd13/2/202016/6/2026
Squirrelmail 4.0 uses the outdated MD5 hash algorithm for passwords.
ModificadaMedia (6.1)1.8%—Squirrelmail1/7/201917/6/2026
XSS was discovered in SquirrelMail through 1.4.22 and 1.5.x through 1.5.2. Due to improper handling of RCDATA and RAWTEXT type elements, the built-in sanitization mechanism can be bypassed. Malicious script content from HTML e-mail can be executed within the application context via crafted use of (for example) a…
ModificadaMedia (6.1)1.4%—Squirrelmail5/8/201817/6/2026
The mail message display page in SquirrelMail through 1.4.22 has XSS via SVG animations (animate to attribute).
ModificadaMedia (6.1)1.6%—Squirrelmail5/8/201817/6/2026
The mail message display page in SquirrelMail through 1.4.22 has XSS via the formaction attribute.
ModificadaMedia (6.1)1.4%—Squirrelmail5/8/201817/6/2026
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack.
ModificadaMedia (6.1)1.4%—Squirrelmail5/8/201817/6/2026
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math><maction xlink:href=" attack.
ModificadaMedia (6.1)1.4%—Squirrelmail5/8/201817/6/2026
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<form action='data:text" attack.
ModificadaMedia (6.1)1.4%—Squirrelmail5/8/201817/6/2026
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<svg><a xlink:href=" attack.
ModificadaAlta (8.8)4.2%—SquirrelmailDebian Linux17/3/201817/6/2026
A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the hosting server, related to ../ in the att_local_name field in Deliver.class.php.