Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
94 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (1.9) | 0.19% | — | Squirrel-lang Squirrel | 26/5/2026 | 23/7/2026 | A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqobject.cpp of the component Cnut File Handler. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access. The exploit has been released to the… | |
| Aplazada | Baja (2) | 0.21% | — | Squirrel-lang SquirrelAI | 11/5/2026 | 23/7/2026 | A vulnerability was determined in Squirrel up to 3.2. This affects the function SQFunctionProto::Load of the file squirrel/sqobject.cpp. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. The project was… | |
| Aplazada | Baja (1.9) | 0.17% | — | Squirrel-lang SquirrelAI | 11/5/2026 | 23/7/2026 | A flaw has been found in Squirrel up to 3.2. Impacted is the function validate_format in the library sqstdlib/sqstdstring.cpp. Executing a manipulation can lead to stack-based buffer overflow. The attack can only be executed locally. The exploit has been published and may be used. The project was informed of the… | |
| Analizada | Baja (1.9) | 0.19% | — | Squirrel-lang Squirrel | 1/3/2026 | 17/6/2026 | A vulnerability was determined in Squirrel up to 3.2. This vulnerability affects the function sqstd_rex_newnode in the library sqstdlib/sqstdrex.cpp. Executing a manipulation can lead to null pointer dereference. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The… | |
| Analizada | Baja (1.9) | 0.19% | — | Squirrel-lang Squirrel | 1/3/2026 | 17/6/2026 | A vulnerability was found in Squirrel up to 3.2. This affects the function SQCompiler::Factor/SQCompiler::UnaryOP of the file squirrel/sqcompiler.cpp. Performing a manipulation results in uncontrolled recursion. The attack needs to be approached locally. The exploit has been made public and could be used. The project… | |
| Analizada | Baja (1.9) | 0.23% | — | Squirrel-lang Squirrel | 18/2/2026 | 17/6/2026 | A security flaw has been discovered in Squirrel up to 3.2. This affects the function SQObjectPtr::operator in the library squirrel/sqobject.h. The manipulation results in heap-based buffer overflow. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. The… | |
| Analizada | Baja (1.9) | 0.21% | — | Squirrel-lang Squirrel | 18/2/2026 | 17/6/2026 | A vulnerability was determined in Squirrel up to 3.2. Affected by this vulnerability is the function SQFuncState::PopTarget of the file src/squirrel/squirrel/sqfuncstate.cpp. Executing a manipulation of the argument _target_stack can lead to out-of-bounds read. It is possible to launch the attack on the local host.… | |
| Aplazada | Media (4.4) | 0.19% | — | Squirrels Auto InventoryAI | 11/11/2025 | 17/6/2026 | The Squirrels Auto Inventory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,… | |
| Aplazada | Alta (7.2) | 0.27% | — | SquirrelmailAI | 2/4/2025 | 17/6/2026 | mime.php in SquirrelMail through 1.4.23-svn-20250401 and 1.5.x through 1.5.2-svn-20250401 allows XSS via e-mail headers, because JavaScript payloads are mishandled after $encoded has been set to true. | |
| Modificada | Crítica (9.8) | 1.1% | — | Squirrelly | 21/8/2024 | 17/6/2026 | squirrellyjs squirrelly v9.0.0 and fixed in v.9.0.1 was discovered to contain a code injection vulnerability via the component options.varName. | |
| Modificada | Alta (7.8) | 0.41% | — | Squirrel.windows Project Squirrel.windows | 21/12/2022 | 17/6/2026 | Squirrel.Windows is both a toolset and a library that provides installation and update functionality for Windows desktop applications. Installers generated by Squirrel.Windows 2.0.1 and earlier contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result,… | |
| Modificada | Crítica (10) | 2.8% | — | Squirrel-lang SquirrelFedoraproject Fedora | 28/7/2022 | 17/6/2026 | sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that can lead to Code Execution. If a victim executes an attacker-controlled squirrel script, it is possible for the attacker to break out of the squirrel script sandbox even if all dangerous functionality… | |
| Modificada | Crítica (10) | 3.6% | — | Squirrel-lang SquirrelFedoraproject Fedora | 4/5/2022 | 17/6/2026 | Heap-based buffer overflow in sqbaselib.cpp in SQUIRREL 3.2 due to lack of a certain sq_reservestack call. | |
| Modificada | Alta (8.8) | 58% | — | Squirrelly | 14/5/2021 | 17/6/2026 | Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration options remote code execution may be triggered in downstream applications. This… | |
| Modificada | Alta (8.8) | 1.4% | — | Squirrelmail | 20/6/2020 | 17/6/2026 | compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request. NOTE: the vendor disputes this because these two conditions for PHP object injection are not satisfied: existence of a PHP magic method (such as __wakeup or __destruct), and any attack-relevant… | |
| Modificada | Crítica (9.8) | 1.4% | — | Squirrelmail | 20/6/2020 | 17/6/2026 | compose.php in SquirrelMail 1.4.22 calls unserialize for the $mailtodata value, which originates from an HTTP GET request. This is related to mailto.php. | |
| Modificada | Alta (7.5) | 0.67% | — | Squirrelmail Change Passwd | 13/2/2020 | 16/6/2026 | Squirrelmail 4.0 uses the outdated MD5 hash algorithm for passwords. | |
| Modificada | Media (6.1) | 1.8% | — | Squirrelmail | 1/7/2019 | 17/6/2026 | XSS was discovered in SquirrelMail through 1.4.22 and 1.5.x through 1.5.2. Due to improper handling of RCDATA and RAWTEXT type elements, the built-in sanitization mechanism can be bypassed. Malicious script content from HTML e-mail can be executed within the application context via crafted use of (for example) a… | |
| Modificada | Media (6.1) | 1.4% | — | Squirrelmail | 5/8/2018 | 17/6/2026 | The mail message display page in SquirrelMail through 1.4.22 has XSS via SVG animations (animate to attribute). | |
| Modificada | Media (6.1) | 1.6% | — | Squirrelmail | 5/8/2018 | 17/6/2026 | The mail message display page in SquirrelMail through 1.4.22 has XSS via the formaction attribute. | |
| Modificada | Media (6.1) | 1.4% | — | Squirrelmail | 5/8/2018 | 17/6/2026 | The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack. | |
| Modificada | Media (6.1) | 1.4% | — | Squirrelmail | 5/8/2018 | 17/6/2026 | The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math><maction xlink:href=" attack. | |
| Modificada | Media (6.1) | 1.4% | — | Squirrelmail | 5/8/2018 | 17/6/2026 | The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<form action='data:text" attack. | |
| Modificada | Media (6.1) | 1.4% | — | Squirrelmail | 5/8/2018 | 17/6/2026 | The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<svg><a xlink:href=" attack. | |
| Modificada | Alta (8.8) | 4.2% | — | SquirrelmailDebian Linux | 17/3/2018 | 17/6/2026 | A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the hosting server, related to ../ in the att_local_name field in Deliver.class.php. |