Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2570▼ 302 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

28 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.51%—Coresmartcontracts UniswapAI29/4/202517/6/2026
An issue in Coresmartcontracts Uniswap v.3.0 and fixed in v.4.0 allows a remote attacker to escalate privileges via the _modifyPosition function
AplazadaMedia (6.5)0.26%—Oniswap Mini Twitter FeedAI24/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in oniswap Mini twitter feed mini-twitter-feed allows Stored XSS.This issue affects Mini twitter feed: from n/a through <= 3.0.
ModificadaMedia (5.4)0.56%—Swapnilsahu Stock Management System27/1/202417/6/2026
A vulnerability was found in CodeAstro Stock Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /index.php of the component Add Category Handler. The manipulation of the argument Category Name/Category Description leads to cross site scripting. The attack may be…
ModificadaAlta (7.5)0.39%—Uniswapfrontrunbot Project Uniswapfrontrunbot19/1/202417/6/2026
A vulnerability in UniswapFrontRunBot 0xdB94c allows attackers to cause financial losses via unspecified vectors.
ModificadaMedia (6.1)0.48%—Swapnilpatil Login AND Logout Redirect19/12/202317/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Swapnil V. Patil Login and Logout Redirect.This issue affects Login and Logout Redirect: from n/a through 2.0.3.
ModificadaMedia (4.3)0.46%—Menu Swapper Project Menu Swapper1/7/202317/6/2026
The Menu Swapper plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.0.2. This is due to missing or incorrect nonce validation on the mswp_save_meta() function. This makes it possible for unauthenticated attackers to save meta data via a forged request granted they…
ModificadaMedia (5.7)0.38%—Uniswap Web3-react Coinbase-walletUniswap Web3-react Eip1193Uniswap Web3-react MetamaskUniswap Web3-react Walletconnect17/4/202317/6/2026
@web3-react is a framework for building Ethereum Apps . In affected versions the `chainId` may be outdated if the user changes chains as part of the connection flow. This means that the value of `chainId` returned by `useWeb3React()` may be incorrect. In an application, this means that any data derived from `chainId`…
ModificadaAlta (7.5)0.76%—Uniswap Universal Router Firmware4/1/202317/6/2026
Uniswap Universal Router before 1.1.0 mishandles reentrancy. This would have allowed theft of funds.
ModificadaAlta (7.5)1.6%—Arc-swap Project Arc-swap25/12/202017/6/2026
An issue has been discovered in the arc-swap crate before 0.4.8 (and 1.x before 1.1.0) for Rust. Use of arc_swap::access::Map with the Constant test helper (or with a user-supplied implementation of the Access trait) could sometimes lead to dangling references being returned by the map.
ModificadaAlta (8.8)0.65%—Oswapp Warehouse Inventory System1/9/202017/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability in edit_user.php in OSWAPP Warehouse Inventory System (aka OSWA-INV) through 2020-08-10 allows remote attackers to change the admin's password after an authenticated admin visits a third-party site.
ModificadaCrítica (9.8)2.0%—Upperthemes Swape9/9/201917/6/2026
The Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator accounts via vectors involving xmlPath to wp-admin/admin-ajax.php.
ModificadaCrítica (9.8)3.3%—Thephpfactory Swap Factory28/9/201817/6/2026
SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter.
ModificadaAlta (7.5)1.1%—T-swap-token Project T-swap-token9/7/201817/6/2026
The mintToken function of a smart contract implementation for t_swap, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaAlta (7.5)1.0%—T-swap-token Project T-swap-token9/7/201817/6/2026
The mintToken function of a smart contract implementation for T-Swap-Token (T-S-T), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaAlta (7.5)1.0%—Airswaptoken Project Airswaptoken5/7/201817/6/2026
The sellBuyerTokens function of a smart contract implementation for SwapToken, an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.
ModificadaAlta (7.5)0.99%—T-swap-token Project T-swap-token5/7/201817/6/2026
The sell function of a smart contract implementation for T-Swap-Token (T-S-T), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.
ModificadaAlta (7.5)0.88%—Javaswaptest Project Javaswaptest4/7/201817/6/2026
The mintToken function of a smart contract implementation for JavaSwapTest (JST), an Ethereum token, has an integer overflow.
ModificadaAlta (8.8)1.0%—Iscripts Eswap25/5/201817/6/2026
iScripts eSwap v2.4 has SQL injection via the "search.php" 'Told' parameter in the User Panel.
ModificadaCrítica (9.8)1.2%—Iscripts Eswap22/5/201817/6/2026
iScripts eSwap v2.4 has SQL injection via the "salelistdetailed.php" User Panel ToId parameter.
ModificadaCrítica (9.8)1.2%—Iscripts Eswap22/5/201817/6/2026
iScripts eSwap v2.4 has SQL injection via the wishlistdetailed.php User Panel ToId parameter.
ModificadaMedia (6.1)0.67%—Iscripts Eswap16/4/201817/6/2026
iScripts eSwap v2.4 has Reflected XSS via the "catwiseproducts.php" catid parameter in the User Panel.
ModificadaAlta (7.2)1.0%—Iscripts Eswap11/4/201817/6/2026
iScripts eSwap v2.4 has SQL injection via the "registration_settings.php" ddlFree parameter in the Admin Panel.
ModificadaMedia (4.8)0.53%—Iscripts Eswap11/4/201817/6/2026
iScripts eSwap v2.4 has XSS via the "registration_settings.php" txtDate parameter in the Admin Panel.
ModificadaAlta (8.8)0.49%—Iscripts Eswap11/4/201817/6/2026
iScripts eSwap v2.4 has CSRF via "registration_settings.php" in the Admin Panel.
ModificadaMedia (5.3)0.41%—Comforte Swap1/3/201817/6/2026
comforte SWAP 1049 through 1069 and 20.0.0 through 21.5.3 (as used in SSLOBJ on HPE NonStop SSL T0910, and in the comforte SecurCS, SecurFTP, SecurLib/SSL-AT, and SecurTN products), after executing the RELOAD CERTIFICATES command, does not ensure that clients use a strong TLS cipher suite, which makes it easier for…