Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 302 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
28 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.51% | — | Coresmartcontracts UniswapAI | 29/4/2025 | 17/6/2026 | An issue in Coresmartcontracts Uniswap v.3.0 and fixed in v.4.0 allows a remote attacker to escalate privileges via the _modifyPosition function | |
| Aplazada | Media (6.5) | 0.26% | — | Oniswap Mini Twitter FeedAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in oniswap Mini twitter feed mini-twitter-feed allows Stored XSS.This issue affects Mini twitter feed: from n/a through <= 3.0. | |
| Modificada | Media (5.4) | 0.56% | — | Swapnilsahu Stock Management System | 27/1/2024 | 17/6/2026 | A vulnerability was found in CodeAstro Stock Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /index.php of the component Add Category Handler. The manipulation of the argument Category Name/Category Description leads to cross site scripting. The attack may be… | |
| Modificada | Alta (7.5) | 0.39% | — | Uniswapfrontrunbot Project Uniswapfrontrunbot | 19/1/2024 | 17/6/2026 | A vulnerability in UniswapFrontRunBot 0xdB94c allows attackers to cause financial losses via unspecified vectors. | |
| Modificada | Media (6.1) | 0.48% | — | Swapnilpatil Login AND Logout Redirect | 19/12/2023 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Swapnil V. Patil Login and Logout Redirect.This issue affects Login and Logout Redirect: from n/a through 2.0.3. | |
| Modificada | Media (4.3) | 0.46% | — | Menu Swapper Project Menu Swapper | 1/7/2023 | 17/6/2026 | The Menu Swapper plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.0.2. This is due to missing or incorrect nonce validation on the mswp_save_meta() function. This makes it possible for unauthenticated attackers to save meta data via a forged request granted they… | |
| Modificada | Media (5.7) | 0.38% | — | Uniswap Web3-react Coinbase-walletUniswap Web3-react Eip1193Uniswap Web3-react MetamaskUniswap Web3-react Walletconnect | 17/4/2023 | 17/6/2026 | @web3-react is a framework for building Ethereum Apps . In affected versions the `chainId` may be outdated if the user changes chains as part of the connection flow. This means that the value of `chainId` returned by `useWeb3React()` may be incorrect. In an application, this means that any data derived from `chainId`… | |
| Modificada | Alta (7.5) | 0.76% | — | Uniswap Universal Router Firmware | 4/1/2023 | 17/6/2026 | Uniswap Universal Router before 1.1.0 mishandles reentrancy. This would have allowed theft of funds. | |
| Modificada | Alta (7.5) | 1.6% | — | Arc-swap Project Arc-swap | 25/12/2020 | 17/6/2026 | An issue has been discovered in the arc-swap crate before 0.4.8 (and 1.x before 1.1.0) for Rust. Use of arc_swap::access::Map with the Constant test helper (or with a user-supplied implementation of the Access trait) could sometimes lead to dangling references being returned by the map. | |
| Modificada | Alta (8.8) | 0.65% | — | Oswapp Warehouse Inventory System | 1/9/2020 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability in edit_user.php in OSWAPP Warehouse Inventory System (aka OSWA-INV) through 2020-08-10 allows remote attackers to change the admin's password after an authenticated admin visits a third-party site. | |
| Modificada | Crítica (9.8) | 2.0% | — | Upperthemes Swape | 9/9/2019 | 17/6/2026 | The Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator accounts via vectors involving xmlPath to wp-admin/admin-ajax.php. | |
| Modificada | Crítica (9.8) | 3.3% | — | Thephpfactory Swap Factory | 28/9/2018 | 17/6/2026 | SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | T-swap-token Project T-swap-token | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for t_swap, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.5) | 1.0% | — | T-swap-token Project T-swap-token | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for T-Swap-Token (T-S-T), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.5) | 1.0% | — | Airswaptoken Project Airswaptoken | 5/7/2018 | 17/6/2026 | The sellBuyerTokens function of a smart contract implementation for SwapToken, an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets. | |
| Modificada | Alta (7.5) | 0.99% | — | T-swap-token Project T-swap-token | 5/7/2018 | 17/6/2026 | The sell function of a smart contract implementation for T-Swap-Token (T-S-T), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets. | |
| Modificada | Alta (7.5) | 0.88% | — | Javaswaptest Project Javaswaptest | 4/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for JavaSwapTest (JST), an Ethereum token, has an integer overflow. | |
| Modificada | Alta (8.8) | 1.0% | — | Iscripts Eswap | 25/5/2018 | 17/6/2026 | iScripts eSwap v2.4 has SQL injection via the "search.php" 'Told' parameter in the User Panel. | |
| Modificada | Crítica (9.8) | 1.2% | — | Iscripts Eswap | 22/5/2018 | 17/6/2026 | iScripts eSwap v2.4 has SQL injection via the "salelistdetailed.php" User Panel ToId parameter. | |
| Modificada | Crítica (9.8) | 1.2% | — | Iscripts Eswap | 22/5/2018 | 17/6/2026 | iScripts eSwap v2.4 has SQL injection via the wishlistdetailed.php User Panel ToId parameter. | |
| Modificada | Media (6.1) | 0.67% | — | Iscripts Eswap | 16/4/2018 | 17/6/2026 | iScripts eSwap v2.4 has Reflected XSS via the "catwiseproducts.php" catid parameter in the User Panel. | |
| Modificada | Alta (7.2) | 1.0% | — | Iscripts Eswap | 11/4/2018 | 17/6/2026 | iScripts eSwap v2.4 has SQL injection via the "registration_settings.php" ddlFree parameter in the Admin Panel. | |
| Modificada | Media (4.8) | 0.53% | — | Iscripts Eswap | 11/4/2018 | 17/6/2026 | iScripts eSwap v2.4 has XSS via the "registration_settings.php" txtDate parameter in the Admin Panel. | |
| Modificada | Alta (8.8) | 0.49% | — | Iscripts Eswap | 11/4/2018 | 17/6/2026 | iScripts eSwap v2.4 has CSRF via "registration_settings.php" in the Admin Panel. | |
| Modificada | Media (5.3) | 0.41% | — | Comforte Swap | 1/3/2018 | 17/6/2026 | comforte SWAP 1049 through 1069 and 20.0.0 through 21.5.3 (as used in SSLOBJ on HPE NonStop SSL T0910, and in the comforte SecurCS, SecurFTP, SecurLib/SSL-AT, and SecurTN products), after executing the RELOAD CERTIFICATES command, does not ensure that clients use a strong TLS cipher suite, which makes it easier for… |