Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2550▼ 376 respecto a la semana anterior
Críticas / altas1325▲ 47 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
103 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 1.1% | — | Hiraishikentaro Wezterm MCPAI | 1/6/2026 | 22/7/2026 | A vulnerability was identified in hiraishikentaro wezterm-mcp 0.1.0. The affected element is an unknown function of the file src/wezterm_executor.ts of the component switch_pane/write_to_specific_pane. The manipulation of the argument request.params.arguments.pane_id leads to os command injection. The attack can be… | |
| Analizada | Alta (7.8) | 0.77% | — | Wkentaro Gdown | 18/4/2026 | 17/6/2026 | gdown is a Google Drive public file/folder downloader. Versions prior to 5.2.2 are vulnerable to a Path Traversal attack within the extractall functionality. When extracting a maliciously crafted ZIP or TAR archive, the library fails to sanitize or validate the filenames of the archive members. This allow files to be… | |
| Analizada | Media (6.8) | 0.33% | — | Svenstaro Miniserve | 23/1/2026 | 17/6/2026 | A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared… | |
| Aplazada | Alta (8.1) | 0.62% | — | Ancorathemes MilitarologyAI | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Militarology militarology allows PHP Local File Inclusion.This issue affects Militarology: from n/a through <= 1.0.15. | |
| Analizada | Media (5.3) | 0.61% | — | Taro | 9/6/2025 | 17/6/2026 | A vulnerability was found in tarojs taro up to 4.1.1. It has been declared as problematic. This vulnerability affects unknown code of the file taro/packages/css-to-react-native/src/index.js. The manipulation leads to inefficient regular expression complexity. The attack can be initiated remotely. Upgrading to version… | |
| Analizada | Crítica (10) | 99% | ⚠ Explotación activa | Erlang/otpCisco Confd BasicCisco Network Services OrchestratorCisco Cloud Native Broadband Network Gateway+19 | 16/4/2025 | 17/6/2026 | Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain… | |
| Aplazada | Media (6.4) | 0.39% | — | Horoscope AND TarotAI | 7/1/2025 | 17/6/2026 | The Horoscope And Tarot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'divine_horoscope' shortcode in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.5) | 0.24% | — | Nutttaro Video Player FOR WpbakeryAI | 1/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nutttaro Video Player for WPBakery video-player-for-wpbakery allows Stored XSS.This issue affects Video Player for WPBakery: from n/a through <= 1.0.1. | |
| Aplazada | Media (5.3) | 0.81% | — | Cisco ASR 5000 Series SoftwareAICisco StarosAI | 18/11/2024 | 17/6/2026 | A vulnerability in the ipsecmgr process of Cisco ASR 5000 Series Software (StarOS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to insufficient validation of incoming Internet Key Exchange Version 2 (IKEv2) packets. An attacker could… | |
| Aplazada | Alta (8.1) | 12% | — | Cisco RCMAICisco StarosAI | 15/11/2024 | 17/6/2026 | A vulnerability in Cisco RCM for Cisco StarOS Software could allow an unauthenticated, remote attacker to perform remote code execution on the application with root-level privileges in the context of the configured container. This vulnerability exists because the debug mode is incorrectly enabled for… | |
| Aplazada | Media (5.3) | 1.0% | — | Cisco RCMAICisco StarosAI | 15/11/2024 | 17/6/2026 | A vulnerability in a debug function for Cisco RCM for Cisco StarOS Software could allow an unauthenticated, remote attacker to perform debug actions that could result in the disclosure of confidential information that should be restricted. This vulnerability exists because of a debug service that incorrectly… | |
| Modificada | Alta (7.8) | 0.68% | — | Justsystems Easy Postcard MAXJustsystems Ichitaro 2021Justsystems Ichitaro 2022Justsystems Ichitaro 2023+15 | 19/10/2023 | 17/6/2026 | An out-of-bounds write vulnerability exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause a type confusion, which can lead to memory corruption and eventually arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Alta (7.8) | 0.65% | — | Justsystems Easy Postcard MAXJustsystems Ichitaro 2021Justsystems Ichitaro 2022Justsystems Ichitaro 2023+15 | 19/10/2023 | 17/6/2026 | An integer overflow exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause the parser to make an under-sized allocation, which can later allow for memory corruption, potentially resulting in arbitrary code execution. An attacker can provide a malicious file to… | |
| Modificada | Alta (7.8) | 0.64% | — | Justsystems Easy Postcard MAXJustsystems Ichitaro 2021Justsystems Ichitaro 2022Justsystems Ichitaro 2023+15 | 19/10/2023 | 17/6/2026 | A use-after-free vulnerability exists in the Figure stream parsing functionality of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause memory corruption, resulting in arbitrary code execution. Victim would need to open a malicious file to trigger this vulnerability. | |
| Modificada | Alta (7.8) | 0.48% | — | Justsystems Easy Postcard MAXJustsystems Ichitaro 2021Justsystems Ichitaro 2022Justsystems Ichitaro 2023+15 | 19/10/2023 | 17/6/2026 | An out-of-bounds write vulnerability exists within the parsers for both the "DocumentViewStyles" and "DocumentEditStyles" streams of Ichitaro 2023 1.0.1.59372 when processing types 0x0000-0x0009 of a style record with the type 0x2008. A specially crafted document can cause memory corruption, which can lead to… | |
| Modificada | Alta (8.8) | 0.86% | — | Cisco Staros | 9/5/2023 | 17/6/2026 | A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied credentials. An attacker could exploit this vulnerability by sending a… | |
| Modificada | Alta (7.8) | 0.54% | — | Justsystems Ichitaro 2022 | 5/4/2023 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in the way Ichitaro version 2022 1.0.1.57600 processes certain LayoutBox stream record types. A specially crafted document can cause a buffer overflow, leading to memory corruption, which can result in arbitrary code execution.To trigger this vulnerability, the victim… | |
| Modificada | Alta (7.8) | 0.45% | — | Justsystems Ichitaro 2022 | 5/4/2023 | 17/6/2026 | An invalid free vulnerability exists in the Frame stream parser functionality of Ichitaro 2022 1.0.1.57600. A specially crafted document can lead to an attempt to free a stack pointer, which causes memory corruption. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Alta (7.8) | 0.52% | — | Justsystems Ichitaro 2022 | 5/4/2023 | 17/6/2026 | A buffer overflow vulnerability exists in the Attribute Arena functionality of Ichitaro 2022 1.0.1.57600. A specially crafted document can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Alta (7.8) | 0.53% | — | Justsystems Ichitaro 2022 | 5/4/2023 | 17/6/2026 | A use-after-free vulnerability exists within the way Ichitaro Word Processor 2022, version 1.0.1.57600, processes protected documents. A specially crafted document can trigger reuse of freed memory, which can lead to further memory corruption and potentially result in arbitrary code execution. An attacker can provide… | |
| Modificada | Crítica (9.8) | 0.85% | — | Justsystems Atok Medical 2Justsystems Atok Medical 3Justsystems Atok PRO 3Justsystems Atok PRO 4+56 | 16/8/2022 | 17/6/2026 | An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted file path, a malicious file may be executed with the privilege of… | |
| Modificada | Media (6.7) | 0.31% | — | Cisco Staros | 6/4/2022 | 17/6/2026 | A vulnerability in the CLI of Cisco StarOS could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient input validation of CLI commands. An attacker could exploit this vulnerability by sending crafted commands to the CLI. A successful exploit… | |
| Modificada | Crítica (9.8) | 3.5% | — | Datarobot | 28/2/2022 | 17/6/2026 | A Remote Code Execution (RCE) vulnerability exists in DataRobot through 2021-10-28 because it allows submission of a Docker environment or Java driver. | |
| Modificada | Alta (7.5) | 1.3% | — | Taro | 17/9/2021 | 17/6/2026 | taro is vulnerable to Inefficient Regular Expression Complexity | |
| Modificada | Alta (7.2) | 1.1% | — | Cisco StarosCisco Virtualized Packet Core | 4/6/2021 | 17/6/2026 | Multiple vulnerabilities in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenticated, remote attacker to bypass authorization and execute a subset of CLI commands on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. |