Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 329 respecto a la semana anterior
Críticas / altas1353▲ 95 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.26% | — | Star-citizen EmbedvideoAI | 24/9/2026 | 30/9/2026 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with $wgEmbedVideoRequireConsent disabled (not the default), the urls for videos are passed into an iframe src attribute… | |
| Aplazada | Alta (7.5) | 0.49% | — | Star-citizen EmbedvideoAI | 15/9/2026 | 30/9/2026 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedServiceFactory::newFromName in includes/EmbedService/EmbedServiceFactory.php interpolates an attacker-controlled unknown… | |
| Aplazada | Media (6.3) | 0.13% | — | Samsung TizenfxAI | 3/9/2026 | 8/9/2026 | Out-of-bounds Write and Improper Validation of Array Index vulnerability in Samsung Open Source TizenFX Samsung/TizenFX allows Overflow Buffers. | |
| Aplazada | Media (6.5) | 0.45% | — | Starcitizen.tools CitizenAI | 17/10/2025 | 17/6/2026 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Citizen from 3.3.0 to 3.9.0 are vulnerable to stored cross-site scripting in the sticky header button message handling. In stickyHeader.js the copyButtonAttributes function assigns innerHTML from a source element’s textContent when… | |
| Analizada | Media (5.4) | 0.30% | — | Star-citizen Embedvideo | 25/9/2025 | 17/6/2026 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. In versions 4.0.0 and prior, the EmbedVideo extension allows adding arbitrary attributes to an HTML element, allowing for stored XSS through… | |
| Analizada | Media (5.4) | 0.35% | — | Starcitizen.tools Citizen | 3/7/2025 | 17/6/2026 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. From versions 1.9.4 to before 3.4.0, short descriptions set via the ShortDescription extension are inserted as raw HTML by the Citizen skin, allowing any user to insert arbitrary HTML into the DOM by editing a page. This issue has been… | |
| Analizada | Media (5.4) | 0.32% | — | Starcitizen.tools Citizen | 3/7/2025 | 17/6/2026 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. From versions 1.9.4 to before 3.4.0, page descriptions are inserted into raw HTML without proper sanitization by the Citizen skin when using the old search bar. Any user with page editing privileges can insert cross-site scripting (XSS)… | |
| Analizada | Media (4.8) | 0.41% | — | Starcitizen.tools Citizen | 12/6/2025 | 17/6/2026 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. All system messages in menu headings using the Menu.mustache template are inserted as raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This impacts wikis where a group has the `editinterface`… | |
| Analizada | Media (5.4) | 0.42% | — | Starcitizen.tools Citizen | 12/6/2025 | 17/6/2026 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various date messages returned by `Language::userDate` are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This impacts wikis where a group has the `editinterface` but not the… | |
| Analizada | Media (5.4) | 0.41% | — | Starcitizen.tools Citizen | 12/6/2025 | 17/6/2026 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Various preferences messages are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This vulnerability is fixed in 3.3.1. | |
| Analizada | Media (5.4) | 0.41% | — | Starcitizen.tools Citizen | 12/6/2025 | 17/6/2026 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The citizen-search-noresults-title and citizen-search-noresults-desc system messages are inserted into raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This vulnerability is fixed in 3.3.1. | |
| Analizada | Media (5.4) | 0.41% | — | Starcitizen.tools Citizen | 12/6/2025 | 17/6/2026 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Multiple system messages are inserted into the CommandPaletteFooter as raw HTML, allowing anybody who can edit those messages to insert arbitrary HTML into the DOM. This impacts wikis where a group has the `editinterface` but not the… | |
| Analizada | Media (4.8) | 0.46% | — | Starcitizen.tools Citizen | 30/9/2024 | 17/6/2026 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. A user with the editmyprivateinfo right or who can otherwise change their name can XSS themselves by setting their "real name" to an XSS payload. This vulnerability is fixed in 2.31.0. | |
| Analizada | Media (5.4) | 0.47% | — | Starcitizen.tools Citizen | 3/6/2024 | 17/6/2026 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The page `MediaWiki:Tagline` has its contents used unescaped, so custom HTML (including Javascript) can be injected by someone with the ability to edit the MediaWiki namespace (typically those with the `editinterface` permission, or… | |
| Modificada | Alta (8.1) | 0.57% | — | Saat NetizenSaat Netizen Installer | 31/10/2023 | 17/6/2026 | Improper file verification vulnerability in SaAT Netizen installer ver.1.2.0.424 and earlier, and SaAT Netizen ver.1.2.0.8 (Build427) and earlier allows a remote unauthenticated attacker to conduct a man-in-the-middle attack. A successful exploitation may result in a malicious file being downloaded and executed. | |
| Modificada | Alta (7.5) | 1.5% | — | Samsung Tizenrt | 29/9/2022 | 17/6/2026 | An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). l2_packet_receive_timeout in wpa_supplicant/src/l2_packet/l2_packet_pcap.c has a missing check on the return value of pcap_dispatch, leading to a denial of service (malfunction). | |
| Modificada | Alta (7.5) | 1.7% | — | Samsung Tizenrt | 29/9/2022 | 17/6/2026 | An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). createDB in security/provisioning/src/provisioningdatabasemanager.c has a missing sqlite3_free after sqlite3_exec, leading to a denial of service. | |
| Modificada | Alta (7.5) | 0.68% | — | Samsung Tizenrt | 8/9/2022 | 17/6/2026 | An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). cyassl_connect_step2 in curl/vtls/cyassl.c has a missing X509_free after SSL_get_peer_certificate, leading to information disclosure. | |
| Modificada | Alta (7.5) | 1.3% | — | Samsung Tizenrt | 8/9/2022 | 17/6/2026 | An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). createDB in security/provisioning/src/provisioningdatabasemanager.c has a missing sqlite3_close after sqlite3_open_v2, leading to a denial of service. | |
| Modificada | Alta (7.5) | 1.1% | — | Samsung Tizenrt | 31/8/2021 | 17/6/2026 | Tizen RT RTOS version 3.0.GBB is vulnerable to integer wrap-around in functions_calloc and mm_zalloc. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash | |
| Modificada | Crítica (9.8) | 2.4% | — | Linux Tizen | 8/7/2021 | 17/6/2026 | Improper access control vulnerability in Tizen FOTA service prior to Firmware update JUL-2021 Release allows attackers to arbitrary code execution by replacing FOTA update file. | |
| Modificada | Crítica (9.8) | 1.6% | — | Linux Tizen | 8/7/2021 | 17/6/2026 | Improper input validation vulnerability in Tizen FOTA service prior to Firmware update JUL-2021 Release allows arbitrary code execution via Samsung Accessory Protocol. | |
| Modificada | Crítica (9.8) | 1.7% | — | Linux Tizen | 8/7/2021 | 17/6/2026 | Improper input validation vulnerability in Tizen bootloader prior to Firmware update JUL-2021 Release allows arbitrary code execution using recovery partition in wireless firmware download mode. | |
| Modificada | Crítica (9.8) | 1.7% | — | Linux Tizen | 8/7/2021 | 17/6/2026 | Improper input validation vulnerability in Tizen bootloader prior to Firmware update JUL-2021 Release allows arbitrary code execution using param partition in wireless firmware download mode. | |
| Modificada | Media (5.5) | 0.22% | — | Linux Tizen | 8/7/2021 | 17/6/2026 | Improper authorization vulnerability in Tizen factory reset policy prior to Firmware update JUL-2021 Release allows untrusted applications to perform factory reset using dbus signal. |