Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.3) | 0.68% | — | ToonAI | 2/9/2026 | 9/9/2026 | TOON is a compact, human-readable serialization of JSON data for LLM prompts. Prior to 2.3.1, decoding attacker-controlled TOON with a __proto__, constructor, or prototype key wrote through the object prototype chain instead of creating an own property, polluting Object.prototype for the runtime. In… | |
| Aplazada | Baja (2.1) | 0.47% | — | Hbai-ltd Toonflow-appAI | 27/4/2026 | 17/6/2026 | A vulnerability was identified in HBAI-Ltd Toonflow-app up to 1.1.1. This issue affects the function updateStoryboardUrl of the file replaceUrl.ts of the component Storyboard Export. Such manipulation of the argument url leads to path traversal. It is possible to launch the attack remotely. The exploit is publicly… | |
| Aplazada | Baja (1.3) | 0.35% | — | Hbai-ltd Toonflow-appAI | 27/4/2026 | 17/6/2026 | A vulnerability was determined in HBAI-Ltd Toonflow-app up to 1.1.1. This vulnerability affects the function z.url of the file src/routes/setting/about/downloadApp.ts of the component downloadApp Endpoint. This manipulation of the argument url causes path traversal. It is possible to initiate the attack remotely. The… | |
| Aplazada | Baja (2.1) | 0.37% | — | Hbai-ltd Toonflow-appAI | 27/4/2026 | 17/6/2026 | A vulnerability was found in HBAI-Ltd Toonflow-app up to 1.1.1. This affects the function fetch of the file src/routes/setting/vendorConfig/getCodeByLink.ts of the component getCodeByLink Endpoint. The manipulation of the argument Link results in server-side request forgery. The attack may be performed from remote.… | |
| Modificada | Crítica (9.8) | 23% | — | Nintendo Animal Crossing\Nintendo ArmsNintendo Mario Kart 7Nintendo Mario Kart 8+5 | 24/12/2022 | 17/6/2026 | The Nintendo NetworkBuffer class, as used in Animal Crossing: New Horizons before 2.0.6 and other products, allows remote attackers to execute arbitrary code via a large UDP packet that causes a buffer overflow, aka ENLBufferPwn. The victim must join a game session with the attacker. Other affected products include… | |
| Modificada | Media (4.8) | 0.58% | — | Destoon B2B | 17/10/2018 | 17/6/2026 | An issue was discovered in DESTOON B2B 7.0. admin/category.inc.php has XSS via the category[catname] parameter to the admin.php URI. | |
| Modificada | Alta (8.8) | 0.54% | — | Destoon B2B | 17/10/2018 | 17/6/2026 | An issue was discovered in DESTOON B2B 7.0. CSRF exists via the admin.php URI in an action=add request. | |
| Modificada | Media (4.8) | 0.58% | — | Destoon B2B | 17/10/2018 | 17/6/2026 | An issue was discovered in DESTOON B2B 7.0. XSS exists via certain text boxes to the admin.php?moduleid=2&action=add URI. | |
| Modificada | Media (4.8) | 0.58% | — | Destoon B2B | 17/10/2018 | 17/6/2026 | An issue was discovered in DESTOON B2B 7.0. admin\setting.inc.php has XSS via the first text box to the admin.php URI. | |
| Modificada | Alta (7.5) | 1.0% | — | Carrot Cartoon Book Coin Project Carrot Cartoon Book Coin | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for Carrot, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Media (5.4) | 0.27% | — | Fingersoft Cartoon Camera | 9/9/2014 | 17/6/2026 | The Cartoon Camera (aka com.fingersoft.cartooncamera) application 1.2.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |