Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.40% | — | Transmissionbt TransmissionAI | 2/6/2026 | 22/7/2026 | transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI and RPC response paths. | |
| Aplazada | Media (6.3) | 0.18% | — | Turkiye Electricity Transmission Corporation Mobile ApplicationAI | 21/5/2026 | 23/7/2026 | Improper restriction of excessive authentication attempts vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application allows Brute Force. This issue affects Mobile Application: from 1.6.2 before 1.13. | |
| Aplazada | Media (5.7) | 0.18% | — | Turkiye Electricity Transmission Corporation Mobile ApplicationAI | 21/5/2026 | 23/7/2026 | Insufficient session expiration vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application allows Session Hijacking. This issue affects Mobile Application: from 1.6.2 before 1.13. | |
| Modificada | Media (5.3) | 0.68% | — | Yunohost Transmission YNH | 8/1/2023 | 17/6/2026 | A vulnerability classified as critical has been found in YunoHost-Apps transmission_ynh. Affected is an unknown function of the file conf/nginx.conf. The manipulation leads to path traversal. The patch is identified as f136dfd44eda128129e5fd2d850a3a3c600e6a4a. It is recommended to apply a patch to fix this issue.… | |
| Modificada | Alta (7.8) | 2.7% | — | Transmissionbt TransmissionDebian LinuxFedoraproject Fedora | 15/5/2020 | 17/6/2026 | Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted torrent file. | |
| Modificada | Media (5.3) | 1.6% | — | Transmissionbt TransmissionDebian Linux | 30/10/2019 | 16/6/2026 | Transmission before 1.92 allows attackers to prevent download of a file by corrupted data during the endgame. | |
| Modificada | Crítica (9.8) | 1.9% | — | Transmissionbt TransmissionDebian Linux | 30/10/2019 | 16/6/2026 | Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr arguments in a magnet link. | |
| Modificada | Alta (8.8) | 12% | — | Transmissionbt TransmissionDebian Linux | 15/1/2018 | 17/6/2026 | Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access control, which allows remote attackers to execute arbitrary RPC commands, and consequently write to arbitrary files, via POST requests to /transmission/rpc in conjunction with a DNS rebinding attack. | |
| Modificada | Media (6.8) | 5.4% | — | Canonical Ubuntu LinuxFedoraproject FedoraGentoo LinuxTransmissionbt Transmission | 29/7/2014 | 17/6/2026 | Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted peer message, which triggers an out-of-bounds write. | |
| Modificada | Alta (7.5) | 5.1% | — | Transmissionbt TransmissionCanonical Ubuntu LinuxFedoraproject Fedora | 3/4/2013 | 16/6/2026 | Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted "micro transport protocol packets." | |
| Modificada | Baja (2.6) | 1.4% | — | Transmissionbt Transmission | 15/8/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the web client in Transmission before 2.61 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) created by, or (3) name field in a torrent file. | |
| Modificada | Media (6.8) | 3.8% | — | Transmissionbt Transmission | 7/5/2010 | 16/6/2026 | Multiple stack-based buffer overflows in the tr_magnetParse function in libtransmission/magnet.c in Transmission 1.91 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted magnet URL with a large number of (1) tr or (2) ws links. | |
| Modificada | Alta (8.8) | 4.2% | — | Transmissionbt TransmissionDebian LinuxOpensuse | 8/1/2010 | 16/6/2026 | Directory traversal vulnerability in libtransmission/metainfo.c in Transmission 1.22, 1.34, 1.75, and 1.76 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a pathname within a .torrent file. | |
| Modificada | Alta (10) | 3.9% | — | Hitachi JP1 File Transmission Server | 11/9/2009 | 16/6/2026 | Multiple unspecified vulnerabilities in Hitachi JP1/File Transmission Server/FTP before 09-00 allow remote attackers to execute arbitrary code via unknown attack vectors. | |
| Modificada | Media (6.8) | 0.83% | — | Transmissionbt Transmission | 22/5/2009 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Transmission 1.5 before 1.53 and 1.6 before 1.61 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | |
| Modificada | Media (5) | 1.6% | — | Hitachi JP1 File Transmission Server | 27/11/2007 | 16/6/2026 | Unspecified vulnerability in Hitachi JP1/File Transmission Server/FTP 01-00 through 08-10-01 allows remote attackers to bypass authentication and "view files" via unspecified vectors. | |
| Modificada | Media (5) | 2.2% | — | Hitachi JP1 File Transmission Server | 27/11/2007 | 16/6/2026 | Hitachi JP1/File Transmission Server/FTP 01-00 through 08-10-02 on Windows might allow remote attackers to cause a denial of service (service stop) via a "specific file" argument to an FTP command. | |
| Modificada | Alta (7.8) | 3.4% | — | Cisco IOS Transmission Control Protocol | 22/5/2007 | 16/6/2026 | Cisco IOS 12.4 and earlier, when using the crypto packages and SSL support is enabled, allows remote attackers to cause a denial of service via a malformed (1) ClientHello, (2) ChangeCipherSpec, or (3) Finished message during an SSL session. | |
| Modificada | Alta (7.8) | 4.9% | — | Cisco IOS Transmission Control Protocol | 25/1/2007 | 16/6/2026 | Cisco IOS allows remote attackers to cause a denial of service (crash) via a crafted IPv6 Type 0 Routing header. | |
| Modificada | Alta (10) | 9.3% | — | Cisco IOS Transmission Control Protocol | 25/1/2007 | 16/6/2026 | Cisco IOS 9.x, 10.x, 11.x, and 12.x and IOS XR 2.0.x, 3.0.x, and 3.2.x allows remote attackers to cause a denial of service or execute arbitrary code via a crafted IP option in the IP header in a (1) ICMP, (2) PIMv2, (3) PGM, or (4) URD packet. | |
| Modificada | Alta (7.8) | 4.5% | — | Cisco IOS Transmission Control Protocol | 25/1/2007 | 16/6/2026 | Memory leak in the TCP listener in Cisco IOS 9.x, 10.x, 11.x, and 12.x allows remote attackers to cause a denial of service by sending crafted TCP traffic to an IPv4 address on the IOS device. | |
| Modificada | Media (5) | 3.8% | — | Lksctp Stream Control Transmission Protocol | 9/5/2006 | 16/6/2026 | Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (infinite recursion and crash) via a packet that contains two or more DATA fragments, which causes an skb pointer to refer back to itself when the full message is reassembled, leading to infinite recursion in the sctp_skb_pull… | |
| Modificada | Alta (7.5) | 3.6% | — | Lksctp Stream Control Transmission ProtocolCanonical Ubuntu Linux | 9/5/2006 | 16/6/2026 | Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (deadlock) via a large number of small messages to a receiver application that cannot process the messages quickly enough, which leads to "spillover of the receive buffer." | |
| Modificada | Alta (7.8) | 4.3% | — | Lksctp Stream Control Transmission Protocol | 9/5/2006 | 16/6/2026 | Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (kernel panic) via incoming IP fragmented (1) COOKIE_ECHO and (2) HEARTBEAT SCTP control chunks. |