Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2556▼ 352 respecto a la semana anterior
Críticas / altas1335▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.57% | — | Defenseunicorns UDS Identity Config | 5/6/2026 | 17/6/2026 | UDS Identity Config builds the Keycloak configuration image (realm, plugins, theme, truststore, JARs) consumed by UDS Core's Identity deployment. In versions 0.11.0 through 0.26.0, a logic error in the `client-kubernetes-secret` Keycloak client authenticator (shipped by `uds-identity-config` and consumed by UDS Core)… | |
| Analizada | Media (5.3) | 0.31% | — | Django-unicorn Unicorn | 10/3/2026 | 17/6/2026 | Unicorn adds modern reactive component functionality to your Django templates. Prior to 0.67.0, component state manipulation is possible in django-unicorn due to missing access control checks during property updates and method calls. An attacker can bypass the intended _is_public protection to modify internal… | |
| Analizada | Media (4.3) | 0.25% | — | Defenseunicorns Pepr | 16/1/2026 | 17/6/2026 | Pepr is a type safe K8s middleware. Prior to 1.0.5 , Pepr defaults to a cluster-admin RBAC configuration and does not explicitly force or enforce least-privilege guidance for module authors. The default behavior exists to make the “getting started” experience smooth: new users can experiment with Pepr and create… | |
| Aplazada | Baja (1.9) | 0.20% | — | Municorn FAX APPAI | 15/12/2025 | 17/6/2026 | A security vulnerability has been detected in Municorn FAX App 3.27.0 on Android. This vulnerability affects unknown code of the component biz.faxapp.app. Such manipulation leads to path traversal. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The vendor was… | |
| Aplazada | Alta (7.5) | 0.79% | — | GunicornAI | 20/3/2025 | 17/6/2026 | Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session… | |
| Aplazada | Crítica (9.3) | 0.49% | — | Django UnicornAI | 3/2/2025 | 17/6/2026 | Django-Unicorn adds modern reactive component functionality to Django templates. Affected versions of Django-Unicorn are vulnerable to python class pollution vulnerability. The vulnerability arises from the core functionality `set_property_value`, which can be remotely triggered by users by crafting appropriate… | |
| Aplazada | Alta (7.5) | 3.0% | — | GunicornAI | 16/4/2024 | 17/6/2026 | Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of… | |
| Modificada | Alta (7.5) | 0.84% | — | Glitter Unicorn Wallpaper Project Glitter Unicorn Wallpaper | 1/6/2023 | 17/6/2026 | The Glitter Unicorn Wallpaper app for Android 7.0 thru 8.0 allows unauthorized applications to actively request permission to insert data into the database that records information about a user's personal preferences and will be loaded into memory to be read and used when the application is opened. By injecting data,… | |
| Modificada | Crítica (9.1) | 0.78% | — | Glitter Unicorn Wallpaper Project Glitter Unicorn Wallpaper | 1/6/2023 | 17/6/2026 | The Glitter Unicorn Wallpaper app for Android 7.0 thru 8.0 allows unauthorized apps to actively request permission to modify data in the database that records information about a user's personal preferences and will be loaded into memory to be read and used when the app is opened. An attacker could tamper with this… | |
| Modificada | Media (6.1) | 0.52% | — | W3 Unicorn | 29/12/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in w3c Unicorn. This issue affects the function ValidatorNuMessage of the file src/org/w3c/unicorn/response/impl/ValidatorNuMessage.java. The manipulation of the argument message leads to cross site scripting. The attack may be initiated remotely.… | |
| Modificada | Alta (7.5) | 1.1% | — | Unicorn-engine Unicorn Engine | 2/6/2022 | 17/6/2026 | Unicorn Engine v2.0.0-rc7 contains memory leaks caused by an incomplete unicorn engine initialization. | |
| Modificada | Alta (7.5) | 1.9% | — | Unicorn-engine Unicorn Engine | 2/6/2022 | 17/6/2026 | Unicorn Engine v2.0.0-rc7 and below was discovered to contain a NULL pointer dereference via qemu_ram_free. | |
| Modificada | Alta (7.5) | 1.2% | — | Unicorn-engine Unicorn Engine | 2/6/2022 | 17/6/2026 | Unicorn Engine v2.0.0-rc7 and below was discovered to contain a memory leak via the function uc_close at /my/unicorn/uc.c. | |
| Modificada | Alta (7.8) | 0.80% | — | Unicorn-engine Unicorn Engine | 2/6/2022 | 17/6/2026 | Unicorn Engine v1.0.3 was discovered to contain a use-after-free vulnerability via the hook function. | |
| Modificada | Alta (8.1) | 0.53% | — | Unicorn-engine Unicorn Engine | 26/12/2021 | 17/6/2026 | An issue was discovered in split_region in uc.c in Unicorn Engine before 2.0.0-rc5. It allows local attackers to escape the sandbox. An attacker must first obtain the ability to execute crafted code in the target sandbox in order to exploit this vulnerability. The specific flaw exists within the virtual memory… | |
| Modificada | Media (6.1) | 0.70% | — | Django-unicorn Unicorn | 11/10/2021 | 17/6/2026 | The Unicorn framework before 0.36.1 for Django allows XSS via a component. NOTE: this issue exists because of an incomplete fix for CVE-2021-42053. | |
| Modificada | Media (5.4) | 2.5% | — | Django-unicorn Unicorn | 7/10/2021 | 17/6/2026 | The Unicorn framework through 0.35.3 for Django allows XSS via component.name. | |
| Modificada | Media (5.5) | 0.88% | — | Unicorn-engine Unicorn EngineFedoraproject Fedora | 20/7/2021 | 17/6/2026 | Unicorn Engine 1.0.2 has an out-of-bounds write in tb_flush_armeb (called from cpu_arm_exec_armeb and tcg_cpu_exec_armeb). | |
| Modificada | Media (5.5) | 0.27% | — | Unicorn-engine Unicorn Engine | 20/7/2021 | 17/6/2026 | Unicorn Engine 1.0.2 has an out-of-bounds write in helper_wfe_arm. | |
| Modificada | Alta (7.5) | 2.0% | — | Unicorn-list Project Unicorn-list | 7/6/2018 | 17/6/2026 | unicorn-list is a web framework. unicorn-list is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |
| Modificada | Alta (7.5) | 2.4% | — | GunicornDebian Linux | 18/4/2018 | 17/6/2026 | gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0. |