Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2556▼ 352 respecto a la semana anterior
Críticas / altas1335▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
–

21 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.57%—Defenseunicorns UDS Identity Config5/6/202617/6/2026
UDS Identity Config builds the Keycloak configuration image (realm, plugins, theme, truststore, JARs) consumed by UDS Core's Identity deployment. In versions 0.11.0 through 0.26.0, a logic error in the `client-kubernetes-secret` Keycloak client authenticator (shipped by `uds-identity-config` and consumed by UDS Core)…
AnalizadaMedia (5.3)0.31%—Django-unicorn Unicorn10/3/202617/6/2026
Unicorn adds modern reactive component functionality to your Django templates. Prior to 0.67.0, component state manipulation is possible in django-unicorn due to missing access control checks during property updates and method calls. An attacker can bypass the intended _is_public protection to modify internal…
AnalizadaMedia (4.3)0.25%—Defenseunicorns Pepr16/1/202617/6/2026
Pepr is a type safe K8s middleware. Prior to 1.0.5 , Pepr defaults to a cluster-admin RBAC configuration and does not explicitly force or enforce least-privilege guidance for module authors. The default behavior exists to make the “getting started” experience smooth: new users can experiment with Pepr and create…
AplazadaBaja (1.9)0.20%—Municorn FAX APPAI15/12/202517/6/2026
A security vulnerability has been detected in Municorn FAX App 3.27.0 on Android. This vulnerability affects unknown code of the component biz.faxapp.app. Such manipulation leads to path traversal. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The vendor was…
AplazadaAlta (7.5)0.79%—GunicornAI20/3/202517/6/2026
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session…
AplazadaCrítica (9.3)0.49%—Django UnicornAI3/2/202517/6/2026
Django-Unicorn adds modern reactive component functionality to Django templates. Affected versions of Django-Unicorn are vulnerable to python class pollution vulnerability. The vulnerability arises from the core functionality `set_property_value`, which can be remotely triggered by users by crafting appropriate…
AplazadaAlta (7.5)3.0%—GunicornAI16/4/202417/6/2026
Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of…
ModificadaAlta (7.5)0.84%—Glitter Unicorn Wallpaper Project Glitter Unicorn Wallpaper1/6/202317/6/2026
The Glitter Unicorn Wallpaper app for Android 7.0 thru 8.0 allows unauthorized applications to actively request permission to insert data into the database that records information about a user's personal preferences and will be loaded into memory to be read and used when the application is opened. By injecting data,…
ModificadaCrítica (9.1)0.78%—Glitter Unicorn Wallpaper Project Glitter Unicorn Wallpaper1/6/202317/6/2026
The Glitter Unicorn Wallpaper app for Android 7.0 thru 8.0 allows unauthorized apps to actively request permission to modify data in the database that records information about a user's personal preferences and will be loaded into memory to be read and used when the app is opened. An attacker could tamper with this…
ModificadaMedia (6.1)0.52%—W3 Unicorn29/12/202217/6/2026
A vulnerability, which was classified as problematic, has been found in w3c Unicorn. This issue affects the function ValidatorNuMessage of the file src/org/w3c/unicorn/response/impl/ValidatorNuMessage.java. The manipulation of the argument message leads to cross site scripting. The attack may be initiated remotely.…
ModificadaAlta (7.5)1.1%—Unicorn-engine Unicorn Engine2/6/202217/6/2026
Unicorn Engine v2.0.0-rc7 contains memory leaks caused by an incomplete unicorn engine initialization.
ModificadaAlta (7.5)1.9%—Unicorn-engine Unicorn Engine2/6/202217/6/2026
Unicorn Engine v2.0.0-rc7 and below was discovered to contain a NULL pointer dereference via qemu_ram_free.
ModificadaAlta (7.5)1.2%—Unicorn-engine Unicorn Engine2/6/202217/6/2026
Unicorn Engine v2.0.0-rc7 and below was discovered to contain a memory leak via the function uc_close at /my/unicorn/uc.c.
ModificadaAlta (7.8)0.80%—Unicorn-engine Unicorn Engine2/6/202217/6/2026
Unicorn Engine v1.0.3 was discovered to contain a use-after-free vulnerability via the hook function.
ModificadaAlta (8.1)0.53%—Unicorn-engine Unicorn Engine26/12/202117/6/2026
An issue was discovered in split_region in uc.c in Unicorn Engine before 2.0.0-rc5. It allows local attackers to escape the sandbox. An attacker must first obtain the ability to execute crafted code in the target sandbox in order to exploit this vulnerability. The specific flaw exists within the virtual memory…
ModificadaMedia (6.1)0.70%—Django-unicorn Unicorn11/10/202117/6/2026
The Unicorn framework before 0.36.1 for Django allows XSS via a component. NOTE: this issue exists because of an incomplete fix for CVE-2021-42053.
ModificadaMedia (5.4)2.5%—Django-unicorn Unicorn7/10/202117/6/2026
The Unicorn framework through 0.35.3 for Django allows XSS via component.name.
ModificadaMedia (5.5)0.88%—Unicorn-engine Unicorn EngineFedoraproject Fedora20/7/202117/6/2026
Unicorn Engine 1.0.2 has an out-of-bounds write in tb_flush_armeb (called from cpu_arm_exec_armeb and tcg_cpu_exec_armeb).
ModificadaMedia (5.5)0.27%—Unicorn-engine Unicorn Engine20/7/202117/6/2026
Unicorn Engine 1.0.2 has an out-of-bounds write in helper_wfe_arm.
ModificadaAlta (7.5)2.0%—Unicorn-list Project Unicorn-list7/6/201817/6/2026
unicorn-list is a web framework. unicorn-list is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
ModificadaAlta (7.5)2.4%—GunicornDebian Linux18/4/201817/6/2026
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an attacker causing the server to return arbitrary HTTP headers. This vulnerability appears to have been fixed in 19.5.0.