Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.3) | 1.5% | — | Qusetions Minicode-pythonAI | 22/7/2026 | 22/7/2026 | A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the function subprocess.Popen of the file minicode/config.py of the component Project File Handler. Executing a manipulation can lead to os command injection. The attack may be launched remotely. A high complexity level is… | |
| Aplazada | Alta (8.5) | 0.19% | — | Ipknowledge Musetheque V4AIIpknowledge V4l1AI | 15/5/2026 | 17/6/2026 | Cross-site request forgery vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a user views a malicious page while logged-in to the affected product, unexpected operations may be done. | |
| Aplazada | Media (4.8) | 0.13% | — | Ipknowledge Musetheque V4AI | 15/5/2026 | 17/6/2026 | Cross-site scripting vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a file containing malicious contents is uploaded, an arbitrary script may be executed on a user's web browser when viewing the administration page showing the information of the file. | |
| Aplazada | Media (6.9) | 0.49% | — | MousetooltiptranslatorAI | 3/3/2025 | 17/6/2026 | The MouseTooltipTranslator Chrome extension allows mouseover translation of any language at once. The MouseTooltipTranslator browser extension is vulnerable to SSRF attacks. The pdf.mjs script uses the URL parameter from the current URL as the file to download and display to the extension user. Because pdf.mjs is… | |
| Aplazada | Media (4.7) | 0.46% | — | CGI UsetAI | 12/12/2024 | 17/6/2026 | Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The "File Name" page (/cgi/uset.cgi?-cfilename) in the User Settings menu improperly filters the "file name" and wildcard character input field. By exploiting the wildcard… | |
| Modificada | Media (4.3) | 1.6% | — | FusetalkFusetalk. Fusetalk | 4/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login.cfm in FuseTalk Forums 3.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the windowed parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Fusetalk | 11/7/2007 | 16/6/2026 | SQL injection vulnerability in FuseTalk 2.0 allows remote attackers to execute arbitrary SQL commands via the FTVAR_SUBCAT (txForumID) parameter to forum/index.cfm and possibly other unspecified components, related to forum/include/error/forumerror.cfm. | |
| Modificada | Media (4.3) | 4.1% | — | Fusetalk | 21/6/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in forum/include/error/autherror.cfm in FuseTalk Basic, Standard, Enterprise, and ColdFusion allow remote attackers to inject arbitrary web script or HTML via the (1) FTVAR_LINKP and (2) FTVAR_URLP parameters to (a) forum/include/error/autherror.cfm, and the (3)… | |
| Modificada | Alta (7.5) | 1.0% | — | Fusetalk | 20/6/2007 | 16/6/2026 | SQL injection vulnerability in forum/include/error/autherror.cfm in FuseTalk allows remote attackers to execute arbitrary SQL commands via the errorcode parameter. NOTE: a patch may have been released privately between April and June 2007. NOTE: this issue may overlap CVE-2007-3273. | |
| Modificada | Alta (7.5) | 1.1% | — | Fusetalk | 19/6/2007 | 16/6/2026 | SQL injection vulnerability in index.cfm in FuseTalk 2.0 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.5) | 1.8% | — | Fusetalk | 31/12/2004 | 16/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to adduser.cfm. | |
| Modificada | Media (4.3) | 1.3% | — | E-zone Media Inc. Fusetalk | 13/10/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in FuseTalk 4.0 allows remote attackers to execute arbitrary web script via an img src tag. | |
| Modificada | Media (5) | 1.6% | — | E-zone Media Inc. Fusetalk | 5/5/2004 | 16/6/2026 | FuseTalk 4.0 allows remote attackers to ban other users via a direct request to banning.cfm. | |
| Modificada | Media (4.3) | 0.94% | — | E-zone Media Inc. Fusetalk | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in FuseTalk 2.0 and 3.0 allows remote attackers to insert arbitrary HTML and web script. | |
| Modificada | Alta (7.2) | 0.44% | — | University OF Massachusetts Scheme | 20/10/2000 | 16/6/2026 | umb-scheme 3.2-11 for Red Hat Linux is installed with world-writeable files. |