Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.43% | — | WineshopAI | 17/6/2026 | 30/9/2026 | Unauthenticated Local File Inclusion in WineShop <= 3.17 versions. | |
| Aplazada | Alta (7.3) | 0.18% | — | WineAI | 24/5/2026 | 23/7/2026 | Wine ships a .desktop file that registers itself as a MIME handler for EXE files and several other Windows executable file types. In some configurations, handling of an EXE file causes that file to be blindly executed with the permissions of the invoker. This allows escaping Flatpak and Snap sandboxes, because MIME… | |
| Aplazada | Alta (8.1) | 0.58% | — | Themerex Luxury WineAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Luxury Wine luxury-wine allows PHP Local File Inclusion.This issue affects Luxury Wine: from n/a through <= 1.1.14. | |
| Aplazada | Alta (7.5) | 0.36% | — | ABC Liquors INC ABC Fine Wine AND SpiritsAI | 30/10/2025 | 17/6/2026 | ABC Fine Wine & Spirits Android App version v.11.27.5 and before (package name com.cta.abcfinewineandspirits), developed by ABC Liquors, Inc., contains an improper access control vulnerability in its login mechanism. The application does not properly validate user passwords during authentication, allowing attackers to… | |
| Analizada | Alta (7.5) | 0.22% | — | Sungrowpower Winet-s Firmware | 26/2/2025 | 17/6/2026 | SunGrow WiNet-S V200.001.00.P025 and earlier versions is missing integrity checks for firmware upgrades. Sending a specific MQTT message allows an update to an inverter or a WiNet connectivity dongle with a bogus firmware file that is located on attacker-controlled server. | |
| Analizada | Crítica (9.8) | 0.57% | — | Sungrowpower Winet-s Firmware | 24/1/2025 | 17/6/2026 | SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to heap-based buffer overflow due to bounds checks of the MQTT message content. | |
| Analizada | Alta (8.1) | 0.45% | — | Sungrowpower Winet-s Firmware | 24/1/2025 | 17/6/2026 | In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when decrypting MQTT messages, the code that parses specific TLV fields does not have sufficient bounds checks. This may result in a stack-based buffer overflow. | |
| Analizada | Crítica (9.8) | 0.57% | — | Sungrowpower Winet-s Firmware | 24/1/2025 | 17/6/2026 | SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to stack-based buffer overflow when parsing MQTT messages, due to missing MQTT topic bounds checks. | |
| Analizada | Crítica (9.8) | 0.57% | — | Sungrowpower Winet-s Firmware | 24/1/2025 | 17/6/2026 | In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when copying the timestamp read from an MQTT message, the underlying code does not check the bounds of the buffer that is used to store the message. This may lead to a stack-based buffer overflow. | |
| Analizada | Media (5.4) | 0.24% | — | Sungrowpower Winet-s Firmware | 24/1/2025 | 17/6/2026 | SunGrow WiNet-SV200.001.00.P027 and earlier versions contains hardcoded MQTT credentials that allow an attacker to send arbitrary commands to an arbitrary inverter. It is also possible to impersonate the broker, because TLS is not used to identify the real MQTT broker. This means that MQTT communications are… | |
| Analizada | Media (6.5) | 0.25% | — | Sungrowpower Winet-s Firmware | 24/1/2025 | 17/6/2026 | SunGrow WiNet-SV200.001.00.P027 and earlier versions contains a hardcoded password that can be used to decrypt all firmware updates. | |
| Aplazada | Media (6.4) | 0.28% | — | Embed TwineAI | 20/12/2024 | 17/6/2026 | The Embed Twine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'embed_twine' shortcode in all versions up to, and including, 0.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Crítica (9.8) | 2.3% | — | Winehq Wine | 28/6/2018 | 17/6/2026 | PlayEnhMetaFileRecord in enhmetafile.c in Wine 3.7 allows attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact because the attacker controls the pCreatePen->ihPen array index. | |
| Modificada | Crítica (9.8) | 2.4% | — | Winehq Wine | 28/6/2018 | 17/6/2026 | PlayEnhMetaFileRecord in enhmetafile.c in Wine 3.7 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by triggering a large pAlphaBlend->cbBitsSrc value. | |
| Modificada | Media (5.4) | 0.27% | — | Gcspublishing Wine Making | 27/9/2014 | 17/6/2026 | The Wine Making (aka com.gcspublishing.winemakingtalk) application 3.7.15 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.9) | 0.33% | — | Kegel Winetricks | 28/1/2009 | 16/6/2026 | winetricks before 20081223 allows local users to overwrite arbitrary files via a symlink attack on the x_showmenu.txt temporary file. | |
| Modificada | Media (6.3) | 0.36% | — | Xwine | 4/3/2008 | 16/6/2026 | w_export.c in XWine 1.0.1 on Debian GNU/Linux sets insecure permissions (0666) for /etc/wine/config, which might allow local users to execute arbitrary commands or cause a denial of service by modifying the file. | |
| Modificada | Alta (7.2) | 0.37% | — | Freshmeat Xwine | 4/3/2008 | 16/6/2026 | w_editeur.c in XWine 1.0.1 for Debian GNU/Linux allows local users to overwrite or print arbitrary files via a symlink attack on the temporaire temporary file. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.6% | — | Fermentigrafici Wineglass | 5/1/2007 | 16/6/2026 | WineGlass stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/data.mdb. | |
| Modificada | Alta (7.5) | 4.2% | — | Wine | 6/1/2006 | 16/6/2026 | gdi/driver.c and gdi/printdrv.c in Wine 20050930, and other versions, implement the SETABORTPROC GDI Escape function call for Windows Metafile (WMF) files, which allows attackers to execute arbitrary code, the same vulnerability as CVE-2005-4560 but in a different codebase. | |
| Modificada | Alta (7.5) | 5.0% | — | Wineggdropshell | 4/12/2005 | 16/6/2026 | Multiple buffer overflows in WinEggDropShell remote access trojan (RAT) 1.7 allow remote attackers to execute arbitrary code via (1) a long GET request to the HTTP server, or a long (2) USER or (3) PASS command to the FTP server. | |
| Modificada | Baja (2.1) | 0.46% | — | Wine | 2/5/2005 | 16/6/2026 | Wine 20050211 and earlier creates temp files with world readable permissions and predictable file names, which allows local users to obtain sensitive information, such as passwords. |