Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▲ 14 respecto a la semana anterior
Críticas / altas1459▲ 324 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.93% | — | WS Project WS | 17/6/2026 | 11/9/2026 | ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and… | |
| Modificada | Alta (7.5) | 0.68% | — | WS Project WS | 15/5/2026 | 11/9/2026 | ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1. | |
| Analizada | Alta (7.5) | 0.49% | — | Rest Views Project Rest Views | 9/1/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Drupal REST Views allows Forceful Browsing.This issue affects REST Views: from 0.0.0 before 3.0.1. | |
| Analizada | Media (6.1) | 0.33% | — | Mm-breaking News Project Mm-breaking News | 12/9/2024 | 17/6/2026 | The MM-Breaking News WordPress plugin through 0.7.9 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers | |
| Analizada | Media (6.1) | 0.21% | — | Mm-breaking News Project Mm-breaking News | 12/9/2024 | 17/6/2026 | The MM-Breaking News WordPress plugin through 0.7.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |
| Modificada | Alta (7.8) | 0.38% | — | GIT FOR Windows Project GIT FOR Windows | 25/4/2023 | 17/6/2026 | Git for Windows is the Windows port of Git. Prior to version 2.40.1, any user of Git CMD who starts the command in an untrusted directory is impacted by an Uncontrolles Search Path Element vulnerability. Maliciously-placed `doskey.exe` would be executed silently upon running Git CMD. The problem has been patched in… | |
| Modificada | Alta (7.8) | 0.38% | — | GIT FOR Windows Project GIT FOR Windows | 25/4/2023 | 17/6/2026 | Git for Windows, the Windows port of Git, ships with an executable called `connect.exe`, which implements a SOCKS5 proxy that can be used to connect e.g. to SSH servers via proxies when certain ports are blocked for outgoing connections. The location of `connect.exe`'s config file is hard-coded as `/etc/connectrc`… | |
| Modificada | Baja (2.2) | 0.96% | — | GIT FOR Windows Project GIT FOR WindowsFedoraproject Fedora | 25/4/2023 | 17/6/2026 | In Git for Windows, the Windows port of Git, no localized messages are shipped with the installer. As a consequence, Git is expected not to localize messages at all, and skips the gettext initialization. However, due to a change in MINGW-packages, the `gettext()` function's implicit initialization no longer uses the… | |
| Modificada | Media (5.4) | 0.44% | — | Ms-reviews Project Ms-reviews | 24/4/2023 | 17/6/2026 | The MS-Reviews WordPress plugin through 1.5 does not sanitise and escape reviews, which could allow users any authenticated users, such as Subscribers to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (7.8) | 0.39% | — | GIT FOR Windows Project GIT FOR Windows | 14/2/2023 | 17/6/2026 | Git for Windows is the Windows port of the revision control system Git. Prior to Git for Windows version 2.39.2, when `gitk` is run on Windows, it potentially runs executables from the current directory inadvertently, which can be exploited with some social engineering to trick users into running untrusted code. A… | |
| Modificada | Alta (7.3) | 0.35% | — | GIT FOR Windows Project GIT FOR Windows | 14/2/2023 | 17/6/2026 | Git for Windows is the Windows port of the revision control system Git. Prior to Git for Windows version 2.39.2, by carefully crafting DLL and putting into a subdirectory of a specific name living next to the Git for Windows installer, Windows can be tricked into side-loading said DLL. This potentially allows users… | |
| Modificada | Media (6.5) | 0.31% | — | Moodle-block Sitenews Project Moodle-block Sitenews | 27/12/2022 | 17/6/2026 | A vulnerability was found in moodle-block_sitenews 1.0. It has been classified as problematic. This affects the function get_content of the file block_sitenews.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 1.1 is able to address this… | |
| Modificada | Alta (7.8) | 0.41% | — | Squirrel.windows Project Squirrel.windows | 21/12/2022 | 17/6/2026 | Squirrel.Windows is both a toolset and a library that provides installation and update functionality for Windows desktop applications. Installers generated by Squirrel.Windows 2.0.1 and earlier contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result,… | |
| Modificada | Media (4.8) | 0.75% | — | Google Places Reviews Project Google Places Reviews | 13/6/2022 | 17/6/2026 | The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is reflected on the site's administration panel. A malicious administrator could abuse this bug, in a multisite WordPress configuration, to trick super-administrators into viewing the booby-trapped… | |
| Modificada | Alta (7.8) | 1.5% | — | Microsoft Visual Studio 2017Microsoft Visual Studio 2019Microsoft Visual Studio 2022GIT FOR Windows Project GIT FOR Windows | 12/4/2022 | 17/6/2026 | GitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user account. | |
| Modificada | Crítica (9.8) | 4.1% | — | Node-windows Project Node-windows | 22/12/2021 | 17/6/2026 | lib/cmd.js in the node-windows package before 1.0.0-beta.6 for Node.js allows command injection via the PID parameter. | |
| Modificada | Alta (7.2) | 0.67% | — | Dated News Project Dated News | 13/8/2021 | 17/6/2026 | The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 has incorrect Access Control for confirming various applications. | |
| Modificada | Media (5.3) | 0.80% | — | Dated News Project Dated News | 13/8/2021 | 17/6/2026 | The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows Information Disclosure of application registration data. | |
| Modificada | Media (6.1) | 0.59% | — | Dated News Project Dated News | 13/8/2021 | 17/6/2026 | The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows XSS. | |
| Modificada | Crítica (9.8) | 1.00% | — | Dated News Project Dated News | 13/8/2021 | 17/6/2026 | The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Injection. | |
| Modificada | Alta (8.8) | 1.6% | — | Handsome Testimonials & Reviews Project Handsome Testimonials & Reviews | 2/8/2021 | 17/6/2026 | The hndtst_action_instance_callback AJAX call of the Handsome Testimonials & Reviews WordPress plugin before 2.1.1, available to any authenticated users, does not sanitise, validate or escape the hndtst_previewShortcodeInstanceId POST parameter before using it in a SQL statement, leading to an SQL Injection issue. | |
| Modificada | Media (5.3) | 2.8% | — | WS Project WSNetapp E-series Performance Analyzer | 25/5/2021 | 17/6/2026 | ws is an open source WebSocket client and server library for Node.js. A specially crafted value of the `Sec-Websocket-Protocol` header can be used to significantly slow down a ws server. The vulnerability has been fixed in ws@7.4.6 (https://github.com/websockets/ws/commit/00c425ec77993773d823f018f64a5c44e17023ff). In… | |
| Modificada | Alta (7.2) | 2.5% | — | Jaws Project Jaws | 23/12/2020 | 17/6/2026 | Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of UploadTheme to upload a theme ZIP archive containing a .php file that is able to execute OS commands. NOTE: this is unrelated to the JAWS (aka Job Access With Speech) product. | |
| Modificada | Alta (7.2) | 2.5% | — | Jaws Project Jaws | 23/12/2020 | 17/6/2026 | Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of admin.php?reqGadget=Components&reqAction=InstallGadget&comp=FileBrowser and admin.php?reqGadget=FileBrowser&reqAction=Files to upload a .php file. NOTE: this is unrelated to the JAWS (aka Job Access With Speech)… | |
| Modificada | Alta (7.5) | 1.1% | — | CWS Project CWS | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for CWS, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. |