Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 300 respecto a la semana anterior
Críticas / altas1348▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.18% | — | YtreeAI | 28/3/2026 | 17/6/2026 | yTree 1.94-1.1 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an excessively long argument to the application. Attackers can craft a malicious command-line argument containing shellcode and a return address to overwrite the stack and execute code… | |
| Aplazada | Media (5.7) | 0.37% | — | Directorytree ImapengineAI | 14/2/2026 | 17/6/2026 | Versions of the package directorytree/imapengine before 1.22.3 are vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') via the id() function in ImapConnection.php due to improperly escaping user input before including it in IMAP ID commands. This allows… | |
| Modificada | Media (6.1) | 0.50% | — | Cherrytree Project Cherrytree | 17/8/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in CherryTree v0.99.30 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field when creating a node. | |
| Modificada | Crítica (9.8) | 1.2% | — | Querytreeapp Querytree | 25/11/2019 | 17/6/2026 | Controllers/InvitationsController.cs in QueryTree before 3.0.99-beta mishandles invitations. | |
| Modificada | Alta (7.5) | 1.0% | — | Moneytree Project Moneytree | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for MoneyTree (TREE), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.5) | 0.99% | — | Moneytree Project Moneytree | 5/7/2018 | 17/6/2026 | The sell function of a smart contract implementation for MoneyTree (TREE), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets. |