Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.28% | — | Zippy Zstore | 13/1/2026 | 17/6/2026 | Zstore, now referred to as Zippy CRM, 6.5.4 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts through unvalidated input parameters. Attackers can submit crafted payloads in manual insertion points to execute arbitrary JavaScript code in victim's browser context. | |
| Aplazada | Crítica (9.1) | 0.47% | — | Gesundheit-bewegt ZippyAI | 22/10/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Gesundheit Bewegt GmbH Zippy zippy allows Using Malicious Files.This issue affects Zippy: from n/a through <= 1.7.0. | |
| Aplazada | Media (5.3) | 0.59% | — | Gesundheit-bewegt ZippyAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Gesundheit Bewegt GmbH Zippy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zippy: from n/a through 1.6.2. | |
| Modificada | Alta (8.8) | 0.61% | — | Gesundheit-bewegt Zippy | 21/3/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.9. | |
| Modificada | Alta (8.8) | 0.48% | — | Gesundheit-bewegt Zippy | 28/12/2023 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.5. | |
| Modificada | Media (6.5) | 0.72% | — | Gesundheit-bewegt Zippy | 30/11/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.1. | |
| Modificada | Media (6.1) | 0.47% | — | Zippy Zstore | 13/2/2023 | 17/6/2026 | Zstore v6.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /index.php. | |
| Modificada | Baja (2.1) | 0.56% | — | Zippyyum Subway Ordering FOR California | 12/12/2013 | 17/6/2026 | The ZippyYum Subway CA Kiosk app 3.4 for iOS uses cleartext storage in SQLite cache databases, which allows attackers to obtain sensitive information by reading data elements, as demonstrated by password elements. |