Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2753▼ 36 respecto a la semana anterior
Críticas / altas1269▼ 264 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)241▲ 206 respecto a la semana anterior
33 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.37% | — | Zsadmin2025 Zs-adminAIMybatis-plusAI | 21/7/2026 | 23/7/2026 | A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the function getTenantId of the file /api/system/sys/dept/page of the component MyBatis-Plus Tenant Plugin. Such manipulation of the argument X-Tenant-Id leads to authorization bypass. The attack may be… | |
| Analizada | Alta (7.5) | 0.13% | 💥 PoC | Notepad-plus-plus Notepad++ | 26/6/2026 | 29/6/2026 | Notepad++ is a free and open-source source code editor. Prior to 8.9.6.4, NppCommands.cpp checks the HMAC of the on-disk shortcuts.xml at the moment a user command fires (Time-of-Check). However, the command payload is taken from the in-memory _userCommands vector, which is populated at application startup and never… | |
| Analizada | Alta (7.8) | 0.21% | — | Notepad-plus-plus Notepad++ | 26/6/2026 | 29/6/2026 | Notepad++ is a free and open-source source code editor. In v8.9.6.1, isInTrustedDirectory() does NOT canonicalize the path before checking. It uses a prefix-based check (PathIsPrefix() or equivalent) that matches paths starting with trusted directory strings. A path traversal using ..\..\ after a trusted directory… | |
| Modificada | Alta (7.8) | 0.21% | 💥 PoC | Notepad-plus-plus Notepad++ | 26/6/2026 | 30/6/2026 | Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <Command> tag text content inside <UserDefinedCommands> in shortcuts.xml is read by NppXml::value(aNode) (Parameters.cpp:3658) in the feedUserCmds() function and stored in UserCommand._cmd without any validation. When the user clicks the… | |
| Analizada | Alta (7.8) | 0.62% | 💥 Exploit | Notepad-plus-plus Notepad++ | 26/6/2026 | 29/6/2026 | Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <GUIConfig name="commandLineInterpreter"> tag in config.xml is read by NppXml::value() (Parameters.cpp:6430) and stored in _nppGUI._commandLineInterpreter without any validation, whitelist, or digital signature check. When the user triggers… | |
| Analizada | Media (5) | 0.14% | 💥 PoC | Notepad-plus-plus Notepad++ | 26/6/2026 | 29/6/2026 | Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, a local process in the same interactive Windows session can send a malformed WM_COPYDATA message to Notepad++ using the COPYDATA_FULL_CMDLINE path. The handler appears to process COPYDATASTRUCT.lpData as an unbounded NUL-terminated wchar_t*… | |
| Analizada | Alta (7.5) | 0.15% | — | Notepad-plus-plus Notepad++ | 26/6/2026 | 29/6/2026 | Notepad++ is a free and open-source source code editor. From 8.9.4 until 8.9.6, Notepad++ contains a local privilege escalation vulnerability in the installer. During installation, the installer invokes powershell.exe without using an absolute path after setting the working directory to the installation contextMenu… | |
| Analizada | Media (4.6) | 0.19% | — | Notepad-plus-plus Notepad++ | 30/4/2026 | 17/6/2026 | Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers to cause denial of service and information disclosure by crafting a malicious nativeLang.xml language pack file. Attackers can distribute a poisoned language pack through community channels that… | |
| Analizada | Media (6.1) | 0.40% | — | Amazon Freertos-plus-tcp | 29/4/2026 | 17/6/2026 | Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause memory corruption by sending a crafted Router Advertisement with a prefix length value exceeding the maximum valid length, resulting in a… | |
| Analizada | Media (6) | 0.38% | — | Amazon Freertos-plus-tcp | 29/4/2026 | 17/6/2026 | Insufficient option length validation in the IPv6 Router Advertisement parser in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause a denial of service (device crash) by sending a crafted Router Advertisement with a truncated PREFIX_INFORMATION option that is smaller than the expected… | |
| Analizada | Alta (7.2) | 0.37% | — | Amazon Freertos-plus-tcp | 29/4/2026 | 17/6/2026 | Integer underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network actor to corrupt the device's IPv6 address assignment, DNS configuration, and lease times, and to cause a denial of service (permanent IP task freeze requiring hardware reset) by sending a single… | |
| Analizada | Media (6) | 0.36% | — | Amazon Freertos-plus-tcp | 29/4/2026 | 17/6/2026 | Integer underflow in the ICMP and ICMPv6 echo reply handlers in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network user to cause a denial of service (device crash) when outgoing ping support is enabled, because header sizes are subtracted from a packet length field without validating the field is… | |
| Analizada | Alta (7.1) | 0.29% | — | Amazon Freertos-plus-tcp | 29/4/2026 | 17/6/2026 | Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass all checksum and minimum-size validation by spoofing the Ethernet source MAC address to match one of the device's own registered endpoints, because the loopback detection mechanism skips all input… | |
| Aplazada | Media (5.5) | 0.43% | — | Liyupi Yu-pictureAIBaomidou Mybatis-plusAI | 26/4/2026 | 17/6/2026 | A vulnerability was determined in liyupi yu-picture up to a053632c41340152bf75b66b3c543d129123d8ec. This impacts the function PageRequest of the file yu-picture-backend/src/main/java/com/yupi/yupicturebackend/service/impl/PictureServiceImpl.java of the component MyBatis-Plus. Executing a manipulation of the argument… | |
| Analizada | Alta (7.8) | 0.18% | — | Notepad-plus-plus Notepad++ | 10/4/2026 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in Notepad++ version 8.9.3 in the file drop handler component. When a user drags and drops a directory path of exactly 259 characters without a trailing backslash, the application appends a backslash and null terminator without proper bounds checking, resulting in a… | |
| Analizada | Alta (7.3) | 0.21% | — | Notepad-plus-plus Notepad++ | 19/2/2026 | 17/6/2026 | Notepad++ es un editor de código fuente gratuito y de código abierto. Hay una vulnerabilidad de ruta de búsqueda insegura (CWE-426) en versiones anteriores a la 8.9.2 al iniciar el Explorador de Windows sin una ruta de ejecución absoluta. Esto puede permitir la ejecución de un explorer.exe malicioso si un atacante… | |
| Analizada | Alta (7.7) | 1.8% | ⚠ Explotación activa💥 PoC | Notepad-plus-plus Notepad++ | 3/2/2026 | 17/6/2026 | Las versiones de Notepad++ anteriores a la 8.8.9, al usar el actualizador WinGUp, contienen una vulnerabilidad de verificación de integridad de actualización donde los metadatos y los instaladores de actualización descargados no se verifican criptográficamente. Un atacante capaz de interceptar o redirigir el tráfico… | |
| Analizada | Media (5.3) | 0.34% | — | Amazon Freertos-plus-tcp | 10/10/2025 | 8/10/2026 | Una comprobación de validación faltante en el código de procesamiento de paquetes UDP/IPv6 de FreeRTOS-Plus-TCP puede llevar a una desreferencia de puntero no válida al recibir un paquete UDP/IPv6 con un campo de versión IP incorrecto en la cabecera del paquete. Este problema solo afecta a las aplicaciones que… | |
| Analizada | Media (5.3) | 0.31% | — | Amazon Freertos-plus-tcp | 10/10/2025 | 8/10/2026 | Una comprobación de validación faltante en el código de procesamiento de paquetes IPv6 de FreeRTOS-Plus-TCP puede conducir a una lectura fuera de límites al recibir un paquete IPv6 con longitudes de carga útil incorrectas en la cabecera del paquete. Este problema solo afecta a las aplicaciones que utilizan IPv6.… | |
| Analizada | Media (5.3) | 0.31% | — | Amazon Freertos-plus-tcp | 10/10/2025 | 8/10/2026 | Una comprobación de validación faltante en el código de procesamiento de paquetes ICMPv6 de FreeRTOS-Plus-TCP puede llevar a una lectura fuera de límites al recibir paquetes ICMPv6 de ciertos tipos de mensaje que son más pequeños que el tamaño esperado. Estos problemas solo afectan a las aplicaciones que utilizan… | |
| Modificada | Alta (8.1) | 0.61% | — | Amazon Freertos-plus-tcp | 24/6/2024 | 17/6/2026 | FreeRTOS-Plus-TCP es una pila TCP/IP ligera para FreeRTOS. Las versiones 4.0.0 a 4.1.0 de FreeRTOS-Plus-TCP contienen un problema de sobrelectura del búfer en el analizador de respuesta DNS al analizar nombres de dominio en una respuesta DNS. Una respuesta DNS cuidadosamente manipulada con un valor de longitud del… | |
| Modificada | Alta (7.8) | 0.53% | — | Notepad-plus-plus Notepad++ | 30/11/2023 | 17/6/2026 | Una vulnerabilidad de ruta de búsqueda no confiable en notepad++ 6.5 permite a los usuarios locales obtener privilegios aumentados a través del archivo msimg32.dll en el directorio de trabajo actual. | |
| Modificada | Alta (7.8) | 0.33% | 💥 PoC | Notepad-plus-plus Notepad++ | 30/11/2023 | 17/6/2026 | Una vulnerabilidad clasificada como problemática fue encontrada en NotePad++ hasta 8.1. Una función desconocida del archivo dbghelp.exe es afectada por esta vulnerabilidad. La manipulación conduce a una ruta de búsqueda incontrolada. Un ataque debe abordarse localmente. A esta vulnerabilidad se le asignó el… | |
| Modificada | Media (5.5) | 0.41% | — | Notepad-plus-plus Notepad++ | 25/8/2023 | 17/6/2026 | Notepad++ es un editor de código fuente gratuito y de código abierto. Las versiones 8.5.6 y anteriores son vulnerables al desbordamiento de lectura del búfer de montón en `FileManager::detectLanguageFromTextBegining`. La explotabilidad de este problema no está clara. Potencialmente, puede ser utilizado para filtrar… | |
| Modificada | Media (5.5) | 0.50% | — | Notepad-plus-plus Notepad++ | 25/8/2023 | 17/6/2026 | Notepad++ es un editor de código fuente gratuito y de código abierto. Las versiones 8.5.6 y anteriores son vulnerables al desbordamiento global de lectura de búfer en `nsCodingStateMachine::NextStater`. La explotabilidad de este problema no está clara. Potencialmente, puede utilizarse para filtrar información de… |