Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2744▲ 67 respecto a la semana anterior
Críticas / altas1456▲ 350 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)92▼ 421 respecto a la semana anterior
–

22 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.2)0.58%—ACT Project ACTAI31/3/202617/6/2026
act is a project which allows for local running of github actions. Prior to version 0.2.86, act's built in actions/cache server listens to connections on all interfaces and allows anyone who can connect to it including someone anywhere on the internet to create caches with arbitrary keys and retrieve all existing…
AnalizadaAlta (7.5)0.40%—Email Contact Project Email Contact9/1/202517/6/2026
Insufficient Granularity of Access Control vulnerability in Drupal Email Contact allows Forceful Browsing.This issue affects Email Contact: from 0.0.0 before 2.0.4.
ModificadaCrítica (9.8)2.2%—Dawnsparks-node-tesseract Project Dawnsparks-node-tesseractHuedawn-tesseract Project Huedawn-tesseract24/4/202317/6/2026
huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.
ModificadaAlta (8.8)1.3%—ACT Project ACT20/1/202317/6/2026
act is a project which allows for local running of github actions. The artifact server that stores artifacts from Github Action runs does not sanitize path inputs. This allows an attacker to download and overwrite arbitrary files on the host from a Github Action. This issue may lead to privilege escalation. The…
ModificadaCrítica (9.8)1.3%—Npos-tesseract Project Npos-tesseract2/8/202217/6/2026
This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js.
ModificadaCrítica (9.8)3.4%—Ntesseract Project Ntesseract25/7/202217/6/2026
The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js.
ModificadaMedia (4.3)0.43%—Clean-contact Project Clean-contact27/6/202217/6/2026
The Clean-Contact WordPress plugin through 1.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored XSS due to the lack of sanitisation and escaping as well
ModificadaAlta (7.2)1.5%—Wpagecontact Project Wpagecontact20/9/202117/6/2026
The Orders functionality in the WordPress Page Contact plugin through 1.0 has an order_id parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. The feature is available to low privilege users such as contributors
ModificadaMedia (5.3)2.3%—Cabextract Project Cabextract29/11/201917/6/2026
cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.
ModificadaMedia (6.5)3.1%—Cabextract Project CabextractLibmspack Project LibmspackDebian LinuxRedhat Enterprise Linux+323/10/201817/6/2026
In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write.
ModificadaAlta (8.8)3.8%—Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+428/7/201817/6/2026
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression.
ModificadaAlta (8.8)3.8%—Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+428/7/201817/6/2026
An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause a one or two byte overwrite.
ModificadaMedia (6.5)3.7%—Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+428/7/201817/6/2026
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. It does not reject blank CHM filenames.
ModificadaMedia (6.5)3.3%—Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+428/7/201817/6/2026
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial of service (uninitialized data dereference and application crash).
ModificadaAlta (7.5)1.4%—Exacorecontract Project Exacorecontract9/7/201817/6/2026
The mintToken function of a smart contract implementation for ExacoreContract, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaAlta (7.5)1.1%—Icocontract Project Icocontract9/7/201817/6/2026
The mintToken function of a smart contract implementation for IcoContract, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaCrítica (9.8)2.7%—Jquickcontact Project Jquickcontact17/2/201817/6/2026
SQL Injection exists in the JquickContact 1.3.2.2.1 component for Joomla! via a task=refresh&sid= request.
ModificadaAlta (7.8)2.1%—Textract Project Textract6/4/201717/6/2026
textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be a remote attack if a web application accepts names of arbitrary uploaded files.
ModificadaBaja (2.1)0.95%—Mass Contact Project Mass Contact4/9/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Mass Contact module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer mass contact" permission to inject arbitrary web script or HTML via a category label.
ModificadaMedia (5.1)4.0%—Cabextract Project Cabextract9/8/201016/6/2026
Integer signedness error in the Quantum decompressor in cabextract before 1.3, when archive test mode is used, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Quantum archive in a .cab file, related to the libmspack library.
ModificadaMedia (4.3)2.3%—Cabextract Project Cabextract9/8/201016/6/2026
The MS-ZIP decompressor in cabextract before 1.3 allows remote attackers to cause a denial of service (infinite loop) via a malformed MSZIP archive in a .cab file during a (1) test or (2) extract action, related to the libmspack library.
ModificadaMedia (5)3.6%—Cabextract Project Cabextract27/1/200516/6/2026
Directory traversal vulnerability in cabextract before 1.1 allows remote attackers to overwrite arbitrary files via a cabinet file containing .. (dot dot) sequences in a filename.