Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2744▲ 67 respecto a la semana anterior
Críticas / altas1456▲ 350 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)92▼ 421 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.58% | — | ACT Project ACTAI | 31/3/2026 | 17/6/2026 | act is a project which allows for local running of github actions. Prior to version 0.2.86, act's built in actions/cache server listens to connections on all interfaces and allows anyone who can connect to it including someone anywhere on the internet to create caches with arbitrary keys and retrieve all existing… | |
| Analizada | Alta (7.5) | 0.40% | — | Email Contact Project Email Contact | 9/1/2025 | 17/6/2026 | Insufficient Granularity of Access Control vulnerability in Drupal Email Contact allows Forceful Browsing.This issue affects Email Contact: from 0.0.0 before 2.0.4. | |
| Modificada | Crítica (9.8) | 2.2% | — | Dawnsparks-node-tesseract Project Dawnsparks-node-tesseractHuedawn-tesseract Project Huedawn-tesseract | 24/4/2023 | 17/6/2026 | huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function. | |
| Modificada | Alta (8.8) | 1.3% | — | ACT Project ACT | 20/1/2023 | 17/6/2026 | act is a project which allows for local running of github actions. The artifact server that stores artifacts from Github Action runs does not sanitize path inputs. This allows an attacker to download and overwrite arbitrary files on the host from a Github Action. This issue may lead to privilege escalation. The… | |
| Modificada | Crítica (9.8) | 1.3% | — | Npos-tesseract Project Npos-tesseract | 2/8/2022 | 17/6/2026 | This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js. | |
| Modificada | Crítica (9.8) | 3.4% | — | Ntesseract Project Ntesseract | 25/7/2022 | 17/6/2026 | The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js. | |
| Modificada | Media (4.3) | 0.43% | — | Clean-contact Project Clean-contact | 27/6/2022 | 17/6/2026 | The Clean-Contact WordPress plugin through 1.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored XSS due to the lack of sanitisation and escaping as well | |
| Modificada | Alta (7.2) | 1.5% | — | Wpagecontact Project Wpagecontact | 20/9/2021 | 17/6/2026 | The Orders functionality in the WordPress Page Contact plugin through 1.0 has an order_id parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. The feature is available to low privilege users such as contributors | |
| Modificada | Media (5.3) | 2.3% | — | Cabextract Project Cabextract | 29/11/2019 | 17/6/2026 | cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash. | |
| Modificada | Media (6.5) | 3.1% | — | Cabextract Project CabextractLibmspack Project LibmspackDebian LinuxRedhat Enterprise Linux+3 | 23/10/2018 | 17/6/2026 | In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write. | |
| Modificada | Alta (8.8) | 3.8% | — | Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+4 | 28/7/2018 | 17/6/2026 | An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression. | |
| Modificada | Alta (8.8) | 3.8% | — | Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+4 | 28/7/2018 | 17/6/2026 | An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause a one or two byte overwrite. | |
| Modificada | Media (6.5) | 3.7% | — | Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+4 | 28/7/2018 | 17/6/2026 | An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. It does not reject blank CHM filenames. | |
| Modificada | Media (6.5) | 3.3% | — | Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+4 | 28/7/2018 | 17/6/2026 | An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial of service (uninitialized data dereference and application crash). | |
| Modificada | Alta (7.5) | 1.4% | — | Exacorecontract Project Exacorecontract | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for ExacoreContract, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.5) | 1.1% | — | Icocontract Project Icocontract | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for IcoContract, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Crítica (9.8) | 2.7% | — | Jquickcontact Project Jquickcontact | 17/2/2018 | 17/6/2026 | SQL Injection exists in the JquickContact 1.3.2.2.1 component for Joomla! via a task=refresh&sid= request. | |
| Modificada | Alta (7.8) | 2.1% | — | Textract Project Textract | 6/4/2017 | 17/6/2026 | textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be a remote attack if a web application accepts names of arbitrary uploaded files. | |
| Modificada | Baja (2.1) | 0.95% | — | Mass Contact Project Mass Contact | 4/9/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Mass Contact module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer mass contact" permission to inject arbitrary web script or HTML via a category label. | |
| Modificada | Media (5.1) | 4.0% | — | Cabextract Project Cabextract | 9/8/2010 | 16/6/2026 | Integer signedness error in the Quantum decompressor in cabextract before 1.3, when archive test mode is used, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Quantum archive in a .cab file, related to the libmspack library. | |
| Modificada | Media (4.3) | 2.3% | — | Cabextract Project Cabextract | 9/8/2010 | 16/6/2026 | The MS-ZIP decompressor in cabextract before 1.3 allows remote attackers to cause a denial of service (infinite loop) via a malformed MSZIP archive in a .cab file during a (1) test or (2) extract action, related to the libmspack library. | |
| Modificada | Media (5) | 3.6% | — | Cabextract Project Cabextract | 27/1/2005 | 16/6/2026 | Directory traversal vulnerability in cabextract before 1.1 allows remote attackers to overwrite arbitrary files via a cabinet file containing .. (dot dot) sequences in a filename. |