Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3061▲ 555 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 28% | — | Synology PhotosSynology Beephotos | 15/11/2024 | 17/6/2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Aplazada | Alta (7.1) | 0.18% | — | BeepressAI | 16/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Bee BeePress allows Stored XSS.This issue affects BeePress: from n/a through 6.9.8. | |
| Aplazada | Media (6.1) | 0.43% | — | Stewdio Beep.jsAI | 26/2/2024 | 17/6/2026 | A DOM based cross-site scripting (XSS) vulnerability in the component /beep/Beep.Instrument.js of stewdio beep.js before commit ef22ad7 allows attackers to execute arbitrary Javascript via sending a crafted URL. | |
| Modificada | Media (4.7) | 0.34% | — | Beep Project Beep | 26/6/2018 | 17/6/2026 | beep version 1.3 and up contains a External Control of File Name or Path vulnerability in --device option that can result in Local unprivileged user can inhibit execution of arbitrary programs by other users, allowing DoS. This attack appear to be exploitable via The system must allow local users to run beep. | |
| Modificada | Alta (7) | 1.6% | — | Beep Project BeepDebian Linux | 3/4/2018 | 17/6/2026 | Johnathan Nightingale beep through 1.3.4, if setuid, has a race condition that allows local privilege escalation. | |
| Modificada | Baja (2.1) | 0.32% | — | Yamaguchi Shingo Beep2 | 31/12/2002 | 16/6/2026 | The get_parameter_from_freqency_source function in beep2 1.0, 1.1 and 1.2, when installed setuid root, allows local users to read arbitrary files via unknown attack vectors. |