Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3037▲ 563 respecto a la semana anterior
Críticas / altas1444▲ 270 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.32% | — | Securly | 3/6/2026 | 22/7/2026 | Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL matching (25,020 hashes) and CIPA blocklist matching (12,352 hashes). | |
| Analizada | Alta (7.5) | 0.60% | — | Securly | 3/6/2026 | 22/7/2026 | Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions via new RegExp() without complexity validation. An on-path attacker can inject specific patterns to cause catastrophic backtracking, resulting in denial of service on… | |
| Analizada | Alta (7.5) | 0.20% | — | Securly | 3/6/2026 | 22/7/2026 | Version 3.0.7 of the Securly Chrome Extension uses EVP_BytesToKey key derivation with MD5 and a single iteration for AES encryption. MD5 has been broken since 2004 and a single iteration provides no key stretching. | |
| Analizada | Alta (7.5) | 0.51% | — | Securly | 3/6/2026 | 22/7/2026 | Version 3.0.7 of the Securly Chrome Extension dynamically registers content13.min.js as a content script via chrome.scripting.registerContentScripts() at runtime. This script is NOT declared in manifest.json and bypasses Chrome Web Store static security review. It runs on all URLs and immediately hides all page… | |
| Analizada | Alta (7.5) | 0.26% | — | Securly | 3/6/2026 | 22/7/2026 | Version 3.0.7 of the Securly Chrome Extension exposes multiple publicly accessible endpoints that allow unauthenticated access to sensitive data. The exposed information consists of SHA-1 hashes that are inadequately obfuscated using a simple Caesar cipher, which can be easily reversed to recover the original hash… | |
| Analizada | Alta (7.3) | 0.30% | — | Securly | 3/6/2026 | 22/7/2026 | Version 3.0.7 of the Securly Chrome Extension contains hardcoded, plaintext AES passphrases in securly.min.js. These keys decrypt crisis alert keyword data and intervention site data. | |
| Analizada | Alta (7.1) | 0.17% | — | Securly | 3/6/2026 | 22/7/2026 | Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules over unencrypted HTTP via the Fetch API. Other endpoints in the same extension correctly fetch IWF and CIPA data over HTTPS, demonstrating an inconsistent implementation of TLS. | |
| Aplazada | Alta (8.1) | 0.56% | — | Mikado-themes Curly CoreAI | 25/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Curly Core curly-core allows PHP Local File Inclusion.This issue affects Curly Core: from n/a through <= 2.1.6. | |
| Aplazada | Media (5.4) | 0.27% | — | Qodeinteractive CurlyAI | 22/1/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Curly curly allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Curly: from n/a through <= 3.3. | |
| Modificada | Alta (8.1) | 0.48% | — | Qodeinteractive Curly | 8/1/2026 | 30/9/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Curly curly allows PHP Local File Inclusion.This issue affects Curly: from n/a through < 3.3. | |
| Modificada | Media (6.1) | 0.79% | — | Curly-bracket-parser Project Curly-bracket-parser | 28/7/2021 | 17/6/2026 | This affects all versions of package curly-bracket-parser. When used as a template library, it does not properly sanitize the user input. | |
| Modificada | Crítica (9.8) | 2.6% | — | Recurly Client .net | 13/11/2017 | 17/6/2026 | The Recurly Client .NET Library before 1.0.1, 1.1.10, 1.2.8, 1.3.2, 1.4.14, 1.5.3, 1.6.2, 1.7.1, 1.8.1 is vulnerable to a Server-Side Request Forgery vulnerability due to incorrect use of "Uri.EscapeUriString" that could result in compromise of API keys or other critical resources. | |
| Modificada | Crítica (9.8) | 2.6% | — | Recurly Client Python | 13/11/2017 | 17/6/2026 | The Recurly Client Python Library before 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1, 2.6.2 is vulnerable to a Server-Side Request Forgery vulnerability in the "Resource.get" method that could result in compromise of API keys or other critical resources. | |
| Modificada | Crítica (9.8) | 2.6% | — | Recurly Client Ruby | 13/11/2017 | 17/6/2026 | The Recurly Client Ruby Library before 2.0.13, 2.1.11, 2.2.5, 2.3.10, 2.4.11, 2.5.4, 2.6.3, 2.7.8, 2.8.2, 2.9.2, 2.10.4, 2.11.3 is vulnerable to a Server-Side Request Forgery vulnerability in the "Resource#find" method that could result in compromise of API keys or other critical resources. |