Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 74 respecto a la semana anterior
Críticas / altas1464▲ 358 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)89▼ 424 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.43% | — | Frontier X Mobile ApplicationAISeil X2AI | 29/5/2026 | 22/7/2026 | The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range to perform unauthorized control of device functions, including starting/stopping activities, triggering vibrations,… | |
| Analizada | Media (6.9) | 0.33% | — | Flyfrontier Frontier Airlines | 23/10/2025 | 17/6/2026 | The Frontier Airlines website has a publicly available endpoint that validates if an email addresses is associated with an account. An unauthenticated, remote attacker could determine valid email addresses, possibly aiding in further attacks. | |
| Aplazada | Media (6.9) | 0.48% | — | Parity FrontierAI | 28/7/2025 | 17/6/2026 | Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. There are various account address types in Frontier, e.g. precompiled contracts, smart contracts, and externally owned accounts. Some EVM mechanisms should be unreachable by certain types of accounts for safety. For precompiles to… | |
| Aplazada | Media (6.9) | 0.57% | — | Parity FrontierAI | 28/7/2025 | 17/6/2026 | Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. The extrinsic note_min_gas_price_target is an inherent extrinsic, meaning only the block producer can call it. To ensure correctness, the ProvideInherent trait should be implemented for each inherent, which includes the… | |
| Aplazada | Crítica (9.9) | 0.32% | — | Parity FrontierAI | 28/7/2025 | 17/6/2026 | Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. In versions prior to commit 36f70d1, the Curve25519Add and Curve25519ScalarMul precompiles incorrectly handle invalid Ristretto point representations. Instead of returning an error, they silently treat invalid input bytes as the… | |
| Modificada | Alta (8.8) | 0.25% | — | Wpfrontier Frontier Post | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in finnj Frontier Post allows Cross Site Request Forgery.This issue affects Frontier Post: from n/a through 6.1. | |
| Modificada | Alta (7.5) | 0.89% | — | Parity Frontier | 13/10/2023 | 17/6/2026 | Frontier is Substrate's Ethereum compatibility layer. Prior to commit aea528198b3b226e0d20cce878551fd4c0e3d5d0, at the end of a contract execution, when opcode SUICIDE marks a contract to be deleted, the software uses `storage::remove_prefix` (now renamed to `storage::clear_prefix`) to remove all storages associated… | |
| Modificada | Alta (7.5) | 0.87% | — | Parity Frontier | 22/3/2023 | 17/6/2026 | Frontier is an Ethereum compatibility layer for Substrate. Frontier's `modexp` precompile uses `num-bigint` crate under the hood. In the implementation prior to pull request 1017, the cases for modulus being even and modulus being odd are treated separately. Odd modulus uses the fast Montgomery multiplication, and… | |
| Modificada | Media (5.3) | 0.74% | — | Parity Frontier | 24/9/2022 | 17/6/2026 | Frontier is an Ethereum compatibility layer for Substrate. Prior to commit d3beddc6911a559a3ecc9b3f08e153dbe37a8658, the worst case weight was always accounted as the block weight for all cases. In case of large EVM gas refunds, this can lead to block spamming attacks -- the adversary can construct blocks with… | |
| Modificada | Media (6.5) | 1.2% | — | Parity Frontier | 19/8/2022 | 17/6/2026 | Frontier is Substrate's Ethereum compatibility layer. A security issue was discovered affecting parsing of the RPC result of the exit reason in case of EVM reversion. In release build, this would cause the exit reason being incorrectly parsed and returned by RPC. In debug build, this would cause an overflow panic. No… | |
| Modificada | Crítica (9.8) | 0.85% | — | Justsystems Atok Medical 2Justsystems Atok Medical 3Justsystems Atok PRO 3Justsystems Atok PRO 4+56 | 16/8/2022 | 17/6/2026 | An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted file path, a malicious file may be executed with the privilege of… | |
| Modificada | Media (5.3) | 1.4% | — | Parity Frontier | 6/7/2022 | 17/6/2026 | Frontier is Substrate's Ethereum compatibility layer. In affected versions the truncation done when converting between EVM balance type and Substrate balance type was incorrectly implemented. This leads to possible discrepancy between appeared EVM transfer value and actual Substrate value transferred. It is… | |
| Modificada | Media (6.5) | 1.3% | — | Parity Frontier | 14/1/2022 | 17/6/2026 | Frontier is Substrate's Ethereum compatibility layer. Prior to commit number `8a93fdc6c9f4eb1d2f2a11b7ff1d12d70bf5a664`, a bug in Frontier's MODEXP precompile implementation can cause an integer underflow in certain conditions. This will cause a node crash for debug builds. For release builds (and production… | |
| Modificada | Media (5.3) | 1.4% | — | Parity Frontier | 13/10/2021 | 17/6/2026 | Frontier is Substrate's Ethereum compatibility layer. In the newly introduced signed Frontier-specific extrinsic for `pallet-ethereum`, a large part of transaction validation logic was only called in transaction pool validation, but not in block execution. Malicious validators can take advantage of this to put invalid… | |
| Modificada | Media (5.3) | 1.2% | — | Parity Frontier | 3/9/2021 | 17/6/2026 | Frontier is Substrate's Ethereum compatibility layer. Prior to commit number 0b962f218f0cdd796dadfe26c3f09e68f7861b26, a bug in `pallet-ethereum` can cause invalid transactions to be included in the Ethereum block state in `pallet-ethereum` due to not validating the input data size. Any invalid transactions included… | |
| Modificada | Crítica (9.8) | 1.2% | — | Frontiersoftware Ichris | 29/5/2021 | 17/6/2026 | Frontier ichris through 5.18 allows users to upload malicious executable files that might later be downloaded and run by any client user. | |
| Modificada | Alta (7.5) | 1.2% | — | Frontiersoftware Ichris | 29/5/2021 | 17/6/2026 | Frontier ichris through 5.18 mishandles making a DNS request for the hostname in the HTTP Host header, as demonstrated by submitting 127.0.0.1 multiple times for DoS. | |
| Modificada | Crítica (9.8) | 1.5% | — | Gehealthcare 3.0t Signa Hdxt FirmwareGehealthcare 3.0t Signa HD 16 FirmwareGehealthcare 3.0t Signa HD 23 FirmwareGehealthcare 1.5t Brivo Mr355 Firmware+108 | 14/12/2020 | 17/6/2026 | GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network. | |
| Modificada | Crítica (9.8) | 1.1% | — | Gehealthcare 3.0t Signa Hdxt FirmwareGehealthcare 3.0t Signa HD 16 FirmwareGehealthcare 3.0t Signa HD 23 FirmwareGehealthcare 1.5t Brivo Mr355 Firmware+108 | 14/12/2020 | 17/6/2026 | GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network. | |
| Modificada | Alta (7.8) | 1.2% | — | Justsystems HanakoJustsystems Hanako PoliceJustsystems Hanako PROJustsystems Just Frontier+5 | 28/4/2017 | 17/6/2026 | Untrusted search path vulnerability in Hanako 2017, Hanako 2016, Hanako 2015, Hanako Pro 3, JUST Office 3 [Standard], JUST Office 3 [Eco Print Package], JUST Office 3 & Tri-De DataProtect Package, JUST Government 3, JUST Jump Class 2, JUST Frontier 3, JUST School 6 Premium, Hanako Police 5, JUST Police 3, Hanako 2017… | |
| Modificada | Media (6.9) | 0.40% | — | Justsystems IchitaroJustsystems Ichitaro Portable With OreplugJustsystems Ichitaro ViewerJustsystems Just Frontier+3 | 27/4/2012 | 16/6/2026 | Untrusted search path vulnerability in JustSystems Ichitaro 2011 Sou, Ichitaro 2006 through 2011, Ichitaro Government 2006 through 2010, Ichitaro Portable with oreplug, Ichitaro Viewer, JUST School, JUST School 2009 and 2010, JUST Jump 4, JUST Frontier, and oreplug allows local users to gain privileges via a Trojan… | |
| Modificada | Alta (9.3) | 4.2% | — | Justsystems IchitaroJustsystems Ichitaro Portable With OreplugJustsystems Ichitaro ViewerJustsystems Just Frontier+7 | 27/4/2012 | 16/6/2026 | Buffer overflow in JustSystems Ichitaro 2011 Sou, Ichitaro 2006 through 2011, Ichitaro Government 2006 through 2010, Ichitaro Portable with oreplug, Ichitaro Viewer, JUST School, JUST School 2009 and 2010, JUST Jump 4, JUST Frontier, oreplug, Shuriken Pro4, Shuriken 2007 through 2010, Shuriken Pro4 Corporate Edition,… | |
| Modificada | Media (4.3) | 1.0% | — | TOR World COM VoteTOR World I-navigatorTOR World Interactive BBSTOR World Mobile Frontier+6 | 22/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Tor World Tor Search 1.1 and earlier, I-Navigator 4.0, Mobile Frontier 2.1 and earlier, Diary.cgi (aka Quotes of the Day) 1.5 and earlier, Tor News 1.21 and earlier, Simple BBS 1.3 and earlier, Interactive BBS 1.3 and earlier, Tor Board 1.1 and earlier, Simple Vote 1.1 and… |