Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

227 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.11%—Fabasoft Folio ClientAIFabasoft Egov-suiteAI24/9/202626/9/2026
Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension via web messaging, does not restrict which web origins may invoke its functions by default. The registry value VALIDDOMAINS, which limits permitted origins, was optional and empty by default,…
AplazadaMedia (5.3)0.45%—Governikus AusweisappAI15/9/202616/9/2026
A weakness has been identified in Governikus AusweisApp up to 2.5.4. Affected is an unknown function of the component StartPAOSResponse Handler. Executing a manipulation of the argument ResultMessage can lead to cross site scripting. The attack can be launched remotely. Upgrading to version 2.5.5 is able to address…
AplazadaAlta (7.5)0.63%—Govcert.lu EML ParserAI25/8/20269/9/2026
eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.2, eml_parser.routing.noparenthesis in eml_parser/routing.py removes parenthesized CFWS comments from Received: headers with a regex-based fix-point loop whose…
AplazadaMedia (5.3)0.52%—Govcert.lu EML ParserAI25/8/20269/9/2026
eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.2, eml_parser.parser.HeaderParser.header_fetch_parse in eml_parser/parser.py uses email.utils.getaddresses() to parse address-bearing e-mail headers. A deeply…
AplazadaMedia (6.5)0.52%—Govcert.lu EML ParserAI25/8/20269/9/2026
eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.2, the clean_found_uri function in eml_parser/parser.py validates potential URL strings before unescaping HTML entities used for colon, slash, or period…
Pendiente de análisisAlta (8.8)0.81%—Redhat Advanced Cluster Management FOR KubernetesAIRedhat Governance Policy Addon ControllerAI18/8/202627/8/2026
A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container image. This allows an attacker to run a controlled image with…
AnalizadaCrítica (10)0.90%—Microsoft Purview Data Governance24/7/202629/7/2026
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)2.1%—Localgovdrupal Localgov Workflows10/7/20266/8/2026
Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0.
Pendiente de análisisMedia (5.1)0.49%—U.s. Government Accountability Office Electronic Protest Docketing SystemAICivilian Board OF Contract Appeals Electronic Docketing SystemAI18/6/202624/6/2026
The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) do not validate X-Forwarded-For HTTP headers, allowing a remote attacker with compromised administrator credentials to bypass network access…
Pendiente de análisisAlta (8.7)0.72%—U.s. Government Accountability Office Electronic Protest Docketing SystemAICivilian Board OF Contract Appeals Electronic Docketing SystemAI18/6/202622/6/2026
The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the 'epds_role_id' parameter without verification, allowing a remote, authenticated attacker to escalate their own…
AplazadaAlta (8.1)0.47%—Thegov CoreAI17/6/202617/6/2026
Unauthenticated Local File Inclusion in Thegov Core < 2.0.23 versions.
Pendiente de análisisMedia (4.3)0.26%—SAP Master Data GovernanceAI9/6/202623/7/2026
SAP MDG (Review Match Groups Application) does not perform the necessary authorization checks for authenticated users. This could allow a low-privileged user to perform actions that would otherwise be restricted, resulting in escalation of privileges. This has a low impact on integrity, while confidentiality and…
AplazadaMedia (6.3)0.43%—Govcert.lu EML ParserAI26/5/202624/7/2026
eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.1, EmlParser.get_raw_body_text() recurses unconditionally for every nested message/rfc822 attachment without any depth limit. An attacker who can supply a badly…
AnalizadaCrítica (9.6)1.1%⚠ Explotación activaTanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+16712/5/202617/6/2026
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The…
Pendiente de análisisMedia (5.1)0.59%—Cisa Manage.get.govAI7/5/202625/6/2026
manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assign domain manager privileges for domains not already in another organization. Fixed in 1.176.0 on or around 2026-04-30.
AplazadaMedia (5.5)0.50%—Algovate Xhs-mcpAI29/4/202617/6/2026
A vulnerability was found in Algovate xhs-mcp 0.8.11. This affects the function xhs_publish_content of the file src/server/mcp.server.ts of the component MCP Interface. Performing a manipulation of the argument media_paths results in server-side request forgery. The attack may be initiated remotely. The exploit has…
AnalizadaCrítica (9.3)0.80%—Dragonsoft Gcb/fcb Government Financial Cybersecurity Configuration Audit Software17/3/202617/6/2026
GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access certain APIs to create a new administrative account.
AnalizadaMedia (5.5)0.18%—Govcert.lu EML Parser7/3/202617/6/2026
eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to version 2.0.1, the official example script examples/recursively_extract_attachments.py contains a path traversal vulnerability that allows arbitrary file write…
AplazadaCrítica (9.3)0.39%—Govee H6056AIGovee HomeAI18/12/202530/9/2026
A flaw in the binding process of Govee’s cloud platform and devices allows a remote attacker to bind an existing, online Govee device to the attacker’s account, resulting in full control of the device and removal of the device from its legitimate owner’s account. The server‑side API allows device association using a…
AnalizadaMedia (5.1)0.19%—Idieikon Governalia2/12/202517/6/2026
Reflected Cross-Site Scripting (XSS) in IDI Eikon's Governalia. The vulnerability allows an attacker to execute JavaScript code in the victim's browser when a malicious URL with the 'q' parameter in '/search' is sent to them. This vulnerability can be exploited to steal sensitive information such as session cookies or…
AplazadaMedia (6.8)0.24%—Wickr GOVAIWickr EnterpriseAIAmazon WickrAI21/11/202517/6/2026
Improper resource release in the call termination process in AWS Wickr before version 6.62.13 on Windows, macOS and Linux may allow a call participant to continue receiving audio input from another user after they close their call window. This issue occurs under certain conditions, which require the affected user to…
AplazadaAlta (8.7)0.27%—Egovframe-common-componentsAI19/11/202514/7/2026
eGovFramework/egovframe-common-components versions up to and including 4.3.1 includes Web Editor image upload and related file delivery functionality that uses symmetric encryption to protect URL parameters, but exposes an encryption oracle that allows attackers to generate valid ciphertext for chosen values. The…
AplazadaMedia (6.9)0.56%—Egovframework Egovframe-common-componentsAI19/11/202514/7/2026
eGovFramework/egovframe-common-components versions up to and including 4.3.1 contain an unauthenticated file upload vulnerability via the /utl/wed/insertImage.do and /utl/wed/insertImageCk.do image upload endpoints. These controllers accept multipart requests without authentication, pass the uploaded content to a…
AplazadaCrítica (9.3)0.45%—GOV CMSAI4/9/202517/6/2026
Input from search query parameter in GOV CMS is not sanitized properly, leading to a Blind SQL injection vulnerability, which might be exploited by an unauthenticated remote attacker. Versions 4.0 and above are not affected.
AnalizadaMedia (5.3)0.34%—IBM Security Verify Governance28/8/202517/6/2026
IBM Security Verify Governance Identity Manager 10.0.2 could allow a remote attacker to obtain sensitive information when detailed technical error messages are returned. This information could be used in further attacks against the system.