Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 224 respecto a la semana anterior
Críticas / altas1373▲ 143 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 0.98% | — | NgrokAI | 18/5/2026 | 17/6/2026 | ngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection. | |
| Analizada | Media (6.1) | 0.20% | — | Oracle Opengrok | 19/9/2025 | 17/6/2026 | OpenGrok 1.14.1 has a reflected Cross-Site Scripting (XSS) issue when producing the cross reference page. This happens through improper handling of the revision parameter. The application reflects unsanitized user input into the HTML output. | |
| Analizada | Media (6.1) | 0.25% | — | Oracle Opengrok | 2/5/2025 | 17/6/2026 | OpenGrok 1.13.25 has a reflected Cross-Site Scripting (XSS) issue when producing the history view page. This happens through improper handling of path segments. The application reflects unsanitized user input into the HTML output. | |
| Modificada | Media (5.5) | 0.88% | — | Grok Project Grok | 1/1/2022 | 17/6/2026 | Grok 9.5.0 has a heap-based buffer overflow in openhtj2k::T1OpenHTJ2K::decompress (called from std::__1::__packaged_task_func<std::__1::__bind<grk::T1DecompressScheduler::deco and std::__1::packaged_task<int). | |
| Modificada | Alta (7.8) | 1.2% | — | Zope Grok | 1/7/2021 | 17/6/2026 | Grok 7.6.6 through 9.2.0 has a heap-based buffer overflow in grk::FileFormatDecompress::apply_palette_clr (called from grk::FileFormatDecompress::applyColour). | |
| Modificada | Alta (8.8) | 1.4% | — | Oracle Opengrok | 23/6/2021 | 17/6/2026 | Vulnerability in OpenGrok (component: Web App). Versions that are affected are 1.6.7 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise OpenGrok. Successful attacks of this vulnerability can result in takeover of OpenGrok. CVSS 3.1 Base Score 8.8… | |
| Modificada | Media (6.8) | 30% | — | Altnet Download ManagerGroksterKazaa Media Desktop | 5/10/2007 | 16/6/2026 | Stack-based buffer overflow in the ADM4 ActiveX control in adm4.dll in Altnet Download Manager 4.0.0.6, as used in (1) Kazaa 3.2.7 and (2) Grokster, allows remote attackers to execute arbitrary code via a long argument to the Install method. NOTE: the provenance of this information is unknown; the details are obtained… | |
| Modificada | Media (5) | 2.8% | — | Grok Developments Netproxy | 2/3/2007 | 16/6/2026 | Grok Developments NetProxy 4.03 allows remote attackers to bypass URL filtering via a request that omits "http://" from the URL and specifies the destination port (:80). | |
| Modificada | Alta (10) | 4.0% | — | Grok Developments Netproxy | 2/3/2007 | 16/6/2026 | The connection log file implementation in Grok Developments NetProxy 4.03 does not record requests that omit http:// in a URL, which might allow remote attackers to conduct unauthorized activities and avoid detection. | |
| Modificada | Alta (7.5) | 4.2% | — | Altnet Download ManagerGroksterKazaa Media Desktop | 31/12/2004 | 16/6/2026 | Buffer overflow in the IsValidFile function in the ADM ActiveX control for Altnet Download Manager 4.0.0.4 and earlier, as used in Kazaa Media Desktop 1.3 through 2.6.4 and Grokkster 1.3 through 2.6, allows remote attackers to execute arbitrary code via a long bstrFilepath parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | Fasttrack KazaaGroksterMusic City Networks Morpheus | 25/6/2002 | 16/6/2026 | fasttrack p2p, as used in (1) KaZaA, (2) grokster, and (3) morpheus allows remote attackers to spoof other users by modifying the username and network information in the message header. | |
| Modificada | Media (5) | 1.7% | — | Fasttrack KazaaGroksterMusic City Networks Morpheus | 25/6/2002 | 16/6/2026 | fasttrack p2p, as used in (1) KaZaA before 1.5, (2) grokster, and (3) morpheus allows remote attackers to cause a denial of service (memory exhaustion) via a series of client-to-client messages, which pops up new windows per message. |