Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2532▼ 361 respecto a la semana anterior
Críticas / altas1338▲ 69 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

23 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.65%—GeolensAI15/9/202630/9/2026
GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder. Prior to 1.2.3, multiple read and link endpoints authorize only the resource named in the request URL and fail to re-authorize a second caller-influenced dataset reached through a relationship, map layer, VRT…
AplazadaMedia (6.5)0.22%—Netrr Author BOX WP LensAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Netrr Author Box WP Lens author-box-for-divi allows Stored XSS.This issue affects Author Box WP Lens: from n/a through <= 2.1.5.
AplazadaAlta (7.8)0.21%—Roslyn Codelens MCP ServerAI29/5/202621/7/2026
Roslyn CodeLens MCP Server is a Roslyn-based MCP server providing semantic code intelligence for .NET codebases. From 0.0.9 to 1.17.0, the get_diagnostics MCP tool loads and executes all DiagnosticAnalyzer assemblies referenced by the target solution without any allowlist, signature check, or user confirmation;…
AnalizadaCrítica (9.8)0.54%—Millensys Vision Tools Workspace24/11/202517/6/2026
MILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is accessible without authentication. This page leaks plaintext database credentials, file share paths, internal license server configuration, and software update parameters. An unauthenticated attacker…
AnalizadaAlta (7.3)0.29%—HP Poly Lens Desktop9/9/202517/6/2026
A vulnerability in the Poly Lens Desktop application running on the Windows platform might allow modifications to the filesystem, which might lead to SYSTEM level privileges being granted.
AplazadaMedia (6.5)2.6%—Microsoft Hololens 1AIMicrosoft Hololens 2AI6/3/202517/6/2026
The pairing API request handler in Microsoft HoloLens 1 (Windows Holographic) through 10.0.17763.3046 and HoloLens 2 (Windows Holographic) through 10.0.22621.1244 allows remote attackers to cause a Denial of Service (resource consumption and device unusability) by sending many requests through the Device Portal…
AplazadaCrítica (9.8)0.77%—Lens VisualAIMicrosoft Power BIAI5/11/202417/6/2026
An issue in Lens Visual integration with Power BI v.4.0.0.3 allows a remote attacker to execute arbitrary code via the Natural language processing component
AnalizadaAlta (7.3)0.52%—Snapchat Lenscore31/5/202417/6/2026
Type confusion in Snapchat LensCore could lead to denial of service or arbitrary code execution prior to version 12.88. We recommend upgrading to version 12.88 or above.
AplazadaAlta (8.8)0.78%—Yandex Datalens UIAI29/3/202417/6/2026
DataLens is a business intelligence and data visualization system. A specifically crafted request allowed the creation of a special chart type with the ability to pass custom javascript code that would later be executed in an unprotected sandbox on subsequent requests to that chart. The problem was fixed in the…
ModificadaAlta (7.6)0.25%—Poly Trio 8800 FirmwarePoly Trio C60Poly Lens29/12/202317/6/2026
A vulnerability was found in Poly Trio 8500, Trio 8800 and Trio C60. It has been classified as problematic. This affects an unknown part of the component Poly Lens Management Cloud Registration. The manipulation leads to missing authorization. It is possible to launch the attack on the physical device. The exploit has…
ModificadaAlta (7.5)0.68%—Glensawyer Mp3gain22/12/202317/6/2026
A stack buffer overflow vulnerability in MP3Gain v1.6.2 allows an attacker to cause a denial of service via the WriteMP3GainAPETag function at apetag.c:592.
ModificadaAlta (7.8)1.3%—Gitkraken Gitlens28/11/202317/6/2026
An issue in GitKraken GitLens before v.14.0.0 allows an attacker to execute arbitrary code via a crafted file to the Visual Studio Codes workspace trust component.
ModificadaAlta (7.5)0.95%—Dot-lens Project Dot-lens6/3/202317/6/2026
All versions of the package dot-lens are vulnerable to Prototype Pollution via the set() function in index.js file.
ModificadaCrítica (9.8)1.9%—Glensawyer Mp3gain11/5/202217/6/2026
Read access violation in the III_dequantize_sample function in mpglibDBL/layer3.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact, a different vulnerability than CVE-2017-9872. CVE-2017-14409, and CVE-2018-10778.
ModificadaAlta (8.8)1.00%—Mirantis Container Cloud Lens Extension4/2/202217/6/2026
Lack of validation of URLs causes Mirantis Container Cloud Lens Extension before v3.1.1 to open external programs other than the default browser to perform sign on to a new cluster. An attacker could host a webserver which serves a malicious Mirantis Container Cloud configuration file and induce the victim to add a…
ModificadaCrítica (9.6)0.43%—Mirantis Lens10/1/202217/6/2026
Linux users running Lens 5.2.6 and earlier could be compromised by visiting a malicious website. The malicious website could make websocket connections from the victim's browser to Lens and so operate the local terminal feature. This would allow the attacker to execute arbitrary commands as the Lens user.
ModificadaAlta (7.8)0.60%—Mirantis Lens10/1/202217/6/2026
In Lens prior to 5.3.4, custom helm chart configuration creates helm commands from string concatenation of provided arguments which are then executed in the user's shell. Arguments can be provided which cause arbitrary shell commands to run on the system.
ModificadaMedia (5.5)1.4%—Glensawyer Mp3gain23/10/201917/6/2026
A buffer over-read was discovered in ReadMP3APETag in apetag.c in MP3Gain 1.6.2. The vulnerability causes an application crash, which leads to remote denial of service.
ModificadaCrítica (9.8)1.4%—Lens Laboratories Peek-a-view Firmware10/4/201717/6/2026
Lens Peek-a-View has a password of 2601hx for the backdoor admin account, a password of user for the backdoor user account, and a password of guest for the backdoor guest account.
ModificadaAlta (7.5)6.9%—Mollensoft Software Lightweight FTP Server24/3/200416/6/2026
Buffer overflow in Mollensoft Lightweight FTP Server 3.6 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long CWD command, as demonstrated in one example by using the "cd" command in an interactive FTP client.
ModificadaAlta (8.5)4.6%—Mollensoft Software Enceladus Server Suite31/12/200216/6/2026
Buffer overflow in Enceladus Server Suite 3.9 allows remote attackers to execute arbitrary code via a long CD (CWD) command.
ModificadaAlta (8.3)1.6%—Mollensoft Software Enceladus Server Suite31/12/200216/6/2026
Directory traversal vulnerability in Enceladus Server Suite 3.9 allows remote attackers to list arbitrary directories and possibly cause a denial of service via "@" (at) characters in a CD (CWD) command, such as (1) "@/....\", (2) "@@@/..c:\", or (3) "@/..@/..".
ModificadaMedia (5)1.5%—Mollensoft Software Hyperion FTP Server31/12/200216/6/2026
Directory traversal vulnerability in Hyperion FTP server 2.8.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the LS command.