Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3064▲ 561 respecto a la semana anterior
Críticas / altas1461▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.78% | — | Argoproj Argo RolloutsAI | 28/8/2026 | 24/9/2026 | Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection. Attackers on the same network can invoke PromoteRollout, AbortRollout, RestartRollout, SetRolloutImage, UndoRollout, and RetryRollout operations across all… | |
| Modificada | Media (6.1) | 0.52% | — | Fetlife Rollout-ui | 11/5/2023 | 9/7/2026 | Cross Site Scripting (XSS) Vulnerability in Fetlife rollout-ui version 0.5, allows attackers to execute arbitrary code via a crafted url to the delete a feature functionality. | |
| Modificada | Alta (7.8) | 1.6% | — | Lout Project LoutOpensuse Backports SLEFedoraproject FedoraOpensuse Leap | 20/12/2019 | 17/6/2026 | Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c. | |
| Modificada | Alta (7.8) | 1.5% | — | Lout Project LoutOpensuse Backports SLEOpensuse LeapFedoraproject Fedora | 20/12/2019 | 17/6/2026 | Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c. | |
| Modificada | Alta (7.5) | 1.1% | — | Clouttoken Project Clouttoken | 9/7/2018 | 17/6/2026 | The mint function of a smart contract implementation for CloutToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. |