Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3037▲ 502 respecto a la semana anterior
Críticas / altas1448▲ 249 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 158 respecto a la semana anterior
–

28 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisBaja (3.1)0.15%—HCL IreflectionAI2/6/202622/7/2026
HCL iReflection Third party vulnerable and outdated components issue was detected in the web application
ModificadaAlta (8.9)0.99%—Webreflection Flatted20/3/20264/9/2026
flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the internal input buffer is a JavaScript Array, accessing it with the key "__proto__"…
ModificadaAlta (7.5)0.99%—Webreflection Flatted12/3/20264/9/2026
flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve circular references in deserialized JSON. When given a crafted payload with deeply nested or self-referential $ indices, the recursion depth is unbounded, causing a stack overflow that crashes the…
AplazadaAlta (7.1)0.16%—Cobiansoft ReflectorAI20/2/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fox-themes Reflector reflector-plugins allows Reflected XSS.This issue affects Reflector: from n/a through <= 1.2.2.
AnalizadaAlta (8.6)0.39%—Prowise Reflect13/1/202617/6/2026
Prowise Reflect version 1.0.9 contains a remote keystroke injection vulnerability that allows attackers to send keyboard events through an exposed WebSocket on port 8082. Attackers can craft malicious web pages to inject keystrokes, opening applications and typing arbitrary text by sending specific WebSocket messages.
AnalizadaMedia (6.9)0.21%—Cobiansoft Reflector22/12/202517/6/2026
Cobian Reflector 0.9.93 RC1 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the password input field. Attackers can paste a large 8000-byte buffer into the password field to trigger an application crash during SFTP task configuration.
AplazadaAlta (7.7)0.17%—Paramount Macrium ReflectAI4/8/202517/6/2026
Paramount Macrium Reflect through 2025-06-26 allows local attackers to execute arbitrary code with administrator privileges via a crafted .mrimgx backup file and a malicious VSSSvr.dll located in the same directory. When a user with administrative privileges mounts a backup by opening the .mrimgx file, Reflect loads…
AplazadaAlta (7.7)0.15%—Paramount Macrium ReflectAI4/8/202517/6/2026
Paramount Macrium Reflect through 2025-06-26 allows attackers to execute arbitrary code with administrator privileges via a crafted .mrimgx or .mrbax backup file and a renamed executable placed in the same directory. When a user with administrative privileges opens the crafted backup file and proceeds to mount it,…
AplazadaAlta (7.8)0.30%—Macrium ReflectAI16/1/202517/6/2026
A null pointer dereference vulnerability in Macrium Reflect prior to 8.1.8017 allows a local attacker to cause a system crash or potentially elevate their privileges via executing a specially crafted executable.
AplazadaAlta (8.1)0.41%—RDS LightAIReflective Dialogue System RDSAI16/10/202417/6/2026
RDS Light is a simplified version of the Reflective Dialogue System (RDS), a self-reflecting AI framework. Versions prior to 1.1.0 contain a vulnerability that involves a lack of input validation within the RDS AI framework, specifically within the user input handling code in the main module (`main.py`). This leaves…
ModificadaAlta (7.8)0.35%—Macrium Reflect10/10/20239/7/2026
A buffer overflow in Macrium Reflect 8.1.7544 and below allows attackers to escalate privileges or execute arbitrary code.
ModificadaMedia (4.3)0.68%—Fluxcd Flux2Fluxcd Helm-controllerFluxcd Image-automation-controllerFluxcd Image-reflector-controller+322/10/202217/6/2026
Flux is an open and extensible continuous delivery solution for Kubernetes. Versions prior to 0.35.0 are subject to a Denial of Service. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields `.spec.interval` or…
ModificadaBaja (3.3)0.25%—NCH Reflect Customer Relationship Management25/7/202117/6/2026
NCH Reflect CRM 3.01 allows local users to discover cleartext user account information by reading the configuration files.
ModificadaAlta (7.8)0.64%—Macrium Reflect9/12/202017/6/2026
Macrium Reflect includes an OpenSSL component that specifies an OPENSSLDIR variable as C:\openssl\. Macrium Reflect contains a privileged service that uses this OpenSSL component. Because unprivileged Windows users can create subdirectories off of the system root, a user can create the appropriate path to a…
ModificadaAlta (7.8)1.8%—Red-gate .net ReflectorRed-gate Smartassembly31/7/201817/6/2026
Redgate .NET Reflector before 10.0.7.774 and SmartAssembly before 6.12.5 allow attackers to execute code by decompiling a compiled .NET object (such as a DLL or EXE file) with a specific embedded resource file.
ModificadaMedia (6.5)2.2%—Microfocus Host Access Management AND Security ServerMicrofocus Reflection FOR THE WEBMicrofocus Reflection Security GatewayMicrofocus Reflection ZFE29/11/201617/6/2026
Administrative Server in Micro Focus Host Access Management and Security Server (MSS) and Reflection for the Web (RWeb) and Reflection Security Gateway (RSG) and Reflection ZFE (ZFE) allows remote unauthenticated attackers to read arbitrary files via a specially crafted URL that allows limited directory traversal.…
ModificadaAlta (10)7.7%—Attachmate Reflection FTP Client6/2/201517/6/2026
Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to execute arbitrary code via unspecified vectors to the SaveSettings method.
ModificadaAlta (10)6.3%—Attachmate Reflection FTP Client6/2/201517/6/2026
Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to execute arbitrary code via unspecified vectors to the StartLog method.
ModificadaAlta (10)5.7%—Attachmate Reflection FTP Client6/2/201517/6/2026
The rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to cause a denial of service (memory corruption) and execute arbitrary code via vectors related to the (1) GetGlobalSettings or (2) GetSiteProperties3 methods, which triggers a dereference of an arbitrary memory…
ModificadaMedia (6.8)2.8%—Attachmate Reflection FTP Client27/1/201517/6/2026
Stack-based buffer overflow in the Attachmate Reflection FTP Client before 14.1.433 allows remote FTP servers to execute arbitrary code via a large PWD response.
ModificadaMedia (4.3)4.1%—Mindreantre Threewp Email Reflector19/6/201416/6/2026
Cross-site scripting (XSS) vulnerability in the ThreeWP Email Reflector plugin before 1.16 for WordPress allows remote attackers to inject arbitrary web script or HTML via the Subject of an email.
ModificadaMedia (6.9)0.40%—Attachmate Reflection FOR HPAttachmate Reflection FOR IBMAttachmate Reflection FOR Regis Graphics ServerAttachmate Reflection FOR Unix AND Openvms+16/9/201216/6/2026
Untrusted search path vulnerability in Attachmate Reflection before 14.1 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, a related issue to CVE-2011-0107. NOTE: some of these details are obtained from third party information.
ModificadaAlta (10)7.8%—Attachmate ReflectionAttachmate Reflection 2008Attachmate Reflection 2008r1Attachmate Reflection 2008r2+125/12/201116/6/2026
Heap-based buffer overflow in the Reflection FTP Client (rftpcom.dll 7.2.0.106 and possibly other versions), as used in Attachmate Reflection 2008, Reflection 2011 R1 before 15.3.2.569 and R1 SP1 before, Reflection 2011 R2 before 15.4.1.327, Reflection Windows Client 7.2 SP1 before hotfix 7.2.1186, and Reflection 14.1…
ModificadaMedia (4.3)1.1%—Attachmate Reflection FOR THE WEB2/11/201016/6/2026
Cross-site scripting (XSS) vulnerability in Attachmate Reflection for the Web 2008 R2 (builds 10.1.569 and earlier), 2008 R1, and 9.6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (10)1.9%—Attachmate Reflection FOR Secure IT2/2/200916/6/2026
Multiple unspecified vulnerabilities in Attachmate Reflection for Secure IT UNIX Client and Server before 7.0 SP1 have unknown impact and attack vectors, aka "security vulnerabilities found by 3rd party analysis."