Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Acción recomendada:
Actualizar Google Chrome a la versión corregida. Priorizar estaciones con acceso a Internet y monitorear explotación activa.
Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network.
Acción recomendada:
Aplicar los parches de seguridad publicados por Microsoft. Priorizar servidores críticos y controladores de dominio.
Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.
Acción recomendada:
Actualizar sharefile a una versión corregida y validar exposición en activos críticos.
Hirschmann HiSecOS devices versions prior to 05.3.03 contain a buffer overflow vulnerability in the HTTPS login interface when RADIUS authentication is enabled that allows remote attackers to crash the device or execute arbitrary code by submitting a password longer than 128 characters. Attackers can exploit improper bounds checking in password handling to overflow a fixed-size buffer and achieve denial of service or remote code execution.
Acción recomendada:
Actualizar la aplicación vulnerable y aplicar controles compensatorios en el WAF.
Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03 contains an authentication bypass vulnerability in the master service that allows unauthenticated remote attackers to execute arbitrary commands with administrative privileges. Attackers can invoke exposed interface methods over the remote service to bypass authentication and achieve remote code execution on the underlying operating system.
Acción recomendada:
Actualizar hisecos a una versión corregida y validar exposición en activos críticos.
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Acción recomendada:
Actualizar Google Chrome a la versión corregida. Priorizar estaciones con acceso a Internet y monitorear explotación activa.
Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network.
Acción recomendada:
Aplicar los parches de seguridad publicados por Microsoft. Priorizar servidores críticos y controladores de dominio.
Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.
Acción recomendada:
Actualizar sharefile a una versión corregida y validar exposición en activos críticos.
Hirschmann HiSecOS devices versions prior to 05.3.03 contain a buffer overflow vulnerability in the HTTPS login interface when RADIUS authentication is enabled that allows remote attackers to crash the device or execute arbitrary code by submitting a password longer than 128 characters. Attackers can exploit improper bounds checking in password handling to overflow a fixed-size buffer and achieve denial of service or remote code execution.
Acción recomendada:
Actualizar la aplicación vulnerable y aplicar controles compensatorios en el WAF.
Reviactyl is an open-source game server management panel built using Laravel, React, FilamentPHP, Vite, and Go. From version 26.2.0-beta.1 to before version 26.2.0-beta.5, a vulnerability in the OAuth authentication flow allowed automatic linking of social accounts based solely on matching email addresses. An attacker could create or control a social account (e.g., Google, GitHub, Discord) using a victim’s email address and gain full access to the victim's account without knowing their password.
Acción recomendada:
Actualizar el producto afectado a una versión corregida y validar exposición en activos críticos.
Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03 contains an authentication bypass vulnerability in the master service that allows unauthenticated remote attackers to execute arbitrary commands with administrative privileges. Attackers can invoke exposed interface methods over the remote service to bypass authentication and achieve remote code execution on the underlying operating system.
Acción recomendada:
Actualizar hisecos a una versión corregida y validar exposición en activos críticos.
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to Notification test and Phone Number management endpoints allows SMS/Call/Email/WhatsApp abuse and phone number purchase. This issue has been patched in version 10.0.42.
Acción recomendada:
Actualizar el producto afectado a una versión corregida y validar exposición en activos críticos.
Hirschmann HiLCOS OpenBAT and BAT450 products contain a firewall bypass vulnerability in IPv6 IPsec deployments that allows traffic from VPN connections to bypass configured firewall rules. Attackers can exploit this vulnerability by establishing IPv6 IPsec connections (IKEv1 or IKEv2) while simultaneously using an IPv6 Internet connection to circumvent firewall policy enforcement.
Acción recomendada:
Actualizar hisecos a una versión corregida y validar exposición en activos críticos.
The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant full access to all unauthenticated requests, enabling complete read/write access to store resources like products, coupons, and customers.
Acción recomendada:
Actualizar plugins y componentes afectados. Validar exposición pública y aplicar controles WAF temporales.
Object corruption in V8 in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Acción recomendada:
Actualizar Google Chrome a la versión corregida. Priorizar estaciones con acceso a Internet y monitorear explotación activa.
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Acción recomendada:
Actualizar Google Chrome a la versión corregida. Priorizar estaciones con acceso a Internet y monitorear explotación activa.
Use after free in PDF in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)
Acción recomendada:
Actualizar Google Chrome a la versión corregida. Priorizar estaciones con acceso a Internet y monitorear explotación activa.
Heap buffer overflow in GPU in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Acción recomendada:
Actualizar Google Chrome a la versión corregida. Priorizar estaciones con acceso a Internet y monitorear explotación activa.
Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Acción recomendada:
Actualizar Google Chrome a la versión corregida. Priorizar estaciones con acceso a Internet y monitorear explotación activa.
Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Acción recomendada:
Actualizar Google Chrome a la versión corregida. Priorizar estaciones con acceso a Internet y monitorear explotación activa.
Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Acción recomendada:
Actualizar Google Chrome a la versión corregida. Priorizar estaciones con acceso a Internet y monitorear explotación activa.
Use after free in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Acción recomendada:
Actualizar Google Chrome a la versión corregida. Priorizar estaciones con acceso a Internet y monitorear explotación activa.
The MW WP Form plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via the 'generate_user_filepath' function and the 'move_temp_file_to_upload_dir' function in all versions up to, and including, 5.1.0. This makes it possible for unauthenticated attackers to move arbitrary files on the server, which can easily lead to remote code execution when the right file is moved (such as wp-config.php). The vulnerability is only exploitable if a file upload f
Acción recomendada:
Actualizar plugins y componentes afectados. Validar exposición pública y aplicar controles WAF temporales.
Hirschmann HiLCOS devices OpenBAT, WLC, BAT300, BAT54 prior to 8.80 and OpenBAT prior to 9.10 are shipped with identical default SSH and SSL keys that cannot be changed, allowing unauthenticated remote attackers to decrypt or intercept encrypted management communications. Attackers can perform man-in-the-middle attacks, impersonate devices, and expose sensitive information by leveraging the shared default cryptographic keys across multiple devices.
Acción recomendada:
Actualizar hisecos a una versión corregida y validar exposición en activos críticos.
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Acción recomendada:
Actualizar Google Chrome a la versión corregida. Priorizar estaciones con acceso a Internet y monitorear explotación activa.
Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network.
Acción recomendada:
Aplicar los parches de seguridad publicados por Microsoft. Priorizar servidores críticos y controladores de dominio.
Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.
Acción recomendada:
Actualizar sharefile a una versión corregida y validar exposición en activos críticos.
Hirschmann HiSecOS devices versions prior to 05.3.03 contain a buffer overflow vulnerability in the HTTPS login interface when RADIUS authentication is enabled that allows remote attackers to crash the device or execute arbitrary code by submitting a password longer than 128 characters. Attackers can exploit improper bounds checking in password handling to overflow a fixed-size buffer and achieve denial of service or remote code execution.
Acción recomendada:
Actualizar la aplicación vulnerable y aplicar controles compensatorios en el WAF.
Reviactyl is an open-source game server management panel built using Laravel, React, FilamentPHP, Vite, and Go. From version 26.2.0-beta.1 to before version 26.2.0-beta.5, a vulnerability in the OAuth authentication flow allowed automatic linking of social accounts based solely on matching email addresses. An attacker could create or control a social account (e.g., Google, GitHub, Discord) using a victim’s email address and gain full access to the victim's account without knowing their password.
Acción recomendada:
Actualizar el producto afectado a una versión corregida y validar exposición en activos críticos.
Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03 contains an authentication bypass vulnerability in the master service that allows unauthenticated remote attackers to execute arbitrary commands with administrative privileges. Attackers can invoke exposed interface methods over the remote service to bypass authentication and achieve remote code execution on the underlying operating system.
Acción recomendada:
Actualizar hisecos a una versión corregida y validar exposición en activos críticos.
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to Notification test and Phone Number management endpoints allows SMS/Call/Email/WhatsApp abuse and phone number purchase. This issue has been patched in version 10.0.42.
Acción recomendada:
Actualizar el producto afectado a una versión corregida y validar exposición en activos críticos.
Object corruption in V8 in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Acción recomendada:
Actualizar Google Chrome a la versión corregida. Priorizar estaciones con acceso a Internet y monitorear explotación activa.
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Acción recomendada:
Actualizar Google Chrome a la versión corregida. Priorizar estaciones con acceso a Internet y monitorear explotación activa.
Use after free in PDF in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)
Acción recomendada:
Actualizar Google Chrome a la versión corregida. Priorizar estaciones con acceso a Internet y monitorear explotación activa.