Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
334 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 1.3% | — | Atomic-agents-stackAI | 15/9/2026 | 24/9/2026 | atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths. Attackers can bypass path containment checks by including '../' segments in requests to the… | |
| Aplazada | Crítica (9.2) | 0.32% | — | Atomic-agents-stackAI | 15/9/2026 | 24/9/2026 | atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses. Attackers can inject arbitrary command and argument values that are spawned as local subprocesses by MCPClientPool to achieve code… | |
| Aplazada | Alta (7.1) | 0.48% | — | Atomic-agents-stackAI | 15/9/2026 | 24/9/2026 | atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that returns zero cost for unknown models not in the pricing table. Attackers can configure deployments with unknown model identifiers to bypass daily cost caps and exceed budget limits in parallel batch operations. | |
| Aplazada | Alta (8.1) | 0.38% | — | Uptimekuma Uptime KumaAIMatomoAI | 5/8/2026 | 26/8/2026 | Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo value as a bare, unquoted JavaScript expression inside a <script> block rendered on every public status page. A siteId value such as , once saved by an editor/admin, executes arbitrary JavaScript for… | |
| Aplazada | Alta (8.1) | 0.47% | — | AtomlabAI | 17/6/2026 | 17/6/2026 | Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions. | |
| Pendiente de análisis | Alta (8.6) | 0.15% | — | Atomic Alarm ClockAI | 13/5/2026 | 17/6/2026 | Atomic Alarm Clock 6.3 contains a stack overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string to the display name textbox in the Time Zones Clock configuration. Attackers can craft a buffer with structured exception handling overwrite and encoded shellcode to… | |
| Aplazada | Alta (8.7) | 0.31% | — | Atom 3X ProjectorAI | 10/4/2026 | 17/6/2026 | This vulnerability exists in the Atom 3x Projector due to improper exposure of the Android Debug Bridge (ADB) service over the local network without authentication or access controls. An unauthenticated attacker on the same network can exploit this vulnerability to obtain root-level access, leading to complete… | |
| Aplazada | Media (4.3) | 0.29% | — | Atomchat Group Chat AND Video ChatAI | 21/3/2026 | 17/6/2026 | The Group Chat & Video Chat by AtomChat plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'atomchat_update_auth_ajax' and 'atomchat_update_layout_ajax' functions in all versions up to, and including, 1.1.7. This makes it possible for authenticated… | |
| Analizada | Media (5.5) | 0.15% | — | Openatom Openharmony | 16/3/2026 | 17/6/2026 | in OpenHarmony v6.0 and prior versions allow a local attacker case DOS through missing release of memory. | |
| Analizada | Media (5.5) | 0.15% | — | Openatom Openharmony | 16/3/2026 | 17/6/2026 | in OpenHarmony v5.1.0 and prior versions allow a local attacker cause DOS through improper input. | |
| Analizada | Alta (7.8) | 0.16% | — | Openatom Openharmony | 16/3/2026 | 17/6/2026 | in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios. | |
| Analizada | Alta (7.8) | 0.17% | — | Openatom Openharmony | 16/3/2026 | 17/6/2026 | in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios. | |
| Analizada | Baja (3.3) | 0.14% | — | Openatom Openharmony | 16/3/2026 | 17/6/2026 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information improper input. This vulnerability can be exploited only in restricted scenarios. | |
| Analizada | Alta (7) | 0.15% | — | Openatom Openharmony | 16/3/2026 | 17/6/2026 | in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through using incompatible type. This vulnerability can be exploited only in restricted scenarios. | |
| Analizada | Media (6.5) | 0.17% | — | Openatom Openharmony | 16/3/2026 | 17/6/2026 | in OpenHarmony v5.0.3 and prior versions allow a local attacker case sensitive information leak through use of uninitialized resource. | |
| Aplazada | Alta (8.5) | 0.19% | — | Atomic Alarm ClockAI | 30/1/2026 | 17/6/2026 | Atomic Alarm Clock 6.3 contains a local privilege escalation vulnerability in its service configuration that allows attackers to execute arbitrary code with SYSTEM privileges. Attackers can exploit the unquoted service path by placing a malicious executable named 'Program.exe' to gain persistent system-level access. | |
| Analizada | Alta (7.4) | 0.36% | 💥 PoC | Atomberg Erica Smart FAN Firmware | 22/1/2026 | 17/6/2026 | An issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive information and escalate privileges via a crafted deauth frame | |
| Modificada | Crítica (9.3) | 0.47% | — | Thedigitalcraft Atomcms | 22/12/2025 | 17/6/2026 | Atom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries through unvalidated parameters. Attackers can inject malicious SQL code in the 'id' parameter of the admin index page to execute time-based blind SQL injection attacks. | |
| Aplazada | Media (5.5) | 0.22% | — | Interactive Human Anatomy With Clickable Body PartsAI | 3/10/2025 | 17/6/2026 | The Interactive Human Anatomy with Clickable Body Parts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Aplazada | Media (5.9) | 0.19% | — | Rbaer Simple Matomo Tracking CodeAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rbaer Simple Matomo Tracking Code simple-matomo-tracking-code allows Stored XSS.This issue affects Simple Matomo Tracking Code: from n/a through <= 1.1.0. | |
| Analizada | Alta (7) | 0.10% | — | Openatom Openharmony | 11/8/2025 | 17/6/2026 | in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition. | |
| Analizada | Media (5.5) | 0.12% | — | Openatom Openharmony | 11/8/2025 | 17/6/2026 | in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory. | |
| Analizada | Media (5.5) | 0.12% | — | Openatom Openharmony | 11/8/2025 | 17/6/2026 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through type confusion. | |
| Analizada | Alta (7.8) | 0.15% | — | Openatom Openharmony | 11/8/2025 | 17/6/2026 | in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free. | |
| Analizada | Media (5.5) | 0.12% | — | Openatom Openharmony | 11/8/2025 | 17/6/2026 | in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference. |