Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Alta (7) | 0.07% | — | Android BluetoothAI | 5/10/2026 | 6/10/2026 | In handle_app_val_response of btif_rc.cc, there is a possible way to achieve code execution due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| En análisis | Alta (8.8) | 0.23% | — | Android BluetoothAI | 5/10/2026 | 6/10/2026 | In cfg2prop of btif_storage.cc, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Pendiente de análisis | Media (6.3) | 0.32% | — | Svenbluege Event GalleryAI | 5/10/2026 | 6/10/2026 | Joomla Extension - svenbluege.de - Server-side request forgery in the Google Photos picker in Event Gallery extension < 6.6.0 - The Google Photos picker of the back-end upload page fetches the thumbnails of the picked images through the server, with the OAuth access token of the Google Photos account. The task took… | |
| Pendiente de análisis | Media (5.3) | 0.15% | — | Svenbluege.de Event GalleryAI | 5/10/2026 | 6/10/2026 | Joomla Extension - svenbluege.de - Cross-site scripting and open redirect on the share mini page in Event Gallery extension < 6.6.0 - The page a shared image link opens (the share mini page of the front end) can link the article the image was shared from when the option "Share article links" is on. It took the address… | |
| Pendiente de análisis | Media (5.1) | 0.15% | — | Svenbluege Event GalleryAI | 5/10/2026 | 6/10/2026 | Joomla Extension - svenbluege.de - Cross-site request forgery of list tasks of the backend in Event Gallery extension < 6.6.0 - Eight tasks which the buttons of the back-end lists call did not check the form token: setting the default payment method, shipping method, image type set, order status and watermark; putting… | |
| Pendiente de análisis | Baja (2.1) | 0.15% | — | BluealsaAI | 1/10/2026 | 1/10/2026 | BlueALSA (bluez-alsa/bluealsad) contains a division-by-zero vulnerability in the LC3plus sink decoder (a2dp-lc3plus.c, a2dp_lc3plus_dec_thread) that allows a Bluetooth-adjacent attacker to crash the daemon by sending a crafted RTP media header with an attacker-controlled frame count field set to zero. Attackers can… | |
| Pendiente de análisis | Media (6.8) | 0.15% | — | Nvidia ConnectxAINvidia BluefieldAI | 29/9/2026 | 29/9/2026 | NVIDIA ConnectX and Bluefield contain a vulnerability in a control register, where a user with VF access could cause improper access control for the register interface by sending a malicious command to the firmware. A successful exploit of this vulnerability might lead to denial of service. | |
| Aplazada | Crítica (9.1) | 0.28% | — | BluehoodAI | 28/9/2026 | 30/9/2026 | Bluehood monitors local bluetooth activity. Prior to version 0.7.1, when auth_enabled is set in Bluehood, only the HTML page handlers enforced session validation. The /api/* handlers (settings, devices, groups, per-device endpoints including /api/device/{mac}/notes) called no auth check at all. A network attacker… | |
| En análisis | Alta (7) | 0.31% | — | Svenbluege Event GalleryAI | 27/9/2026 | 29/9/2026 | Joomla Extension - svenbluege.de - Authenticated arbitrary path deletion in `clear cache` task in Event Gallery extension < 6.5.0 - Using the `images` parameter of the `cache.process` task, you can recursively delete any directories that the web server is authorized to write to. | |
| En análisis | Media (5.1) | 0.15% | — | Svenbluege Event GalleryAI | 27/9/2026 | 30/9/2026 | Joomla Extension - svenbluege.de - CSRF in backend cleanup actions in Event Gallery extension < 6.5.0 - Only orphaned file entries and shopping carts that are older than 30 days will be deleted. | |
| En análisis | Media (6.9) | 0.15% | — | Svenbluege Event GalleryAI | 27/9/2026 | 29/9/2026 | Joomla Extension - svenbluege.de - CSRF in various cart actions in Event Gallery extension < 6.5.0 | |
| En análisis | Media (5.1) | 0.15% | — | Svenbluege Event GalleryAI | 27/9/2026 | 30/9/2026 | Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0 - Due to lack of an CSRF token check, a third-party site can upload files to an event and overwrite existing files with the same name. | |
| Aplazada | Media (6.3) | 0.16% | — | Pollen Robotics Reachy MiniAIBluezAI | 23/9/2026 | 23/9/2026 | The Reachy Mini Bluetooth service asks a connecting device for a PIN before it will accept commands. The check protects the session but not the caller, so an attacker in Bluetooth range can ride along on someone else's successful authentication. The authenticated state is kept in a single shared flag on the service… | |
| Aplazada | Alta (7) | 0.39% | — | Bluekitchen-gmbh BtstackAI | 17/9/2026 | 24/9/2026 | BlueKitchen BTstack through 1.8.2 fails to validate the peer-reported endpoint count against table bounds in A2DP stream endpoint discovery. A bonded peer can send an AVDTP DISCOVER response with more endpoints than the fixed table holds, causing out-of-bounds writes that corrupt adjacent static objects and crash the… | |
| Pendiente de análisis | Alta (7.1) | 0.27% | — | BluezAI | 15/9/2026 | 18/9/2026 | BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this… | |
| Aplazada | Alta (8.8) | 2.9% | 💥 Exploit | Newfold WP Module DataAINewfold WP Plugin Crazy DomainsAINewfold WP Plugin WEBAINewfold WP Plugin HostgatorAI+1 | 9/9/2026 | 9/9/2026 | Several Newfold plugins are vulnerable to Authentication Bypass. The vulnerability exists because the plugins bundle the wp-module-data module. In the module, the `authenticate()` method — registered on the `rest_authentication_errors` filter and therefore evaluated for every unauthenticated REST API request —… | |
| Aplazada | Alta (7.1) | 0.49% | — | Bluewavelabs CheckmateAI | 3/9/2026 | 10/9/2026 | Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion routes, allowing read-only users to perform administrative actions. Attackers with user-role sessions can create arbitrary maintenance windows to silence alerts, modify notification channels, and… | |
| Pendiente de análisis | Alta (8.5) | 2.3% | — | Amazon Codecatalyst-blueprintsAI | 3/9/2026 | 8/9/2026 | Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository in the project to execute arbitrary commands in the blueprint resynthesis… | |
| Pendiente de análisis | Alta (8.9) | 0.39% | — | Bluetooth Mesh SDKAI | 28/8/2026 | 8/9/2026 | In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution. These messages must come from a device that has already joined the network. Only provisioners supporting extended advertisements may be impacted. | |
| Aplazada | Alta (7.2) | 0.58% | — | Bluewavelabs CheckmateAI | 27/8/2026 | 1/9/2026 | An issue in the inviteController.js component in Bluewave Labs Checkmate <=3.3.0 allows remote authenticated administrators to escalate privileges to superadmin via the role parameter to the /api/v1/invite endpoint. | |
| Pendiente de análisis | Alta (7.6) | 0.50% | — | BluezAI | 25/8/2026 | 28/8/2026 | A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead… | |
| Pendiente de análisis | Media (5.7) | 0.29% | — | BluezAI | 25/8/2026 | 28/8/2026 | BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd. | |
| Aplazada | Alta (8.7) | 0.45% | — | RansomlookAIRocket.chatAIBlueskyAIJoinmastodon MastodonAI+1 | 24/8/2026 | 26/8/2026 | RansomLook fails to enforce the privacy status of ransomware groups and markets when distributing newly collected victim posts to external notification channels. The post-processing logic checks whether an individual post is marked private but does not verify whether the group or market to which the post belongs is… | |
| Aplazada | Alta (7.5) | 0.48% | — | Bluewavelabs CheckmateAI | 21/8/2026 | 18/9/2026 | Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.3.0 until 3.9.2, enabling the global showURL setting causes the unauthenticated GET /api/v1/status-page/:url endpoint to return complete… | |
| Aplazada | Media (4.9) | 0.59% | — | Bluewavelabs CheckmateAI | 21/8/2026 | 18/9/2026 | Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.5.1 until 3.9.2, an authenticated admin or superadmin can set matchMethod to regex and place a malicious expression in the expectedValue… |