Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
124 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.8) | 0.33% | — | Sinaptik AI Pandas-aiAI | 2/10/2026 | 6/10/2026 | sinaptik-ai pandas-ai 3.0.0 is vulnerable to Code Injection in CodeExecutor.execute. | |
| Aplazada | Crítica (9.3) | 0.62% | — | RedpandaAI | 28/8/2026 | 24/9/2026 | Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers. Attackers can reach port 9644 without credentials to create and delete broker accounts, modify cluster configuration, and disrupt partition replication. | |
| Aplazada | Crítica (9.3) | 0.23% | — | LightpandaAI | 15/7/2026 | 15/7/2026 | Lightpanda is a headless browser designed for AI and automation. Prior to 0.2.9, Lightpanda fetch() and XMLHttpRequest unconditionally attached session cookies to every HTTP request, ignoring credentials: omit, credentials: same-origin, credentials: include, and XMLHttpRequest.withCredentials, allowing an… | |
| Aplazada | Crítica (9.3) | 0.25% | — | LightpandaAI | 15/7/2026 | 15/7/2026 | Lightpanda is a headless browser designed for AI and automation. Prior to 0.3.1, Lightpanda searched for @ across the entire URL string instead of only the authority component when computing a page origin, so a URL such as `http://attacker.com/@victim.com/` was fetched from attacker.com but treated as… | |
| Aplazada | Media (5.5) | 0.41% | — | Codepanda Source Canteen Management SystemAI | 27/4/2026 | 17/6/2026 | A vulnerability was detected in CodePanda Source canteen_management_system 1.0. Affected by this issue is some unknown functionality of the file /api/login.php. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. | |
| Aplazada | Media (5.3) | 0.29% | — | Coding Panda Panda Pods Repeater FieldAI | 8/4/2026 | 20/7/2026 | Missing Authorization vulnerability in Coding Panda Panda Pods Repeater Field panda-pods-repeater-field allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Panda Pods Repeater Field: from n/a through <= 1.5.12. | |
| Analizada | Alta (7.3) | 0.30% | — | Gabrieleventuri Pandasai | 1/4/2026 | 17/6/2026 | pandas-ai v3.0.0 was discovered to contain a SQL injection vulnerability via the pandasai.agent.base._execute_sql_query component. | |
| Aplazada | Media (5.5) | 0.67% | — | Gabrieleventuri PandasaiAI | 28/3/2026 | 17/6/2026 | A weakness has been identified in Sinaptik AI PandasAI up to 3.0.0. This vulnerability affects the function CodeExecutor.execute of the file pandasai/core/code_execution/code_executor.py of the component Chat Message Handler. Executing a manipulation can lead to code injection. The attack may be launched remotely. The… | |
| Aplazada | Media (5.5) | 0.77% | — | Gabrieleventuri PandasaiAI | 28/3/2026 | 17/6/2026 | A security flaw has been discovered in Sinaptik AI PandasAI up to 3.0.0. This affects the function is_sql_query_safe of the file pandasai/helpers/sql_sanitizer.py. Performing a manipulation results in path traversal. The attack may be initiated remotely. The exploit has been released to the public and may be used for… | |
| Aplazada | Media (5.5) | 0.41% | — | Sinaptik AI Pandasai LancedbAIGabrieleventuri PandasaiAI | 28/3/2026 | 17/6/2026 | A vulnerability was identified in Sinaptik AI PandasAI up to 0.1.4. Affected by this issue is the function delete_question_and_answers/delete_docs/update_question_answer/update_docs/get_relevant_question_answers_by_id/get_relevant_docs_by_id of the file extensions/ee/vectorstores/lancedb/pandasai_lancedb/lancedb.py of… | |
| Modificada | Alta (8.6) | 0.44% | — | Geopandas | 30/1/2026 | 17/6/2026 | SQL injection vulnerability in geopandas before v.1.1.2 allows an attacker to obtain sensitive information via the to_postgis()` function being used to write GeoDataFrames to a PostgreSQL database. | |
| Analizada | Crítica (9.1) | 0.71% | — | Pandawireless Pwru01 Firmware | 8/1/2026 | 17/6/2026 | An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/goform/setWan, /goform/setLan, /goform/wirelessBasic) that do not enforce authentication. A remote unauthenticated attacker can modify WAN, LAN, and wireless settings directly, leading to privilege… | |
| Modificada | Media (5.1) | 0.37% | — | CMU Panda3d | 7/1/2026 | 14/7/2026 | The egg-mkfont utility in Panda3D versions up to and including 1.10.16 contains an uncontrolled format string vulnerability. The -gp (glyph pattern) command-line option is used directly as the format string for sprintf() with only a single argument supplied. If an attacker provides additional format specifiers,… | |
| Modificada | Media (6.9) | 0.52% | — | CMU Panda3d | 7/1/2026 | 14/7/2026 | The egg-mkfont utility in Panda3D versions up to and including 1.10.16 contains a stack-based buffer overflow vulnerability due to use of an unbounded sprintf() call with attacker-controlled input. When constructing glyph filenames, egg-mkfont formats a user-supplied glyph pattern (-gp) into a fixed-size stack buffer… | |
| Modificada | Media (6.9) | 0.21% | — | CMU Panda3d | 7/1/2026 | 14/7/2026 | The deploy-stub component in Panda3D versions up to and including 1.10.16 contains a denial of service vulnerability due to unbounded stack allocation. The deploy-stub executable allocates argv_copy and argv_copy2 using alloca() based directly on the attacker-controlled argc value without validation. Supplying a large… | |
| Aplazada | Baja (2.9) | 0.32% | — | PandaxAI | 27/12/2025 | 5/10/2026 | A vulnerability was detected in PandaXGO PandaX up to fb8ff40f7ce5dfebdf66306c6d85625061faf7e5. This affects an unknown function of the file config.yml of the component JWT Secret Handler. The manipulation of the argument key results in use of hard-coded cryptographic key . The attack may be performed from remote.… | |
| Modificada | Alta (8.1) | 0.50% | — | Axiomthemes Panda | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Panda panda allows PHP Local File Inclusion.This issue affects Panda: from n/a through <= 1.21. | |
| Aplazada | Alta (8.5) | 0.37% | 💥 Exploit | Pandasecurity Global ProtectionAIPandasecurity Antivirus PROAIPandasecurity Small Business ProtectionAIPandasecurity Internet SecurityAI | 15/7/2025 | 17/6/2026 | PSEvents.exe in multiple Panda Security products runs hourly with SYSTEM privileges and loads DLL files from a user-writable directory without proper validation. An attacker with low-privileged access who can write DLL files to the monitored directory can achieve arbitrary code execution with SYSTEM privileges.… | |
| Analizada | Media (6.9) | 0.63% | — | Pandarobot Ruoyi AI | 4/4/2025 | 17/6/2026 | A vulnerability was found in ageerle ruoyi-ai up to 2.0.1 and classified as critical. Affected by this issue is some unknown functionality of the file ruoyi-modules/ruoyi-system/src/main/java/org/ruoyi/system/controller/system/SysModelController.java of the component API Interface. The manipulation leads to improper… | |
| Aplazada | Media (4.3) | 0.21% | — | Pixolette Christmas-pandaAI | 27/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in pixolette Christmas Panda christmas-panda allows Cross Site Request Forgery.This issue affects Christmas Panda: from n/a through <= 1.0.4. | |
| Aplazada | Media (5.5) | 0.24% | — | Frndzk Expandable Bottom BARAI | 25/3/2025 | 17/6/2026 | The Frndzk Expandable Bottom Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'text' parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and… | |
| Aplazada | Alta (7.2) | 0.66% | — | Giuliopanda AdfoAI | 24/2/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in giuliopanda ADFO admin-form allows Object Injection.This issue affects ADFO: from n/a through <= 1.9.1. | |
| Aplazada | Crítica (9.8) | 1.2% | — | Gabrieleventuri PandasaiAI | 11/2/2025 | 17/6/2026 | PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that can lead to Remote Code Execution (RCE) instead of the intended explanation of the natural language processing by the LLM. | |
| Analizada | Alta (7.8) | 0.28% | — | Watchguard Panda Dome | 30/12/2024 | 17/6/2026 | Panda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Analizada | Alta (7.8) | 0.21% | — | Pandasecurity Panda Dome | 22/11/2024 | 17/6/2026 | Panda Security Dome VPN Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the target system in order to… |