Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
96 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.32% | — | Sharedfilespro Shared Files PROAI | 28/8/2026 | 28/8/2026 | The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured image, allowing unauthenticated attackers to read arbitrary files from the server and republish their contents at a public URL. | |
| Aplazada | Media (5.3) | 0.22% | — | Shared FilesAIShared Files PROAI | 28/8/2026 | 28/8/2026 | The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.70 do not perform a capability check in their file-upload handler, which is registered for unauthenticated users and protected only by a nonce that is output on public pages, so an unauthenticated visitor can upload files to… | |
| Aplazada | Media (6.8) | 0.33% | — | Shared FilesAIShared Files PROAI | 28/8/2026 | 28/8/2026 | The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do not properly sanitize a file path taken from a frontend file submission and their single-pass traversal filter is bypassable, allowing unauthenticated users to store a path that points outside the uploads directory.… | |
| Aplazada | Media (6.4) | 0.23% | — | Shared FilesAI | 24/8/2026 | 24/8/2026 | Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions. | |
| Aplazada | Media (4) | 0.17% | — | Data Disjointset SharedAI | 21/7/2026 | 23/7/2026 | Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in dsu.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW… | |
| Aplazada | Baja (3.8) | 0.14% | — | Perl Data Spatialhash SharedAI | 21/7/2026 | 23/7/2026 | Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sphash.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable).… | |
| Aplazada | Baja (3.8) | 0.14% | — | Data Intern SharedAI | 21/7/2026 | 23/7/2026 | Data::Intern::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in intern.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW is… | |
| Aplazada | Baja (3.8) | 0.14% | — | Data Ringbuffer SharedAI | 21/7/2026 | 23/7/2026 | Data::RingBuffer::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in ring.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW… | |
| Aplazada | Media (5.5) | 0.15% | — | Data Roaringbitmap SharedAI | 21/7/2026 | 24/7/2026 | Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in roaring.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable).… | |
| Aplazada | Baja (3.8) | 0.14% | — | Perl Data Hashmap SharedAI | 21/7/2026 | 23/7/2026 | Data::HashMap::Shared versions before 0.14 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in shm_generic.h with open(path, O_RDWR | O_CREAT | O_CLOEXEC, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644… | |
| Aplazada | Baja (3.8) | 0.14% | — | Data Radixtree SharedAI | 21/7/2026 | 23/7/2026 | Data::RadixTree::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in radix.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW… | |
| Aplazada | Baja (3.8) | 0.14% | — | Data Sortedset SharedAI | 21/7/2026 | 23/7/2026 | Data::SortedSet::Shared versions before 0.03 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sortedset.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable).… | |
| Aplazada | Baja (3.8) | 0.14% | — | Perl Data Reqrep SharedAI | 21/7/2026 | 23/7/2026 | Data::ReqRep::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in reqrep.h with open(path, O_RDWR | O_CREAT, 0666), for both the request-reply and the integer-variant segments. The mode is 0666, so under the default umask… | |
| Aplazada | Baja (3.8) | 0.14% | — | Data Pubsub SharedAI | 21/7/2026 | 23/7/2026 | Data::PubSub::Shared versions before 0.07 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in pubsub.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW is… | |
| Aplazada | Baja (3.3) | 0.14% | — | Data Ndarray SharedAI | 21/7/2026 | 30/7/2026 | Data::NDArray::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in ndarray.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW… | |
| Aplazada | Baja (3.3) | 0.14% | — | Data Graph SharedAI | 21/7/2026 | 23/7/2026 | Data::Graph::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in graph.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW is… | |
| Aplazada | Baja (3.8) | 0.14% | — | Data Deque SharedAI | 21/7/2026 | 23/7/2026 | Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in deque.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW is… | |
| Aplazada | Media (6.2) | 0.18% | — | Data Buffer SharedAI | 21/7/2026 | 23/7/2026 | Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_NOFOLLOW. The segment is created in buf_generic.h with open(path, O_RDWR|O_CREAT|O_EXCL, 0666). O_EXCL blocks a pre-seeded file on create, but the mode is 0666, so under the default umask 022 the file is… | |
| Aplazada | Crítica (9.8) | 0.55% | — | Perl Data Disjointset SharedAI | 21/7/2026 | 23/7/2026 | Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_find. The attach-time validator dsu_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then trusts. dsu_find… | |
| Aplazada | Alta (7.8) | 0.17% | — | Data Spatialhash SharedAI | 21/7/2026 | 22/7/2026 | Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, link and free-list indices in sph_walk_cell and sph_alloc_slot. The attach-time validator sph_validate_header checks the header scalars and region layout against the file size, but does not validate the… | |
| Aplazada | Crítica (9.1) | 0.54% | — | Perl Data Intern SharedAI | 21/7/2026 | 22/7/2026 | Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find. The attach-time validator si_validate_header is thorough about the header and layout (magic, version, section offsets, total_size, count and arena_used) but does not validate… | |
| Aplazada | Crítica (9.8) | 0.60% | — | Perl Data Ringbuffer SharedAI | 21/7/2026 | 22/7/2026 | Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq. The attach-time validator ring_validate_header checks the capacity-overflow and total_size consistency of the header but never caps elem_size against the destination size. ring_read_seq… | |
| Aplazada | Media (6.3) | 0.29% | — | Data Roaringbitmap SharedAI | 21/7/2026 | 23/7/2026 | Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via an unvalidated container offset and cardinality in rb_contains_locked. The attach-time validator rb_validate_header checks the header scalars and region layout against the file size, but does not validate the bucket contents it… | |
| Aplazada | Crítica (9.1) | 0.54% | — | Data Hashmap SharedAI | 21/7/2026 | 22/7/2026 | Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy. The attach-time validator shm_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then trusts.… | |
| Aplazada | Crítica (9.1) | 0.54% | — | Data Radixtree SharedAI | 21/7/2026 | 22/7/2026 | Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked. The attach-time validator rdx_validate_header checks the header scalars and region layout against the file size, but does not validate the node records it then trusts.… |