Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
5113 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6) | 0.41% | — | Sysadminsmedia HomeboxAI | 21/9/2026 | 29/9/2026 | HomeBox is a home inventory and organization system. Prior to 0.26.0, the default-on BlockBogonNets and BlockCloudMetadata notifier SSRF protections in backend/internal/sys/validate/notifier_url.go do not inspect IPv4 destinations embedded in the NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48. An authenticated user… | |
| Aplazada | Alta (8.1) | 0.45% | — | Sysadminsmedia HomeboxAI | 21/9/2026 | 23/9/2026 | HomeBox is a home inventory and organization system. Prior to 0.26.0, NotifierRepository.Update in backend/internal/data/repo/repo_notifier.go updates a notifier through UpdateOneID(id) without requiring the record's user ID to match the authenticated user. An authenticated user who supplies another tenant's notifier… | |
| Aplazada | Alta (8.1) | 0.49% | — | Sysadminsmedia HomeboxAI | 21/9/2026 | 23/9/2026 | HomeBox is a home inventory and organization system. Prior to 0.26.0, MaintenanceEntryRepository.Update and MaintenanceEntryRepository.Delete in backend/internal/data/repo/repo_maintenance_entry.go use UpdateOneID(id) and DeleteOneID(id) without verifying that the maintenance entry belongs to the authenticated user's… | |
| Aplazada | Media (5.4) | 0.29% | — | Sysadminsmedia HomeboxAI | 21/9/2026 | 29/9/2026 | HomeBox is a home inventory and organization system. Prior to 0.26.0, POST /v1/groups/members invokes HandleGroupMemberAdd and GroupService.AddMember using a caller-supplied userID without requiring an owner role, an invitation token, target-user consent, or target-user notification. Any authenticated user can force… | |
| Aplazada | Alta (8.1) | 0.49% | — | Sysadminsmedia HomeboxAI | 21/9/2026 | 23/9/2026 | HomeBox is a home inventory and organization system. Prior to 0.26.0, HandleWipeInventory in backend/app/api/handlers/v1/v1_ctrl_actions.go authorizes POST /v1/actions/wipe-inventory through the global ctx.User.IsOwner value instead of the caller's role in the active group, while the active group is selected through… | |
| Pendiente de análisis | Media (6.1) | 0.33% | — | Semantic-mediawiki Semantic MediawikiAI | 18/9/2026 | 24/9/2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. In versions 7.0.0 through 7.1.0, `Special:Ask` accepts a `cursor` query parameter for keyset pagination (added in 7.0.0). The token is decoded by `CursorEncoder`, which is an **unsigned**… | |
| Pendiente de análisis | Media (6.1) | 0.26% | — | MediawikiAISemantic-mediawiki Semantic MediawikiAI | 18/9/2026 | 24/9/2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, query debug output (`format=debug`, or the `debug` request parameter on `Special:Ask`) is assembled by `SMW\Query\DebugFormatter` and emitted as raw HTML. Several of… | |
| Pendiente de análisis | Media (6.1) | 0.25% | — | MediawikiAISemantic-mediawiki Semantic MediawikiAI | 18/9/2026 | 24/9/2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, `Special:URIResolver` resolves its user-controlled subpage to a MediaWiki title and issues an HTTP 303 redirect to `$title->getFullURL()` without validating the… | |
| Pendiente de análisis | Media (6.1) | 0.26% | — | Semantic-mediawiki Semantic MediawikiAI | 18/9/2026 | 24/9/2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, when the `value` parameter was reflected back into rendered output and error messaging paths without enough output-context encoding. Version 7.2.0 fixes the issue. | |
| Pendiente de análisis | Media (6.1) | 0.26% | — | Semantic-mediawiki Semantic MediawikiAI | 18/9/2026 | 23/9/2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, `sep` was inserted verbatim into HTML cell joins. This made it possible to inject HTML through the separator value. Version 7.2.0 fixes the issue. | |
| Pendiente de análisis | Media (6.1) | 0.26% | — | Semantic-mediawiki Semantic MediawikiAI | 18/9/2026 | 24/9/2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, when `headers=plain`, table header text was emitted into `<th>` via a raw HTML path. User-controlled `mainlabel` content could therefore become executable HTML. Version… | |
| Pendiente de análisis | Alta (8.6) | 0.29% | — | Semantic-mediawiki Semantic MediawikiAI | 18/9/2026 | 24/9/2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and prior to 7.0.0 insert the unsanitized value of a data attribute into the DOM as HTML, allowing for stored XSS through wikitext. Version 7.0.0 patches the issue. | |
| Aplazada | Crítica (9.4) | 0.51% | — | Obsidian WEB MCPAI | 17/9/2026 | 30/9/2026 | Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authorization code without a login, consent, or session check, and /oauth/token can exchange that code for the static VAULT_MCP_TOKEN without authenticating a client. An unauthenticated remote caller who can… | |
| Aplazada | Media (6.9) | 0.19% | — | McpvaultAIObsidianAI | 15/9/2026 | 30/9/2026 | MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5, PathFilter in src/pathfilter.ts uses root-anchored deny-list patterns, so nested .git, .obsidian, and node_modules path segments do not match the restriction and pass both isAllowed() and… | |
| Aplazada | Alta (7.5) | 0.49% | — | Mediawiki EmbedvideoAI | 15/9/2026 | 30/9/2026 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with the default $wgEmbedVideoRequireConsent configuration enabled, includes/EmbedService/EmbedHtmlFormatter.php places JSON… | |
| Aplazada | Alta (8.6) | 0.48% | — | Mediawiki EmbedvideoAI | 15/9/2026 | 30/9/2026 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedHtmlFormatter::toHtml in includes/EmbedService/EmbedHtmlFormatter.php passes the user-supplied class value directly to… | |
| Pendiente de análisis | Alta (8.1) | 0.39% | — | Openbmc Phosphor-net-ipmidAINvidia IpmiAIH3C IpmiAI | 15/9/2026 | 18/9/2026 | OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force the RAKP Message 1 handler to return before it overwrites the authentication object's constructor defaults. The IPMI service then accepts a RAKP Message 3 whose HMAC is computed with the constant… | |
| Pendiente de análisis | Alta (8.8) | 0.27% | — | Openbmc Phosphor-net-ipmidAINvidia IpmiAIH3C IpmiAI | 15/9/2026 | 18/9/2026 | OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an existing session can be replaced with a target account while still maintaining the original integrity and encryption keys. Several downstream vendors implement phosphor-net-ipmid as their IPMI stack,… | |
| Pendiente de análisis | Baja (3.1) | 0.24% | — | Mediawiki ProofreadpageAI | 14/9/2026 | 16/9/2026 | An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3. It leaks information about a suppressed user via the API and config variables. | |
| Pendiente de análisis | Media (5.4) | 0.21% | — | Mediawiki MassmessageAIMediawikiAI | 14/9/2026 | 28/9/2026 | An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss URL, the i18n key massmessage-form-page-help allows XSS. | |
| Pendiente de análisis | Baja (3.1) | 0.24% | — | Mediawiki CheckuserAIMediawikiAI | 14/9/2026 | 16/9/2026 | An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden. | |
| Aplazada | Media (4.2) | 0.19% | — | Rtcamp RtmediaAI | 13/9/2026 | 14/9/2026 | The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changing the privacy level of an activity and its attached media, relying only on a nonce shared with every logged-in user, allowing users with a subscriber-level account or above to make another user's… | |
| Aplazada | Alta (7.5) | 0.34% | — | Rtcamp RtmediaAI | 12/9/2026 | 15/9/2026 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'compare' parameter in all versions up to, and including, 4.7.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Aplazada | Media (4.3) | 0.28% | — | Arma Digital Media INC Website TemplateAI | 11/9/2026 | 11/9/2026 | Improper neutralization of special elements used in a template engine vulnerability in Arma Digital Media Inc. Website Template allows Code Injection. This issue affects Website Template: through 11092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Media (6.4) | 0.36% | — | Media Library AssistantAI | 11/9/2026 | 11/9/2026 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset export/import mechanism in versions up to and including 3.35. This is due to insufficient output escaping on preset field values when they are rendered in HTML attribute contexts in the… |