Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
23.377 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.4) | 0.23% | — | Zephyrproject ZephyrAI | 31/8/2026 | 1/9/2026 | The LwM2M JSON content formatter's get_string() in subsys/net/lib/lwm2m/lwm2m_rw_json.c copies a parsed JSON string into a caller-supplied buffer and NUL-terminates it. The length guard used if (string_length > buflen), which accepts a string whose length is exactly buflen. After memcpy() fills the whole buffer,… | |
| Pendiente de análisis | Media (6.4) | 0.16% | — | Silabs Siwx917AIZephyrproject ZephyrAI | 31/8/2026 | 1/9/2026 | The Silicon Labs SiWx917 WiFi driver's transmit callback siwx91x_send() in drivers/wifi/siwx91x/siwx91x_wifi.c frees a network packet it does not own. In the Zephyr TX path the net_pkt is owned by the L2/networking stack; the driver only borrows it to copy the frame bytes into a local net_buf. Before the fix, after… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Online Shopping SystemAI | 31/8/2026 | 2/9/2026 | A vulnerability was determined in code-projects Online Shopping System 1.0. Affected by this issue is some unknown functionality of the file /action.php of the component Search Functionality. This manipulation of the argument keyword causes sql injection. It is possible to initiate the attack remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.47% | — | Code-projects Online Shopping SystemAI | 31/8/2026 | 31/8/2026 | A vulnerability was found in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /offersmail.php of the component Newsletter Subscription. The manipulation of the argument email results in cross site scripting. The attack may be performed from remote. The… | |
| Aplazada | Baja (2.1) | 0.37% | — | Diem-project DiemAI | 31/8/2026 | 2/9/2026 | A security flaw has been discovered in diem-project diem up to 5.1.3. The impacted element is an unknown function of the file dmFrontPlugin/lib/dmWidget/media/dmWidgetContentBaseMediaForm.php of the component Widget Editor. Performing a manipulation results in unrestricted upload. The attack may be initiated remotely.… | |
| Aplazada | Baja (2) | 2.2% | — | Diem-project DiemAI | 31/8/2026 | 31/8/2026 | A vulnerability was identified in diem-project diem up to 5.1.3. The affected element is the function executeCommand of the file dmAdminPlugin/modules/dmConsole/actions/actions.class.php of the component Administrative Console. Such manipulation of the argument dm_command leads to os command injection. The attack can… | |
| Aplazada | Baja (1.9) | 0.52% | — | Lfprojects ValkeyAI | 31/8/2026 | 31/8/2026 | A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/module.c of the component Module Timer Subsystem. This manipulation causes double free. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name:… | |
| Aplazada | Baja (1.2) | 0.55% | — | Lfprojects ValkeyAI | 31/8/2026 | 31/8/2026 | A security flaw has been discovered in valkey-io valkey 9.1.0. The affected element is the function handleClientsBlockedOnKey of the file src/blocked.c of the component Blocked-on-keys Subsystem. The manipulation results in use after free. The attack may be performed from remote. A high complexity level is associated… | |
| Aplazada | Baja (2.1) | 0.47% | — | Code-projects Simple Inventory SystemAI | 31/8/2026 | 1/9/2026 | A vulnerability has been found in code-projects Simple Inventory System 1.0. This affects an unknown part of the file /register.php of the component User Registration. Such manipulation of the argument last_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (5.5) | 0.53% | — | Code-projects Simple Inventory SystemAI | 31/8/2026 | 31/8/2026 | A flaw has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown functionality of the file inventorymanagement.sql of the component Database Backup File Handler. This manipulation causes information disclosure. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Baja (2) | 0.35% | — | Code-projects Employee Leave Managing SystemAI | 31/8/2026 | 31/8/2026 | A security vulnerability has been detected in code-projects Employee Leave Managing System 1.0. Affected is an unknown function of the file /EmpManageSys/editaction.php of the component Employee Profile Update. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated remotely.… | |
| Aplazada | Baja (2.3) | 0.47% | — | Ash-project ASH PhoenixAI | 31/8/2026 | 1/9/2026 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_phoenix writes the entire raw submitted param map into an exception message, so secrets submitted alongside a union form field leak into logs, crash reports and the dev error page. When AshPhoenix.Form.Auto builds a union… | |
| Aplazada | Media (6.3) | 0.52% | — | Ash-project ASH PhoenixAI | 31/8/2026 | 1/9/2026 | Permissive Regular Expression vulnerability in ash-project ash_phoenix lets a remote client select the tenant an Ash application uses, or degrade the request, by sending a crafted Host header. AshPhoenix.Helpers.get_subdomain/2 stripped the root domain with String.replace(host, ~r/.?#{root_host}/, ""). The root host… | |
| Aplazada | Baja (2.3) | 0.45% | — | Ash-project ASH PhoenixAI | 31/8/2026 | 1/9/2026 | Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_phoenix lets an attacker who controls filter form parameters filter across relationships the resource author marked non-public, turning the returned rows into a boolean oracle over private related data. AshPhoenix.FilterForm resolved… | |
| Aplazada | Alta (7.6) | 0.43% | — | Ash-project ASH PhoenixAI | 31/8/2026 | 1/9/2026 | Incorrect Authorization vulnerability in ash-project ash_phoenix invokes the SubdomainHook authorization callback with a nil tenant, so tenant-scoped access checks never see the tenant they are meant to enforce. AshPhoenix.LiveView.SubdomainHook.on_mount/4 attached a handle_params hook to assign the tenant and then… | |
| Aplazada | Alta (8.3) | 0.47% | — | Ash-project ASH AdminAI | 31/8/2026 | 1/9/2026 | Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_admin lets any client that can reach the admin LiveView exhaust the BEAM atom table and crash the entire node. Two LiveView event handlers interned atoms from unvalidated client input: AshAdmin.PageLive's set_actor built modules from… | |
| Aplazada | Baja (2) | 0.47% | — | Ash-project ASH AdminAI | 31/8/2026 | 1/9/2026 | Improper Encoding or Escaping of Output vulnerability in ash-project ash_admin lets an attacker who controls a record's string primary key rewrite the target of AshAdmin's row-action links. The Table, DataTable, and Show components built row-action URLs by raw string interpolation, splicing the primary key (and table,… | |
| Aplazada | Alta (8.3) | 0.79% | — | Ash-project ASH AdminAI | 31/8/2026 | 1/9/2026 | Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in ash-project ash_admin allows writing attacker-controlled bytes to arbitrary paths on the server. AshAdmin.Components.Resource.Form.consume_file_uploads/1 builds the destination as Path.join([tmp_dir, entry.client_name]) and… | |
| Aplazada | Baja (2.3) | 0.45% | — | Ash-project ASH AdminAI | 31/8/2026 | 1/9/2026 | Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_admin turns a record-lookup URL into an equality oracle over sensitive attributes. AshAdmin.Helpers.decode_primary_key/2 decodes the composite-primary-key form (Base64 plus ETF) and returns the decoded map verbatim as the lookup filter,… | |
| Aplazada | Baja (2.1) | 0.53% | — | Ash-project ASH AdminAI | 31/8/2026 | 1/9/2026 | Use of Insufficiently Random Values vulnerability in ash-project ash_admin ships a hardcoded, publicly known CSP nonce, defeating nonce-based Content-Security-Policy protection. When mounted without :csp_nonce_assign_key, AshAdmin.Router.ash_admin/2 defaulted the img, style, and script nonces to the literal constant… | |
| Aplazada | Alta (8.4) | 0.48% | — | Ash-project ASH AdminAI | 31/8/2026 | 1/9/2026 | Stored Cross-site Scripting vulnerability in ash-project ash_admin executes attacker-supplied record content as script in an administrator's browser. The relationship typeahead components AshAdmin.Components.Resource.RelationshipField and AshAdmin.Components.Resource.ManagedRelationshipSelectField highlight the… | |
| Aplazada | Alta (8.3) | 0.52% | — | Ash-project ASH AdminAI | 31/8/2026 | 1/9/2026 | Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin's client JavaScript read its state cookies (tenant, actor_resource,… | |
| Aplazada | Media (5.3) | 0.47% | — | Ash-project ASH AIAI | 31/8/2026 | 1/9/2026 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In AshAi.ToolLoop and AshAi.Tools, an exception raised while executing a tool was serialized verbatim with Exception.message/1 into the tool-result content. That content is… | |
| Aplazada | Media (6) | 0.47% | — | Ash-project ASH AIAI | 31/8/2026 | 1/9/2026 | Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests. AshAi.ToolLoop classifies a model response of :tool_calls, then filters the calls through… | |
| Aplazada | Alta (7.1) | 0.54% | — | Ash-project ASH AIAI | 31/8/2026 | 1/9/2026 | Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configured tool to update or destroy records it never identified, including every row in the table. In AshAi.Tool.Execution, identity_filter/3 built the update/destroy filter directly from the raw tool… |