Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
30.457 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.36% | — | MakecommerceAI | 30/9/2026 | 30/9/2026 | Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions. | |
| Aplazada | Media (5.8) | 0.21% | — | Pluginrx Broken Link NotifierAI | 30/9/2026 | 30/9/2026 | The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate the destination of redirects when checking links, allowing unauthenticated attackers to bypass its internal-address filter and make the server send requests to internal services. | |
| Aplazada | Media (6.8) | 0.24% | — | Keywordrush Content EGGAI | 30/9/2026 | 30/9/2026 | The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulting post, allowing users with contributor-level access and above to store arbitrary… | |
| Pendiente de análisis | Alta (7.5) | 0.25% | — | Wikimedia UserpageviewtrackerAI | 29/9/2026 | 1/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wikimedia Foundation Mediawiki - UserPageViewTracker Extension allows SQL Injection. This issue affects Mediawiki - UserPageViewTracker Extension: from * before 1.46.1, 1.45.5, 1.43.10. | |
| Pendiente de análisis | Alta (7.5) | 0.37% | — | Socket.io Cluster-engineAI | 29/9/2026 | 30/9/2026 | Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 0.1.1, @socket.io/cluster-engine uses inherited object properties when looking up attacker-controlled session IDs in clustered deployments. Special property names such as __proto__ or constructor can resolve through the object… | |
| Aplazada | Alta (7) | 0.24% | — | ClipbucketAI | 29/9/2026 | 30/9/2026 | ClipBucket v5 through 5.5.3-#197 contains a time-based blind SQL injection vulnerability in the language update function where the language_id parameter is concatenated unescaped into the WHERE clause of an UPDATE statement. An authenticated administrator with basic_settings permission can inject arbitrary SQL… | |
| Aplazada | Alta (7) | 0.24% | — | ClipbucketAI | 29/9/2026 | 2/10/2026 | ClipBucket v5 through 5.5.3-#197 contains a time-based blind SQL injection vulnerability in the admin video edit function where the videoid parameter is concatenated into an UPDATE statement without proper escaping. An authenticated administrator with video_moderation permission can inject arbitrary SQL commands to… | |
| Modificada | Media (5.5) | 0.15% | — | Linux Kernel | 29/9/2026 | 7/10/2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Check write tracking in all address spaces kvm_gfn_is_write_tracked() checks only the supplied memslot, but page tracking is per-address-space and shadow pages are shared across all address spaces. With SMM, a GFN can therefore be… | |
| Pendiente de análisis | Crítica (9.4) | 0.42% | — | Psyb0t Docker MailboxAI | 29/9/2026 | 29/9/2026 | Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to inject additional IMAP commands into an authenticated upstream mailbox connection via crafted folder, UID, or… | |
| Analizada | Media (6.3) | 0.22% | — | Apache-airflow-providers-snowflake | 29/9/2026 | 7/10/2026 | Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before interpolating them into request URLs. The SQL API endpoint is built as `https://{account}.snowflakecomputing.com/api/v2/statements`, so an `account` value containing `/`, `?` or `#` demotes the intended domain to… | |
| Aplazada | Baja (2) | 0.25% | — | Rocketsoft Rocket LMSAI | 29/9/2026 | 29/9/2026 | A vulnerability was determined in CodeCanyon Rocket LMS up to 2.2. This affects an unknown function of the component Student Profile Image Upload. Executing a manipulation can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was… | |
| Aplazada | Alta (8.4) | 0.70% | — | Token Optimizer MCPAI | 28/9/2026 | 1/10/2026 | Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge graph across 16 CLI clients. Prior to version 5.1.0, token-optimizer-mcp is vulnerable to OS command injection in the smart_user tool. Any MCP client that can call the smart_user tool can execute… | |
| Aplazada | Media (5.3) | 0.45% | — | Token Optimizer MCPAI | 28/9/2026 | 30/9/2026 | Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge graph across 16 CLI clients. Prior to version 5.1.0, the dashboard HTTP server in token-optimizer-mcp exposes /api/session-summary and /api/session-events with no authentication middleware — any… | |
| Pendiente de análisis | Baja (3.7) | 0.23% | — | KeycloakAI | 28/9/2026 | 28/9/2026 | A flaw was found in the Micrometer user-event metrics listener of Keycloak, a solution for integrated identity and access management. The issue occurs when the listener is configured to include the idp tag. An unauthenticated attacker can send requests to the identity broker login endpoint using arbitrary provider… | |
| Aplazada | Baja (2.3) | 0.20% | — | Utcp-gqlAIUtcp-websocketAI | 27/9/2026 | 30/9/2026 | utcp-gql before 1.1.1 and utcp-websocket before 1.1.1 contain server-side request forgery vulnerabilities due to incomplete application of CVE-2026-44661 fixes. The GraphQL plugin uses a vulnerable prefix check allowing bypass URLs like http://127.0.0.1.attacker.example, while the WebSocket plugin performs no URL… | |
| Modificada | Alta (7) | 0.10% | — | Linux Kernel | 26/9/2026 | 7/10/2026 | In the Linux kernel, the following vulnerability has been resolved: cgroup: Avoid iteration of dying tasks with zero refcount The commit 260fbcb92bbea ("cgroup: Move dying_tasks cleanup from cgroup_task_release() to cgroup_task_free()") extended the lifetime of tasks on the dying_tasks list. The iterators have… | |
| Aplazada | Alta (8.4) | 0.36% | — | ClinvokeAIAlastair Lundy ClinvokeAI | 25/9/2026 | 30/9/2026 | CliInvoke and its formerly named `AlastairLundy.CliInvoke` package are .NET libraries for invoking command-line programs and wrapping executable processes. `CliInvoke` versions 2.0.0 through 2.8.4, 2.9.0 through 2.9.3, 2.10.0 through 2.10.4, and 3.0.0-alpha.1 through 3.0.0-beta.1, as well as `AlastairLundy.CliInvoke`… | |
| Aplazada | Alta (8.6) | 1.1% | — | ClipbucketAI | 25/9/2026 | 30/9/2026 | ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authenticated administrators to overwrite PHP files by supplying directory traversal sequences in the folder parameter. Attackers with manage_template_access permission can traverse outside the layout… | |
| Aplazada | Alta (8.4) | 0.58% | — | Clinvoke SpecializationsAIAlastair Lundy Clinvoke SpecializationsAI | 25/9/2026 | 30/9/2026 | CliInvoke is a .NET library for invoking command-line programs, and its `CliInvoke.Specializations` packages provide specialized wrappers for shells such as PowerShell and Windows Command Prompt. `CliInvoke.Specializations` versions 2.2.0 through 2.8.4, 2.9.0 through 2.9.3, 2.10.0 through 2.10.4, 3.0.0-alpha.1 through… | |
| En análisis | Media (6.3) | 0.35% | — | RabbitmqAIRabbitmq Auth Backend LdapAI | 25/9/2026 | 28/9/2026 | RabbitMQ is a messaging and streaming broker. The advisory establishes affected 3.13, 4.0, 4.1, 4.2, and 4.3 maintenance lines but contains conflicting first-fixed versions for the 3.13, 4.0, and 4.1 lines. fill/2 substitutes ${username} into user_dn_pattern without RFC 4514 DN escaping, allowing a crafted username to… | |
| Analizada | Media (5.5) | 0.10% | — | Linux Kernel | 25/9/2026 | 2/10/2026 | In the Linux kernel, the following vulnerability has been resolved: smb/server: fix tree connection leak in smb2_tree_connect() See the procedure below: Disconnect the new tree connection if ksmbd_iov_pin_rsp() fails. | |
| Modificada | Media (5.5) | 0.11% | — | Linux Kernel | 25/9/2026 | 3/10/2026 | In the Linux kernel, the following vulnerability has been resolved: nvdimm: pmem: keep PREFLUSH before data writes pmem_submit_bio() records a REQ_PREFLUSH error, but continues to copy the bio data and can later overwrite the error with a successful REQ_FUA flush. That lets data writes run after a failed preflush and… | |
| Analizada | Media (5.5) | 0.11% | — | Linux Kernel | 25/9/2026 | 2/10/2026 | In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() padapter->HalData is allocated via vzalloc(), but incorrectly freed using kfree() in the rtw_sdio_if1_init() error path. Using kfree() to release this vmalloc-backed buffer can… | |
| Analizada | Media (5.5) | 0.11% | — | Linux Kernel | 25/9/2026 | 2/10/2026 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: unregister debugfs entries on teardown ucsi_register() creates per-instance debugfs entries, but ucsi_unregister() keeps them around until ucsi_destroy(). Drivers like ucsi_glink that unregister/register the same UCSI instance across… | |
| En análisis | Media (5.5) | 0.11% | — | Linux Kernel | 25/9/2026 | 2/10/2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mei: pass correct argument to function The first argument to iwl_mei_write_cyclic_buf() should be the cldev but the q_head pointer is passed instead. Fix it. |