Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
5400 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.3) | 0.40% | — | Geovision GeoplayerAIGeovision GV VMSAIGeovision GV CloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.40% | — | Geovision WEB PluginAIGeovision GV VMSAIGeovision GV CloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.40% | — | Geovision GeowebplayerAIGeovision GV VMSAIGeovision GV CloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.39% | — | Geovision GeowebplayerAIGeovision GV VMSAIGeovision GV CloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.37% | — | Geovision GeowebplayerAIGeovision Gv-vmsAIGeovision Gv-cloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.37% | — | Geovision GeowebplayerAIGeovision Gv-vmsAIGeovision Gv-cloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.45% | — | Geovision VMSAIGeovision GV CloudAIGeovision GeowebplayerAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.37% | — | Geovision SoftwareAIGeovision Gv-vmsAIGeovision Gv-cloudAIGeovision GeowebplayerAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.37% | — | Geovision GeoplayerAIGeovision GV VMSAIGeovision GV CloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.37% | — | Geovision GeoplayerAIGeovision GV VMSAIGeovision GV CloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.37% | — | Geovision GeoplayerAIGeovision GV VMSAIGeovision GV CloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.37% | — | Geovision GeowebplayerAIGeovision Gv-vmsAIGeovision Gv-cloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.37% | — | Geovision GeowebplayerAIGeovision Gv-vmsAIGeovision Gv-cloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.8) | 0.38% | — | Geovision GeowebplayerAIGeovision GV VMSAIGeovision GV CloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Pendiente de análisis | Alta (7.6) | 0.20% | — | Cloudflare Universal SSLAI | 1/7/2026 | 2/7/2026 | Description: To issue and renew TLS certificates on behalf of customers, Cloudflare's Universal SSL feature automatically manages the CAA RRset for the customer's zone. This auto-managed RRset is permissive by design (e.g. 'issue "letsencrypt.org"' without parameters). On Universal SSL zones, Cloudflare's… | |
| Aplazada | Alta (7.1) | 0.40% | — | Iocoder Yudao-cloudAI | 30/6/2026 | 14/7/2026 | yudao-cloud before 2026.06 contains a broken access control vulnerability in the BPM module that allows any authenticated user to access arbitrary process instance records by supplying a caller-controlled process-instance identifier to an unprotected endpoint lacking the @PreAuthorize annotation. Attackers can query… | |
| Analizada | Alta (7.9) | 0.63% | — | Amazon Cloudfront | 29/6/2026 | 1/7/2026 | Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected. This issue was remediated server-side. No… | |
| Aplazada | Alta (7.7) | 0.74% | — | Cloudflare WarpAI | 24/6/2026 | 25/6/2026 | Warp is an agentic development environment. From 0.2024.03.12.08.02.stable_01 until 0.2026.05.06.15.42.stable_01, Warp contains an OS command injection vulnerability in the WSL URL-opening fallback. When Warp is running under WSL and cannot open a URL through wslview, it falls back to a Windows command processor path.… | |
| Aplazada | Media (4.3) | 0.40% | 💥 PoC | Cloudflare WarpAI | 24/6/2026 | 25/6/2026 | Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp accepted certain state-mutating terminal lifecycle hooks from the PTY stream without verifying that the hooks were emitted by Warp's shell integration for the active session. An attacker who could… | |
| Aplazada | Alta (8.8) | 1.4% | 💥 PoC | Cloudflare WarpAI | 24/6/2026 | 25/6/2026 | Warp is an agentic development environment. From 0.2023.03.21.08.02.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection issue in the legacy SSH background command path. Warp used the remote working directory reported by the session when building helper commands for SSH-backed metadata… | |
| Aplazada | Alta (7.8) | 0.89% | — | Cloudflare WarpAI | 24/6/2026 | 25/6/2026 | Warp is an agentic development environment. From 0.2024.02.20.08.01.stable_01 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection issue in the Linux external editor launcher. Warp expanded freedesktop .desktop Exec templates for affected editor integrations and executed the expanded command through a… | |
| Aplazada | Alta (8.1) | 0.38% | — | Cloudflare WarpAI | 24/6/2026 | 25/6/2026 | Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp allows terminal output to request access to the local system clipboard. A malicious remote host, remote program, or other attacker-controlled terminal output source can trigger clipboard reads or… | |
| Aplazada | Alta (8.6) | 0.22% | — | Cloudflare WarpAI | 24/6/2026 | 25/6/2026 | Warp is an agentic development environment. From 0.2025.10.08.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command execution permission-check bypass in the default unsandboxed CLI agent profile. The CLI profile is non-interactive and relies on a command denylist as a safety boundary for commands… | |
| Aplazada | Alta (8.8) | 0.44% | — | Cloudflare WarpAI | 24/6/2026 | 25/6/2026 | Warp is an agentic development environment. From 0.2025.03.05.08.02.stable_00 until 0.2026.05.06.15.42.stable_01, Warp accepts non-inline `OSC 1337;File` payloads from terminal output and materialize the decoded payload as a local file without an additional confirmation step. This vulnerability is fixed in… | |
| Aplazada | Alta (8) | 1.3% | — | Cloudflare WarpAI | 24/6/2026 | 25/6/2026 | Warp is an agentic development environment. From 0.2025.08.06.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection in the prompt branch selector. A user who can publish a branch to a Git repository opened in Warp can cause a crafted branch name to be interpreted by the victim's shell… |