Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1319 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.2) | 0.33% | — | Frappe Erpnext | 1/10/2025 | 17/6/2026 | In Frappe ERPNext 15.57.5, the function get_blanket_orders() at erpnext/controllers/queries.py is vulnerable to SQL Injection, which allows an attacker can extract all information from databases by injecting a SQL query into the blanket_order_type parameter. | |
| Analizada | Alta (8.2) | 0.34% | — | Frappe Erpnext | 1/10/2025 | 17/6/2026 | In Frappe ERPNext 15.57.5, the function get_material_requests_based_on_supplier() at erpnext/stock/doctype/material_request/material_request.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting a SQL query into the txt parameter. | |
| Analizada | Media (6.5) | 0.27% | — | Frappe Erpnext | 30/9/2025 | 17/6/2026 | In Frappe ERPNext 15.57.5, the function get_loyalty_program_details_with_points() at erpnext/accounts/doctype/loyalty_program/loyalty_program.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting a SQL query into the expiry_date parameter. | |
| Analizada | Media (6.5) | 0.27% | — | Frappe Erpnext | 30/9/2025 | 17/6/2026 | In Frappe ErpNext v15.57.5, the function get_timesheet_detail_rate() at erpnext/projects/doctype/timesheet/timesheet.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting SQL query into the timelog parameter. | |
| Analizada | Media (6.5) | 0.26% | — | Frappe Erpnext | 30/9/2025 | 17/6/2026 | In Frappe ErpNext v15.57.5, the function get_income_account() at erpnext/controllers/queries.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting a SQL query into the filters.disabled parameter. | |
| Analizada | Media (6.5) | 0.26% | — | Frappe Erpnext | 30/9/2025 | 17/6/2026 | In Frappe ERPNext v15.57.5, the function import_coa() at erpnext/accounts/doctype/chart_of_accounts_importer/chart_of_accounts_importer.py is vulnerable to SQL injection, which allows an attacker to extract all information from databases by injecting a SQL query into the company parameter. | |
| Modificada | Media (5.8) | 0.21% | — | RTI Connext Professional | 23/9/2025 | 22/9/2026 | Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation. This issue affects Connext Professional: from 7.5.0 before 7.6.0. | |
| Modificada | Alta (8.3) | 0.37% | — | RTI Connext Professional | 23/9/2025 | 22/9/2026 | Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation. This issue affects Connext Professional: from 7.4.0 before 7.6.0, from 7.0.0 before 7.3.0.10, from 6.1.0 before 6.1.2.27, from 6.0.0 before 6.0.1.43, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*,… | |
| Modificada | Media (4.8) | 0.14% | — | RTI Connext Professional | 23/9/2025 | 22/9/2026 | Buffer Over-read, Off-by-one Error vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation, Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.6.0, from 7.0.0 before 7.3.0.8, from 6.1.0 before 6.1.2.26, from 6.0.0 before 6.0.1.43, from 5.3.0 before 5.3.*, from… | |
| Modificada | Alta (8.3) | 0.37% | — | RTI Connext Professional | 23/9/2025 | 22/9/2026 | Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation. This issue affects Connext Professional: from 7.4.0 before 7.6.0, from 7.2.0 before 7.3.0.9. | |
| Aplazada | Media (6.5) | 0.21% | — | Nextendweb Nextend Facebook ConnectAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nextendweb Nextend Facebook Connect nextend-facebook-connect allows Stored XSS.This issue affects Nextend Facebook Connect : from n/a through <= 3.1.19. | |
| Analizada | Alta (7.5) | 0.39% | — | Frappe Erpnext | 16/9/2025 | 17/6/2026 | In Frappe ERPNext v15.57.5, the function get_stock_balance() at erpnext/stock/utils.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting SQL query into inventory_dimensions_dict parameter. | |
| Aplazada | Alta (8.8) | 0.41% | — | Error-exAIBabelAINext.jsAIRollupjs RollupAI+1 | 15/9/2025 | 17/6/2026 | error-ex allows error subclassing and stack customization. On 8 September 2025, an npm publishing account for error-ex was taken over after a phishing attack. Version 1.3.3 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency… | |
| Aplazada | Alta (8.8) | 0.41% | — | Simple-swizzleAIBabelAIVercel Next.jsAIRollupjs RollupAI+1 | 15/9/2025 | 17/6/2026 | simple-swizzle swizzles function arguments. On 8 September 2025, the npm publishing account for simple-swizzle was taken over after a phishing attack. Version 0.2.3 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions… | |
| Aplazada | Alta (8.8) | 0.41% | — | BacklashAINPMAIBabelAIVercel Next.jsAI+2 | 15/9/2025 | 17/6/2026 | backlash parses collected strings with escapes. On 8 September 2025, the npm publishing account for backslash was taken over after a phishing attack. Version 0.2.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to… | |
| Aplazada | Alta (8.8) | 0.55% | — | Color-nameAIBabelAIVercel Next.jsAIRollupjs RollupAI+1 | 15/9/2025 | 30/9/2026 | color-name is a JSON with CSS color names. On 8 September 2025, an npm publishing account for color-name was taken over after a phishing attack. Version 2.0.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the… | |
| Analizada | Crítica (9.1) | 0.32% | — | Frappe Erpnext | 6/9/2025 | 17/6/2026 | ERP is a free and open source Enterprise Resource Planning tool. In versions below 14.89.2 and 15.0.0 through 15.75.1, lack of validation of parameters left certain endpoints vulnerable to error-based SQL Injection. Some information like version could be retrieved. This issue is fixed in versions 14.89.2 and 15.76.0. | |
| Analizada | Alta (8.2) | 2.5% | 💥 Exploit | Vercel Next.js | 29/8/2025 | 17/6/2026 | Next.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next() was used without explicitly passing the request object, it could lead to SSRF in self-hosted applications that incorrectly forwarded user-supplied headers. This vulnerability has been fixed in… | |
| Analizada | Media (6.2) | 0.35% | — | Vercel Next.js | 29/8/2025 | 17/6/2026 | Next.js is a React framework for building full-stack web applications. In versions before 14.2.31 and from 15.0.0 to before 15.4.5, Next.js Image Optimization API routes are affected by cache key confusion. When images returned from API routes vary based on request headers (such as Cookie or Authorization), these… | |
| Analizada | Media (4.3) | 0.53% | — | Vercel Next.js | 29/8/2025 | 17/6/2026 | Next.js is a React framework for building full-stack web applications. In versions before 14.2.31 and from 15.0.0 to before 15.4.5, Next.js Image Optimization is vulnerable to content injection. The issue allowed attacker-controlled external image sources to trigger file downloads with arbitrary content and filenames… | |
| Aplazada | Alta (7.1) | 0.23% | — | Koen Schuit Nextgen Gallery SearchAI | 28/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Koen Schuit NextGEN Gallery Search nextgen-gallery-search-galleries allows Reflected XSS.This issue affects NextGEN Gallery Search: from n/a through <= 2.12. | |
| Aplazada | Media (6.1) | 0.20% | — | NextchatAI | 22/8/2025 | 17/6/2026 | NextChat contains a cross-site scripting (XSS) vulnerability in the HTMLPreview component of artifacts.tsx that allows attackers to execute arbitrary JavaScript code when HTML content is rendered in the AI chat interface. The vulnerability occurs because user-influenced HTML from AI responses is rendered in an iframe… | |
| Aplazada | Alta (8.1) | 0.43% | — | Pandoranext TokenstoolAI | 21/8/2025 | 17/6/2026 | An authentication bypass vulnerability in PandoraNext-TokensTool v0.6.8 and before. An attacker can exploit this vulnerability to access API without any token. | |
| Aplazada | Media (6.4) | 0.24% | — | Posimyth Nexter BlocksAI | 19/8/2025 | 17/6/2026 | The Nexter Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 4.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access… | |
| Aplazada | Alta (7.5) | 0.53% | — | NextgenassistantAI | 15/8/2025 | 17/6/2026 | The Assistant for NextGEN Gallery plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in the /wp-json/nextgenassistant/v1.0.0/control REST endpoint in all versions up to, and including, 1.0.9. This makes it possible for unauthenticated attackers to delete… |