Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.62% | — | Bluewavelabs CheckmateAI | 21/8/2026 | 18/9/2026 | Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. Prior to 3.9.1, the public POST /api/v1/auth/register route in server/src/api/routes/authRoutes.ts passes multipart profileImage uploads through… | |
| Aplazada | Media (5.4) | 0.29% | — | BigbluebuttonAI | 20/8/2026 | 16/9/2026 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape meetingName in record-and-playback/screenshare/playback/index.html.erb when generating the screenshare playback format. A low-privileged user could store a crafted meeting name that embedded script content, and the… | |
| Aplazada | Media (4.9) | 0.31% | — | BigbluebuttonAI | 20/8/2026 | 16/9/2026 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton presenters could submit a presentationId through /api/graphql that identified a presentation belonging to another meeting. akka-bbb-apps/src/main/scala/org/bigbluebutton/core/apps/presentationpod/RemovePresentationPubMsgHdlr.scala did… | |
| Aplazada | Alta (8.5) | 0.58% | — | BigbluebuttonAI | 20/8/2026 | 16/9/2026 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authenticated moderators to inject SQL through the meetingId and userId values used by refreshBreakoutRoomsVisibleForUsers in akka-bbb-apps/src/main/scala/org/bigbluebutton/core/db/BreakoutRoomUserDAO.scala. The method… | |
| Aplazada | Alta (7.1) | 0.37% | — | BigbluebuttonAI | 20/8/2026 | 16/9/2026 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebutton/api/handleJoinExistingUser through bigbluebutton-web/grails-app/controllers/org/bigbluebutton/web/controllers/ApiController.groovy. A requester able to supply an existingUserID for an active participant could reuse… | |
| Aplazada | Media (5.3) | 0.45% | — | Blueprint StudioAIHome-assistant Home AssistantAI | 18/8/2026 | 8/9/2026 | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio backend API handlers in custom_components/blueprint_studio/backend/api.py returned raw exception strings to authenticated Home Assistant users. Some exception messages could contain internal… | |
| Aplazada | Media (5.1) | 0.76% | — | Blueprint StudioAIHome-assistant Home AssistantAI | 18/8/2026 | 8/9/2026 | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, the legacy stateless terminal command execution path in custom_components/blueprint_studio/backend/terminal_manager.py accepted a cwd working-directory parameter and checked only whether the directory existed,… | |
| Aplazada | Media (5.6) | 0.21% | — | Blueprint StudioAI | 18/8/2026 | 8/9/2026 | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio terminal SSH key authentication in custom_components/blueprint_studio/backend/terminal_manager.py wrote SSH private-key material to a file under the Home Assistant configuration directory before… | |
| Aplazada | Alta (8.6) | 0.50% | — | Blueprint StudioAIHome-assistant Home AssistantAI | 18/8/2026 | 8/9/2026 | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio generated a shell-based Git credential helper in custom_components/blueprint_studio/backend/git_manager.py by interpolating the configured Git username and token directly into executable helper… | |
| Aplazada | Media (6.9) | 0.46% | — | GITAIHome-assistant Blueprint StudioAI | 18/8/2026 | 8/9/2026 | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio configured Git's credential.helper store when saving Git credentials, causing Git credential-store to persist usernames and access tokens in plaintext in the .git-credentials file for the user… | |
| Aplazada | Alta (8.7) | 0.45% | — | Blueprint StudioAIHome-assistant Home AssistantAI | 18/8/2026 | 8/9/2026 | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio exposed administrator-intended backend API actions to any authenticated Home Assistant user because the backend did not consistently enforce the panel's admin-only authorization boundary. Affected… | |
| Pendiente de análisis | Media (6.3) | 0.24% | — | BluezAI | 18/8/2026 | 20/8/2026 | A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP) implementation allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This vulnerability, affecting the parse_media_element() and… | |
| Aplazada | Alta (7.2) | 0.42% | — | Platnosci Online Blue MediaAI | 16/8/2026 | 20/8/2026 | The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.0 via the 'bm_woocommerce_css_editor_content' POST parameter. This is due to the Css_Editor::handle_save() method being wired to the WordPress 'init' hook by… | |
| Pendiente de análisis | Media (5.9) | 0.25% | — | Realtek BEE Bluetooth HCI DriverAI | 11/8/2026 | 26/8/2026 | The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci_bee.c, violated the bt_hci_driver_api buffer-ownership contract. That contract requires the driver to consume (unref) the transmit net_buf only on success; on an error return the host caller retains ownership and… | |
| Aplazada | Media (5.3) | 0.42% | — | Bluewavelabs CheckmateAI | 10/8/2026 | 28/8/2026 | A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to determine whether a given email address is registered. The POST /api/v1/auth/recovery/request endpoint returns HTTP 200 for registered email addresses and a different status code for unregistered… | |
| Aplazada | Media (4.1) | 0.29% | — | BigbluebuttonAITHM PilosAI | 6/8/2026 | 10/9/2026 | PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.1.0 until 4.14.1, PILOS does not send a Cross-Origin-Opener-Policy response header, so pages opened by PILOS via a link that opens a new browsing context (e.g., target="_blank") retain a window.opener reference back to the… | |
| Aplazada | Alta (8.2) | 0.33% | — | Bluewavelabs CheckmateAI | 6/8/2026 | 26/8/2026 | The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not properly restrict access to its license-management functionality, relying on a shared secret computed entirely from publicly available information, allowing unauthenticated attackers to deactivate the… | |
| Aplazada | Baja (1.9) | 0.21% | — | Blix Email Blue Mail Calendar APPAIReact Native Receive Sharing IntentAI | 3/8/2026 | 12/8/2026 | A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDataColumn/FileDirectory.getFileFromUri of the component react-native-receive-sharing-intent. The manipulation of the argument _display_name results in path traversal. The attack is only possible with… | |
| Pendiente de análisis | Media (4.3) | 0.30% | — | Bluez SBCAI | 22/7/2026 | 30/7/2026 | A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio payload to trigger a one-byte heap out-of-bounds read. This could allow an adjacent attacker streaming Bluetooth audio to read a single byte of adjacent heap memory. | |
| Aplazada | Media (6.8) | 0.43% | — | BigbluebuttonAI | 16/7/2026 | 17/7/2026 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, the presentation URL validation did not properly restrict access to site local and link local addresses. The redirect following logic now pins resolved IPs. This issue is fixed in version 3.0.23. | |
| Aplazada | Alta (8.1) | 0.48% | — | BigbluebuttonAI | 16/7/2026 | 17/7/2026 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web checksum validation could be bypassed when a presentationUploadExternalUrl parameter was supplied to API request handling in CreateMeeting.java and ValidationService.java, allowing a user to send valid requests to some endpoints without a… | |
| Aplazada | Alta (8.1) | 0.46% | — | BigbluebuttonAI | 16/7/2026 | 17/7/2026 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web generated conference sessionToken values with insufficiently secure randomness in bbb-common-web/src/main/java/org/bigbluebutton/api/Util.java and bigbluebutton-web/grails-app/controllers/org/bigbluebutton/web/controllers/ApiController.groovy,… | |
| Pendiente de análisis | Crítica (9.8) | 0.66% | — | Ciena Navigator Network Control SuiteAICiena Manage Control PlanAICiena Blue PlanetAI | 14/7/2026 | 15/7/2026 | An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. The issue is caused by improper handling of HTTP request paths and headers, which allows an unauthenticated attacker to manipulate requests in a manner… | |
| Aplazada | Baja (2.1) | 0.49% | — | Stephen Kruger BlueboxAI | 5/7/2026 | 6/7/2026 | A vulnerability was found in stephen-kruger bluebox up to 4.5.12. Affected by this vulnerability is an unknown functionality. Performing a manipulation of the argument code results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The project… | |
| Pendiente de análisis | Crítica (9) | 0.37% | — | Nvidia ConnectxAINvidia BluefieldAI | 1/7/2026 | 6/10/2026 | NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device. |