Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
751 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.53% | — | Broken Link CheckerAI | 2/9/2026 | 2/9/2026 | The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author URL / Link Log in all versions up to, and including, 2.4.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Media (5.5) | 0.41% | — | Ericsson CodecheckerAI | 28/8/2026 | 1/9/2026 | CodeChecker's massStoreRun processing path performs one-shot decompression of attacker-controlled, Base64-encoded zlib data without enforcing a maximum decompressed size. An authenticated user with permission to store analysis runs can submit a highly compressed payload that expands to a significantly larger byte… | |
| Aplazada | Baja (2) | 0.17% | — | Ericsson CodecheckerAI | 28/8/2026 | 1/9/2026 | CVE-2025-40843 https://github.com/advisories/GHSA-5xf2-f6ch-6p8r was fixed by replacing unchecked strcpy() with a bounded safe_strcpy() helper. At ldlogger-tool-gcc.c:129 the destination passed to that helper is fullPath + 2, but the size passed down is the full PATH_MAX. safe_strcpy() is strncpy(), which NUL-pads the… | |
| Aplazada | Alta (7.2) | 0.58% | — | Bluewavelabs CheckmateAI | 27/8/2026 | 1/9/2026 | An issue in the inviteController.js component in Bluewave Labs Checkmate <=3.3.0 allows remote authenticated administrators to escalate privileges to superadmin via the role parameter to the /api/v1/invite endpoint. | |
| Aplazada | Media (5.3) | 0.21% | — | CheckmkAI | 25/8/2026 | 26/8/2026 | Missing authorization in Checkmk <2.5.0p12, <2.4.0p36, <2.3.0p50 and all 2.2.0 versions allows an authenticated user who knows the ID of a background job to view that job's status and results. | |
| Aplazada | Alta (7.5) | 0.48% | — | Bluewavelabs CheckmateAI | 21/8/2026 | 18/9/2026 | Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.3.0 until 3.9.2, enabling the global showURL setting causes the unauthenticated GET /api/v1/status-page/:url endpoint to return complete… | |
| Aplazada | Media (4.9) | 0.59% | — | Bluewavelabs CheckmateAI | 21/8/2026 | 18/9/2026 | Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.5.1 until 3.9.2, an authenticated admin or superadmin can set matchMethod to regex and place a malicious expression in the expectedValue… | |
| Aplazada | Alta (7.5) | 0.62% | — | Bluewavelabs CheckmateAI | 21/8/2026 | 18/9/2026 | Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. Prior to 3.9.1, the public POST /api/v1/auth/register route in server/src/api/routes/authRoutes.ts passes multipart profileImage uploads through… | |
| Aplazada | Media (6.9) | 0.45% | — | CheckmkAI | 21/8/2026 | 26/8/2026 | Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass mutual TLS client certificate verification of relay endpoints by supplying a fixed placeholder identity in the request URL, resulting in limited impact on integrity and availability. Only the Cloud,… | |
| Aplazada | Media (5.3) | 0.30% | — | Tamara CheckoutAI | 21/8/2026 | 26/8/2026 | The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any capability on its public payment cancel/fail return URLs, changing a WooCommerce order's status based solely on an attacker-supplied numeric order id, so an unauthenticated attacker can cancel or fail arbitrary orders… | |
| Aplazada | Baja (2.3) | 0.35% | — | CheckmkAI | 20/8/2026 | 26/8/2026 | Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allows an authenticated user with restricted host and service visibility to learn the names and the existence of hosts and services they are not authorized to see. | |
| Aplazada | Crítica (9) | 0.54% | 💥 PoC | Broken Link CheckerAI | 19/8/2026 | 26/8/2026 | The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalinks, allowing unauthenticated users to overwrite arbitrary PHP global variables, and to execute arbitrary code on the server when a classic (non-block) is active. | |
| Aplazada | Media (6.3) | 0.26% | — | AcycheckerAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Access Control in Anti Spam and list cleaner – AcyChecker <= 2.0.0 versions. | |
| Aplazada | Media (5.3) | 0.37% | — | Npm-check-updatesAI | 10/8/2026 | 24/9/2026 | npm-check-updates through 23.0.2, fixed in commit b554b84, contains a terminal escape sequence injection vulnerability that allows an attacker to embed arbitrary terminal control characters in a dependency's package.json homepage or repository URL fields. When a developer runs ncu with the --format homepage or… | |
| Aplazada | Media (5.3) | 0.42% | — | Bluewavelabs CheckmateAI | 10/8/2026 | 28/8/2026 | A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to determine whether a given email address is registered. The POST /api/v1/auth/recovery/request endpoint returns HTTP 200 for registered email addresses and a different status code for unregistered… | |
| Aplazada | Alta (8.8) | 0.54% | — | CheckviewAI | 10/8/2026 | 26/8/2026 | The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and unconditionally discards the authentication error raised for any request whose URI merely contains a CheckView WordPress plugin before 2.3.2-specific string, making it possible for unauthenticated… | |
| Pendiente de análisis | Media (5.3) | 0.36% | — | Langchain Langgraph Checkpoint PostgresAILangchain Langgraph Checkpoint SqliteAI | 6/8/2026 | 10/9/2026 | LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoint saver. Prior to 3.1.1, the langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite packages persisted hierarchical namespaces as a dot joined string and scoped reads by matching that string… | |
| Aplazada | Alta (8.2) | 0.33% | — | Bluewavelabs CheckmateAI | 6/8/2026 | 26/8/2026 | The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not properly restrict access to its license-management functionality, relying on a shared secret computed entirely from publicly available information, allowing unauthenticated attackers to deactivate the… | |
| Analizada | Media (4.6) | 0.23% | — | Eclipse Accessibility Tools FrameworkSoumu Michecker | 5/8/2026 | 10/8/2026 | In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. If this vulnerability is exploited, a malicious third party… | |
| Pendiente de análisis | Media (6.7) | 0.36% | 💥 PoC | Langchain Langgraph-checkpoint-mongodbAI | 4/8/2026 | 9/9/2026 | @langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage. Versions 1.3.0 and below are vulnerable to NoSQL injection: checkpoint identifiers (thread_id, checkpoint_ns, checkpoint_id) from config.configurable are passed into MongoDB find() queries in… | |
| Aplazada | Alta (8.5) | 0.17% | — | FirmacheckAIOpensslAI | 3/8/2026 | 24/9/2026 | FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafted openssl.cnf file in the unvalidated C:\Program Files (x86)\Common Files\SSL\ directory path. Attackers can write a malicious OpenSSL configuration file referencing an… | |
| Aplazada | Media (6.4) | 0.16% | — | Jiransoft Appcheck PROAI | 3/8/2026 | 12/8/2026 | A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. Affected is an unknown function in the library AppCheckD.sys of the component Kernel Mini-Filter Driver. Performing a manipulation results in uncontrolled search path. The attack requires a local approach. The complexity of an attack is rather… | |
| Pendiente de análisis | Crítica (9.3) | 0.89% | 💥 PoC | Checkpoint Security Management ServerAICheckpoint Multi Domain Security Management ServerAI | 3/8/2026 | 5/8/2026 | An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could… | |
| Aplazada | Media (5.3) | 0.35% | — | CheckmkAI | 31/7/2026 | 3/9/2026 | Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" permission to modify reports owned by other users. | |
| Aplazada | Media (6.5) | 0.40% | — | Check LOG EmailAI | 31/7/2026 | 26/8/2026 | The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them in SQL queries, allowing users with administrator privileges to perform SQL injection attacks. |