Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 35 respecto a la semana anterior
Críticas / altas1418▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
111 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.66% | — | Fedify/fedifyFedify/vocab-runtime | 6/4/2026 | 17/6/2026 | Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1, @fedify/fedify follows HTTP redirects recursively in its remote document loader and authenticated document loader without enforcing a maximum redirect count or visited-URL loop detection.… | |
| Aplazada | Alta (7.1) | 0.26% | — | Astoundify ListifyAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Astoundify Listify listify allows Reflected XSS.This issue affects Listify: from n/a through <= 3.2.5. | |
| Analizada | Media (5.1) | 0.23% | — | Dify | 3/3/2026 | 17/6/2026 | Dify is an open-source LLM app development platform. Prior to 1.11.2, Dify is vulnerable to a stored XSS issue when rendering Mermaid diagrams within chats. This occurs because Dify’s default Mermaid configuration uses securityLevel: loose, which allows potentially unsafe content to execute. This vulnerability is… | |
| Analizada | Media (5.5) | 0.71% | — | Dify | 27/2/2026 | 17/6/2026 | Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-existent accounts differ, allowing an attacker to enumerate email addresses registered with Dify. Version 1.9.0 fixes the issue. | |
| Analizada | Media (5.3) | 0.36% | — | Dify | 11/2/2026 | 17/6/2026 | Dify is an open-source LLM app development platform. Prior to 1.13.0, a cross site scripting vulnerability has been found in the web application chat frontend when using echarts. User or llm inputs containing echarts containing a specific javascript payload will be executed. This vulnerability is fixed in 1.13.0. | |
| Analizada | Alta (7.5) | 0.53% | — | Fedify Hollo | 9/2/2026 | 17/6/2026 | Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Prior to 0.6.20 and 0.7.2, there is a security vulnerability where DMs and followers-only posts were exposed through the ActivityPub outbox endpoint without authorization. This vulnerability is fixed in 0.6.20 and… | |
| Aplazada | Crítica (9.3) | 0.83% | — | UploadifyAI | 15/1/2026 | 16/6/2026 | Uploadify WordPress plugin versions up to and including 1.0 contain an arbitrary file upload vulnerability in process_upload.php due to missing file type validation. An unauthenticated remote attacker can upload arbitrary files to the affected WordPress site, which may allow remote code execution by uploading… | |
| Aplazada | Alta (7.1) | 0.22% | — | Xtendify WofficeAI | 8/1/2026 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WofficeIO Woffice woffice allows Reflected XSS.This issue affects Woffice: from n/a through <= 5.4.30. | |
| Aplazada | Alta (7.1) | 0.22% | — | Astoundify JobifyAI | 8/1/2026 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Astoundify Jobify jobify allows Reflected XSS.This issue affects Jobify: from n/a through <= 4.3.0. | |
| Analizada | Alta (8.4) | 0.35% | — | Dify | 5/1/2026 | 30/9/2026 | Dify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the frontend, allowing non-administrator users to view and reuse it. This can lead to unauthorized access to third-party services, potentially consuming limited quotas. Version 1.11.0 fixes the issue. | |
| Analizada | Alta (8.4) | 0.89% | — | Connectify Speedify | 23/12/2025 | 17/6/2026 | A command injection vulnerability in the me.connectify.SMJobBlessHelper XPC service of Speedify VPN up to v15.0.0 allows attackers to execute arbitrary commands with root-level privileges. | |
| Analizada | Alta (7.5) | 0.56% | — | Fedify | 22/12/2025 | 28/9/2026 | Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.6.13, 1.7.14, 1.8.15, and 1.9.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Fedify's document loader. The HTML parsing regex at packages/fedify/src/runtime/docloader.ts:259 contains… | |
| Modificada | Crítica (9.8) | 0.86% | — | Langgenius Dify | 18/12/2025 | 5/7/2026 | Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE: the Supplier reports that the Docker configuration does not make PostgreSQL (on TCP port 5432) exposed by default in version 1.0.1 or later. | |
| Modificada | Alta (7.5) | 30% | — | Langgenius Dify | 18/12/2025 | 5/10/2026 | Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-features endpoint without any authentication credentials or session tokens. The endpoint fails to implement proper authorization checks, allowing anonymous access to sensitive… | |
| Modificada | Crítica (9.1) | 0.22% | — | Langgenius Dify | 18/12/2025 | 17/6/2026 | A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoint implements an overly permissive CORS policy that reflects arbitrary Origin headers and sets Access-Control-Allow-Credentials: true, allowing any external domain to make… | |
| Modificada | Crítica (9.1) | 0.24% | — | Langgenius Dify | 18/12/2025 | 17/6/2026 | A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint. The endpoint implements an insecure CORS policy that reflects any Origin header and enables Access-Control-Allow-Credentials: true, permitting arbitrary external domains to make authenticated… | |
| Aplazada | Media (4.3) | 0.13% | — | Astoundify ListifyAI | 16/12/2025 | 5/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Astoundify Listify listify allows Cross Site Request Forgery.This issue affects Listify: from n/a through <= 3.2.5. | |
| Aplazada | Crítica (10) | 0.43% | — | Addify Custom User Registration Fields FOR WoocommerceAI | 6/11/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Addify Custom User Registration Fields for WooCommerce user-registration-plugin-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects Custom User Registration Fields for WooCommerce: from n/a through <= 2.1.2. | |
| Analizada | Media (5.3) | 0.70% | — | Langgenius Dify | 22/10/2025 | 17/6/2026 | In langgenius/dify-web version 1.6.0, the authentication mechanism reveals the existence of user accounts by returning different error messages for non-existent and existing accounts. Specifically, when a login or registration attempt is made with a non-existent username or email, the system responds with a message… | |
| Analizada | Baja (2) | 5.7% | — | Langgenius Dify | 17/10/2025 | 17/6/2026 | Dify is an LLM application development platform. In Dify versions through 1.9.1, the MCP OAuth component is vulnerable to cross-site scripting when a victim connects to an attacker-controlled remote MCP server. The vulnerability exists in the OAuth flow implementation where the authorization_url provided by a remote… | |
| Analizada | Media (5.3) | 0.70% | — | Dify | 30/9/2025 | 17/6/2026 | Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi. A different vulnerability than CVE-2025-29720. | |
| Analizada | Media (6) | 0.25% | — | Langgenius Dify | 25/9/2025 | 17/6/2026 | Dify is an open-source LLM app development platform. In version 1.8.1, a broken access control vulnerability on the /console/api/apps/<APP_ID>chat-messages?conversation_id=<CONVERSATION_ID>&limit=10 endpoint allows users in the same workspace to read chat messages of other users. A regular user is able to read the… | |
| Aplazada | Media (6.4) | 0.24% | — | Astoundify JobifyAI | 11/9/2025 | 30/9/2026 | The Jobify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘keyword’ parameter in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Media (5.9) | 0.23% | — | Astoundify WP Modal Popup With Cookie IntegrationAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Astoundify WP Modal Popup with Cookie Integration wp-modal-popup-with-cookie-integration allows Reflected XSS.This issue affects WP Modal Popup with Cookie Integration: from n/a through <= 2.4. | |
| Aplazada | Alta (8.7) | 0.61% | — | FedifyAI | 9/8/2025 | 17/6/2026 | Fedify is a TypeScript library for building federated server apps powered by ActivityPub. In versions below 1.3.20, 1.4.0-dev.585 through 1.4.12, 1.5.0-dev.636 through 1.5.4, 1.6.0-dev.754 through 1.6.7, 1.7.0-pr.251.885 through 1.7.8 and 1.8.0-dev.909 through 1.8.4, an authentication bypass vulnerability allows any… |