Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.52% | — | Elixir-mint MintAI | 2/6/2026 | 22/7/2026 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attacker-controlled HTTP/2 servers to exhaust memory in a Mint client (HTTP/2 CONTINUATION flood). When Mint's HTTP/2 receive path observes a HEADERS frame without the END_HEADERS flag, the unparsed header-block fragment is… | |
| Aplazada | Media (6.3) | 0.52% | — | Elixir MintAI | 2/6/2026 | 22/7/2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint Mint allows attacker-controlled HTTP/1 servers to desynchronise response framing on shared connections. Mint's HTTP/1 Content-Length parser, Mint.HTTP1.Parse.content_length_header/1 in lib/mint/http1/parse.ex,… | |
| Aplazada | Alta (8.2) | 0.52% | — | Elixir-mint MintAI | 2/6/2026 | 22/7/2026 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attacker-controlled HTTP/2 servers to exhaust memory in a Mint client via PUSH_PROMISE flooding. In lib/mint/http2.ex, Mint.HTTP2.decode_push_promise_headers_and_add_response/5 inserts a :reserved_remote entry into… | |
| Aplazada | Baja (2.1) | 0.22% | — | Elixir-mint MintAI | 2/6/2026 | 22/7/2026 | Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in elixir-mint Mint allows HTTP Request Splitting and HTTP Request Smuggling. In lib/mint/http1/request.ex, the encode_request_line/2 function splices the caller-supplied method and target arguments directly into the HTTP/1 request line without… | |
| Aplazada | Alta (8.7) | 0.40% | — | Elixir WebrtcAI | 14/5/2026 | 17/6/2026 | Elixir WebRTC is an Elixir implementation of the W3C WebRTC API. Prior to 0.15.1 and 0.16.1, missing DTLS peer certificate fingerprint validation in the DTLS client (active) role removes one side of WebRTC's mutual authentication. The bug is not independently exploitable for media interception in standard deployments,… | |
| Modificada | Alta (7.5) | 0.22% | — | Elixir-ecto Postgrex | 12/5/2026 | 24/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgrex ('Elixir.Postgrex.Notifications' module) allows SQL Injection. The channel argument passed to 'Elixir.Postgrex.Notifications':listen/3 and 'Elixir.Postgrex.Notifications':unlisten/3 is… | |
| Aplazada | Alta (8.7) | 0.64% | — | Mtrudel BanditAIPhoenixframework PhoenixAIEmatia ElixirAI | 1/5/2026 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion. The fragment reassembly path in 'Elixir.Bandit.WebSocket.Connection':handle_frame/3 in lib/bandit/websocket/connection.ex appends every incoming Continuation{fin:… | |
| Analizada | Alta (8.7) | 0.78% | — | Elixir-plug Plug.cowboy | 27/4/2026 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-plug plug_cowboy allows unauthenticated remote denial of service via atom table exhaustion. Plug.Cowboy.Conn.conn/1 in lib/plug/cowboy/conn.ex calls String.to_atom/1 on the value returned by :cowboy_req.scheme/1. For HTTP/2 connections,… | |
| Pendiente de análisis | Alta (7.1) | 0.45% | — | Elixir-nodejsAI | 27/3/2026 | 17/6/2026 | elixir-nodejs provides an Elixir API for calling Node.js functions. A vulnerability in versions prior to 3.1.4 results in Cross-User Data Leakage or Information Disclosure due to a race condition in the worker protocol. The lack of request-response correlation creates a "stale response" vulnerability. Because the… | |
| Aplazada | Alta (7.5) | 0.48% | — | SysmonelixirAI | 24/6/2025 | 17/6/2026 | SysmonElixir is a system monitor HTTP service in Elixir. Prior to version 1.0.1, the /read endpoint reads any file from the server's /etc/passwd by default. In v1.0.1, a whitelist was added that limits reading to only files under priv/data. This issue has been patched in version 1.0.1. | |
| Modificada | Alta (7.5) | 0.60% | — | Ortussolutions Coldbox Elixir | 6/11/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in Ortus Solutions ColdBox Elixir 3.1.6. This affects an unknown part of the file src/defaultConfig.js of the component ENV Variable Handler. The manipulation leads to information disclosure. Upgrading to version 3.1.7 is able to address this issue. The… | |
| Modificada | Media (6.1) | 0.68% | — | Mind-elixir Project Mind-elixir | 20/2/2023 | 17/6/2026 | Mind-elixir is a free, open source mind map core. Prior to version 0.18.1, mind-elixir is prone to cross-site scripting when handling untrusted menus. This issue is patched in version 0.18.1 | |
| Modificada | Crítica (9.8) | 1.1% | — | Starkbank Elixir Ecdsa | 9/11/2021 | 17/6/2026 | The verify function in the Stark Bank Elixir ECDSA library (ecdsa-elixir) 1.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages. | |
| Modificada | Crítica (9.8) | 2.9% | — | Elixir Alpine Docker Image | 8/12/2020 | 17/6/2026 | The official elixir Docker images before 1.8.0-alpine (Alpine specific) contain a blank password for a root user. Systems using the elixir Linux Docker container deployed by affected versions of the Docker image may allow a remote attacker to achieve root access with a blank password. | |
| Modificada | Crítica (9.8) | 2.9% | — | Alchemist-elixir Alchemist-server | 17/11/2017 | 17/6/2026 | Elixir's vim plugin, alchemist.vim is vulnerable to remote code execution in the bundled alchemist-server. A malicious website can execute requests against an ephemeral port on localhost that are then evaluated as elixir code. | |
| Modificada | Media (4.3) | 1.7% | — | Ematia Elixir | 26/8/2012 | 16/6/2026 | Elixir 0.8.0 uses Blowfish in CFB mode without constructing a unique initialization vector (IV), which makes it easier for context-dependent users to obtain sensitive information and decrypt the database. |