Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
115 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.6) | 0.25% | — | Cloudflare QuicheAI | 19/6/2026 | 22/6/2026 | Cloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The “quiche_connection_id_iter_next” and “quiche_conn_retired_scid_next” functions would return a pointer to a “ConnectionId” to the applications via function arguments, but the owned “ConnectionId” would be… | |
| Aplazada | Alta (8.8) | 1.1% | — | Offload AI Optimize With Cloudflare ImagesAI | 18/6/2026 | 18/6/2026 | The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.10.2 via the 'account-id' parameter parameter. This is due to insufficient privilege enforcement on the cf_images_do_setup AJAX handler, which requires only the… | |
| Aplazada | Media (5.3) | 0.36% | — | Simple Cloudflare TurnstileAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in Simple Cloudflare Turnstile <= 1.38.0 versions. | |
| Analizada | Media (6.5) | 0.36% | — | Nvidia Nvflare | 28/4/2026 | 17/6/2026 | NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A successful exploit of this vulnerability may lead to information disclosure. | |
| Analizada | Alta (8.8) | 0.48% | — | Nvidia Nvflare | 28/4/2026 | 17/6/2026 | NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBS- encoded message. A successful exploit of this vulnerability might lead to code execution. | |
| Analizada | Crítica (9.8) | 0.57% | — | Nvidia Nvflare | 28/4/2026 | 17/6/2026 | NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A successful exploit of this vulnerability may lead to privilege escalation, data tampering, information disclosure, code… | |
| Aplazada | Baja (2.2) | 0.32% | — | CloudflareAI | 24/4/2026 | 17/6/2026 | @astrojs/cloudflare is an SSR adapter for use with Cloudflare Workers targets. Prior to 13.1.10, the fetch() call for remote images in packages/integrations/cloudflare/src/utils/image-binding-transform.ts uses the default redirect: 'follow' behavior. This allows the Cloudflare Worker to follow HTTP redirects to… | |
| Analizada | Alta (8.3) | 0.57% | — | Flintsh Flare | 10/3/2026 | 17/6/2026 | Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to 1.7.3, an authenticated path traversal vulnerability in /api/avatars/[filename] allows any logged-in user to read arbitrary files from within the application container. The filename URL parameter is passed to… | |
| Analizada | Alta (7.5) | 0.49% | — | Lyc8503 Uptimeflare | 7/3/2026 | 17/6/2026 | UptimeFlare is a serverless uptime monitoring & status page solution, powered by Cloudflare Workers. Prior to commit 377a596, configuration file uptime.config.ts exports both pageConfig (safe for client use) and workerConfig (server-only, contains sensitive data) from the same module. Due to pages/incidents.tsx… | |
| Analizada | Media (6) | 0.32% | — | Flintsh Flare | 6/3/2026 | 17/6/2026 | Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to version 1.7.2, the raw and direct file routes only block unauthenticated users from accessing private files. Any authenticated, non‑owner user who knows the file URL can retrieve the content, which is… | |
| Analizada | Alta (8.2) | 0.42% | — | Flintsh Flare | 6/3/2026 | 17/6/2026 | Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to version 1.7.2, the thumbnail endpoint does not validate the password for password‑protected files. It checks ownership/admin for private files but skips password verification, allowing thumbnail access without… | |
| Analizada | Alta (8.4) | 0.22% | — | Cloudflare Pingora | 5/3/2026 | 17/6/2026 | A cache poisoning vulnerability has been found in the Pingora HTTP proxy framework’s default cache key construction. The issue occurs because the default HTTP cache key implementation generates cache keys using only the URI path, excluding critical factors such as the host header (authority). Operators relying on the… | |
| Analizada | Crítica (9.3) | 0.58% | — | Cloudflare Pingora | 5/3/2026 | 17/6/2026 | An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding requests. The issue occurs due to improperly allowing HTTP/1.0 request bodies to be close-delimited and incorrect handling of multiple Transfer-Encoding values, allowing attackers to send HTTP/1.0… | |
| Analizada | Crítica (9.3) | 0.52% | — | Cloudflare Pingora | 5/3/2026 | 17/6/2026 | An HTTP request smuggling vulnerability (CWE-444) was found in Pingora's handling of HTTP/1.1 connection upgrades. The issue occurs when a Pingora proxy reads a request containing an Upgrade header, causing the proxy to pass through the rest of the bytes on the connection to a backend before the backend has accepted… | |
| Analizada | Alta (7.7) | 0.44% | — | Opennextjs Opennext FOR Cloudflare | 4/3/2026 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package, resulting from a path normalization bypass in the /cdn-cgi/image/ handler.The @opennextjs/cloudflare worker template includes a /cdn-cgi/image/ handler intended for development use only. In production, Cloudflare's… | |
| Analizada | Baja (2.9) | 0.39% | — | Cloudflare Circl | 24/2/2026 | 17/6/2026 | The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signing relying on this curve are not affected. The bug was fixed in v1.6.3… | |
| Analizada | Media (5.4) | 0.37% | — | Flintsh Flare | 20/2/2026 | 17/6/2026 | Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Versions 1.7.0 and below allow users to upload files without proper content validation or sanitization. By embedding malicious JavaScript within an SVG (or other active content formats such as HTML or XML), an attacker… | |
| Aplazada | Media (6.2) | 0.39% | — | Cloudflare AgentsAI | 13/2/2026 | 17/6/2026 | Summary A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the AI Playground's OAuth callback handler. The `error_description` query parameter was directly interpolated into an HTML script tag without proper escaping, allowing attackers to execute arbitrary JavaScript in the context of the victim's… | |
| Aplazada | Media (6.9) | 0.47% | — | Cloudflare Agents SDKAI | 3/2/2026 | 17/6/2026 | Summary An Insecure Direct Object Reference has been found to exist in `createHeaderBasedEmailResolver()` function within the Cloudflare Agents SDK. The issue occurs because the `Message-ID` and `References` headers are parsed to derive the target agentName and agentId without proper validation or origin checks,… | |
| Analizada | Alta (7.7) | 1.5% | — | Cloudflare Wrangler | 20/1/2026 | 17/6/2026 | SummaryA command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The issue occurs because the `--commit-hash` parameter is passed directly to a shell command without proper validation or sanitization, allowing an attacker with control of `--commit-hash` to execute… | |
| Modificada | Media (6.8) | 0.32% | — | Blurams Dome Flare Firmware | 14/1/2026 | 5/7/2026 | An insecure authentication mechanism in the safe_exec.sh startup script of Blurams Flare Camera version 24.1114.151.929 and earlier allows an attacker with physical access to the device to execute arbitrary commands with root privileges, if file /opt/images/public_key.der is not present in the file system. The… | |
| Modificada | Media (6.1) | 0.21% | — | Blurams Dome Flare Firmware | 14/1/2026 | 5/7/2026 | A vulnerability in the boot process of Blurams Flare Camera version 24.1114.151.929 and earlier allows a physically proximate attacker to hijack the boot mechanism and gain a bootloader shell via the UART interface. This is achieved by inducing a read error from the SPI flash memory during the boot, by shorting a data… | |
| Aplazada | Media (6.5) | 0.25% | — | Anton Vanyukov Offload AI Optimize With Cloudflare ImagesAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Anton Vanyukov Offload, AI & Optimize with Cloudflare Images cf-images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Offload, AI & Optimize with Cloudflare Images: from n/a through <= 1.9.5. | |
| Analizada | Alta (7.1) | 0.16% | — | Cloudflare Gokey | 2/12/2025 | 17/6/2026 | In gokey versions <0.2.0, a flaw in the seed decryption logic resulted in passwords incorrectly being derived solely from the initial vector and the AES-GCM authentication tag of the key seed. This issue has been fixed in gokey version 0.2.0. This is a breaking change. The fix has invalidated any passwords/secrets… | |
| Aplazada | Crítica (9.3) | 0.37% | 💥 PoC | Rekinddns Serverless-dnsAICloudflare WorkersAIDeno DeployAIFastlyAI+1 | 30/9/2025 | 17/6/2026 | serverless-dns is a RethinkDNS resolver that deploys to Cloudflare Workers, Deno Deploy, Fastly, and Fly.io. Versions through abd including 0.1.30 have a vulnerability where the pr.yml GitHub Action interpolates in an unsafe manner untrusted input, specifically the github.event.pull_request.head.repo.clone_url and… |