Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
171 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.55% | — | NanomodbusAI | 5/8/2026 | 26/8/2026 | nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record function (FC 0x14, Read File Record) in nanomodbus.c. The function validates that the total request size does not exceed 245 bytes and that each sub-request's record_length is at most 124, but it never… | |
| Analizada | Alta (8.2) | 0.59% | — | Nanoid Project Nanoid | 29/7/2026 | 18/8/2026 | nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satisfies its exit condition and spins indefinitely, hanging the calling thread. An application that passes an unvalidated,… | |
| Analizada | Alta (8.2) | 0.33% | — | Nanoid Project Nanoid | 29/7/2026 | 30/9/2026 | nanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the loop counter is decremented from a negative value and never reaches its termination condition, spinning… | |
| Aplazada | Baja (2.1) | 0.37% | — | Nanoco NanoclawAI | 26/7/2026 | 27/7/2026 | A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been published and may be… | |
| Aplazada | Baja (1.9) | 0.15% | — | Nanoco NanoclawAI | 26/7/2026 | 27/7/2026 | A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MCP Server Approval. Performing a manipulation results in improper authorization. The attack needs to be approached locally. The exploit is… | |
| Pendiente de análisis | Media (6.8) | 0.15% | — | GNU NanoAI | 23/7/2026 | 1/9/2026 | A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow an attacker to achieve stack… | |
| Aplazada | Media (6.5) | 0.41% | — | Emqx NanomqAI | 20/7/2026 | 23/7/2026 | In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `properties_parse()` allows an authenticated attacker to crash the NanoMQ broker by sending a POST request to `/api/v4/mqtt/publish` with `user_properties` as a JSON array instead of a JSON object. The crash occurs because `strlen()` is called on a… | |
| Aplazada | Baja (2.6) | 0.27% | — | Emqx NanomqAI | 20/7/2026 | 23/7/2026 | In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `nni_mqttv5_msg_decode_connect()` allows a malicious MQTT broker to crash any connecting NanoMQ MQTTv5 client (including bridge mode) with a single packet, causing remote denial of service via SIGSEGV. In `nni_mqttv5_msg_decode_connect()`… | |
| Aplazada | Media (6.5) | 0.32% | — | Emqx NanomqAI | 20/7/2026 | 23/7/2026 | NanoMQ contains a protocol-semantics flaw in its MQTT v5 `SUBSCRIBE` handling: if a subscription entry is missing the final 1-byte `Subscription Options` field, the broker may still accept the malformed packet and install the subscription into internal broker state. Under a specific packet-length construction, the… | |
| Analizada | Alta (7.5) | 0.59% | 💥 PoC | Emqx Nanomq | 15/7/2026 | 16/7/2026 | An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in broker_tcp.c component | |
| Aplazada | Crítica (9.8) | 0.39% | — | Perl DBIAIPerl DBI SQL NanoAI | 14/7/2026 | 14/7/2026 | DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_matched method, <= was evaluated using Perl's ge operator, and >= was… | |
| Aplazada | Alta (7.1) | 0.25% | — | NanomagAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Scripting (XSS) in NanoMag <= 1.8 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | Nanoco NanoclawAI | 23/6/2026 | 17/9/2026 | NanoClaw before 2.1.0 contains a privilege escalation vulnerability in the channel-registration approval flow where handleChannelApprovalResponse fails to validate admin privileges over target agent groups. Scoped admins can submit forged or stale connect callback values to wire messaging channels into out-of-scope… | |
| Aplazada | Media (6.8) | 0.17% | — | Nanoco NanoclawAI | 23/6/2026 | 17/9/2026 | NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the create_agent delivery-action handler that performs privileged central-database writes without host-side authorization checks. Confined agent containers can invoke create_agent to create arbitrary agent groups, container configurations, and… | |
| Aplazada | Media (6.8) | 0.17% | — | Nanoco NanoclawAI | 23/6/2026 | 17/9/2026 | NanoClaw before 2.1.17 contains a symlink following vulnerability in forwardAttachedFiles that allows container-controlled agents to exfiltrate host-readable files. The host validates attachment filenames using only isSafeAttachmentName before copying with fs.copyFileSync, which follows symlinks without containment… | |
| Aplazada | Alta (7.1) | 0.38% | — | Nanoco NanoclawAI | 23/6/2026 | 17/9/2026 | NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails to verify responder role authorization. Attackers with a valid questionId can approve or reject privileged actions like package installation by submitting approval response payloads without proper… | |
| Aplazada | Alta (8.7) | 0.42% | — | NanobotAI | 18/6/2026 | 23/6/2026 | nanobot is a personal AI assistant. In versions 0.1.5.post3 and prior, the WhatsApp bridge in bridge/src/whatsapp.ts constructs a filesystem path using the fileName field from an incoming WhatsApp document message without sanitization. The WhatsApp bridge downloads media attachments and writes them to disk using a… | |
| Aplazada | Alta (7.8) | 0.86% | — | Nanomodus NanomodbbusAI | 14/6/2026 | 10/8/2026 | nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header function of the Modbus/TCP server that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of the 260-byte receive buffer by sending a crafted MBAP frame whose Length field is set to 255. | |
| Aplazada | Media (5.5) | 0.20% | — | WP Nano ADAI | 2/6/2026 | 22/7/2026 | The WP Nano AD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blogrole_link’ parameter in all versions up to, and including, 1.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject… | |
| Aplazada | Media (5.3) | 0.47% | — | NanobotAI | 1/6/2026 | 22/7/2026 | Nanobot prior to version 0.2.1 contains a denial of service vulnerability in the Matrix channel media download handler that allows authenticated room members to exhaust process memory and bandwidth by sending media events with missing or invalid size metadata. Attackers can send multiple concurrent Matrix media events… | |
| Aplazada | Alta (7) | 0.66% | — | NanobotAIMicrosoft TeamsAIMicrosoft BOT FrameworkAI | 1/6/2026 | 22/7/2026 | Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handler that allows remote attackers to exfiltrate Bot Framework bearer tokens by supplying a forged activity with an attacker-controlled serviceUrl value. Attackers can poison the stored conversation… | |
| Aplazada | Media (5.3) | 0.49% | — | NanobotAI | 1/6/2026 | 22/7/2026 | Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the web_fetch tool that allows remote attackers to reach internal or private network hosts by supplying a URL that redirects to a loopback or private address via a 3xx Location header. Attackers can exploit the automatic HTTP… | |
| Aplazada | Baja (2.9) | 0.33% | — | Emqx NanomqAI | 29/5/2026 | 22/7/2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In 0.24.8 and earlier, quic_stream_recv can dereference a null substream pointer when a substream is in reopen state. The code finishes the AIO with error but does not return before locking c->mtx. | |
| Aplazada | Media (4.5) | 0.13% | — | Emqx NanomqAI | 29/5/2026 | 22/7/2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to 0.24.14, aio->prov_data is stored as nni_quic_conn* during dialing, but read as ex_quic_conn* during dialer close. This type confusion causes invalid object interpretation and leads to close-path hang/crash behavior. This vulnerability is… | |
| Aplazada | Media (5.4) | 0.29% | — | Linethemes NanocareAI | 25/5/2026 | 24/7/2026 | Missing Authorization vulnerability in Linethemes NanoCare allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects NanoCare: from n/a before 1.2.2. |