Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.42% | — | NeotomaAI | 29/5/2026 | 21/7/2026 | Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public reverse-proxied requests as local when the app receives them over a loopback socket and no Bearer token is present. In affected deployments, the REST auth middleware can resolve unauthenticated… | |
| Aplazada | Baja (2.2) | 0.12% | — | GrapheneosAI | 9/5/2026 | 24/7/2026 | GrapheneOS before 2026050400 allows attackers to discover the real IP address of a VPN user as a consequence of a registerQuicConnectionClosePayload optimization, because an application can let system_server transmit UDP traffic on its behalf. This occurs when the "Block connections without VPN" and "Always-on VPN"… | |
| Analizada | Media (5.5) | 0.20% | — | NeovimVIM | 8/5/2026 | 24/7/2026 | Vim is an open source, command line text editor. Prior to version 9.2.0450, a heap buffer overflow exists in read_compound() in src/spellfile.c when loading a crafted spell file (.spl) with UTF-8 encoding active. An attacker-controlled length field in the spell file's compound section overflows a 32-bit signed integer… | |
| Aplazada | Baja (2.3) | 0.39% | — | Mcp-neo4j-cypherAINeo4jAINeo4j ApocAI | 17/4/2026 | 17/6/2026 | mcp-neo4j-cypher is an MCP server for executing Cypher queries against Neo4j databases. In versions prior to 0.6.0, the read_only mode enforcement can be bypassed using APOC CALL procedures, potentially allowing unauthorized write operations or server-side request forgery. This issue is fixed in version 0.6.0. | |
| Aplazada | Media (4.1) | 0.23% | — | Parisneo LollmsAI | 8/4/2026 | 25/7/2026 | An insufficient session expiration vulnerability exists in the latest version of parisneo/lollms. The application fails to invalidate active sessions after a password reset, allowing an attacker to continue using an old session token. This issue arises due to the absence of logic to reject requests after a period of… | |
| Analizada | Crítica (9.8) | 0.86% | — | Neo.maru | 31/3/2026 | 24/7/2026 | An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure. | |
| Aplazada | Alta (8.1) | 0.50% | — | Elated-themes NeobeatAI | 25/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes NeoBeat neobeat allows PHP Local File Inclusion.This issue affects NeoBeat: from n/a through <= 1.2. | |
| Aplazada | Baja (2.3) | 0.41% | — | Omnipemf NeorhythmAI | 21/3/2026 | 16/9/2026 | A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the component BLE Interface. Such manipulation leads to missing authentication. The attack can only be initiated within the local network. This attack is characterized by high complexity. The… | |
| Aplazada | Media (4.3) | 0.19% | — | Neos Connector FOR FakturamaAI | 21/3/2026 | 17/6/2026 | The Neos Connector for Fakturama plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.0.14. This is due to missing nonce validation in the ncff_add_plugin_page() function which handles settings updates. This makes it possible for unauthenticated attackers to modify… | |
| Analizada | Baja (2.1) | 0.32% | — | Neo4j | 11/3/2026 | 28/8/2026 | An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following conditions: If a neo4j admin configures two or more OIDC providers AND configures one or more of them to be an authorization provider AND configures one or more of them to… | |
| Analizada | Baja (2.1) | 0.24% | — | Neo4j | 11/3/2026 | 17/6/2026 | Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticated users inheriting the context of the first user who authenticated after restart. The issue is limited to certain non-default configurations of SSO (UserInfo endpoint). We recommend upgrading to… | |
| Analizada | Baja (2) | 0.24% | — | Neo4j | 11/3/2026 | 28/8/2026 | Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22 can lead to the following scenario: an admin that intends to give a user an access to a remote database constituent "namespace.name" will inadvertently grant access to any local database or remote… | |
| Analizada | Media (6.6) | 0.22% | — | NeovimVIM | 6/2/2026 | 17/6/2026 | Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'helpfile' option. The vulnerability is located in the get_tagfname() function in src/tag.c. When processing help file tags, Vim copies the… | |
| Analizada | Baja (1.1) | 0.25% | 💥 PoC | Neo4j | 6/2/2026 | 28/8/2026 | Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML. There is no security impact on Neo4j products, but this advisory is released as a precaution to treat the logs as plain… | |
| Aplazada | Media (4.8) | 0.16% | — | Neo4j EnterpriseAINeo4j CommunityAI | 4/2/2026 | 17/6/2026 | Neo4j Enterprise and Community editions versions prior to 2026.01.3 and 5.26.21 are vulnerable to a potential information disclosure by a user who has ability to access the local log files. The "obfuscate_literals" option in the query logs does not redact error information, exposing unredacted data in the query log… | |
| Aplazada | Crítica (9.6) | 0.90% | — | Parisneo Lollms-webuiAI | 2/2/2026 | 17/6/2026 | A Local File Inclusion (LFI) vulnerability exists in the '/reinstall_extension' endpoint of the parisneo/lollms-webui application, specifically within the `name` parameter of the `@router.post("/reinstall_extension")` route. This vulnerability allows attackers to inject a malicious `name` parameter, leading to the… | |
| Aplazada | Alta (8.2) | 0.59% | — | Parisneo LollmsAI | 2/2/2026 | 17/6/2026 | A vulnerability in the `lollms_generation_events.py` component of parisneo/lollms version 5.9.0 allows unauthenticated access to sensitive Socket.IO events. The `add_events` function registers event handlers such as `generate_text`, `cancel_generation`, `generate_msg`, and `generate_msg_from` without implementing… | |
| Aplazada | Alta (7.6) | 0.35% | — | Saeros1984 NeoforumAI | 23/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in saeros1984 Neoforum neoforum allows Blind SQL Injection.This issue affects Neoforum: from n/a through <= 1.0. | |
| Aplazada | Alta (7.1) | 0.17% | — | Saeros1984 NeoforumAI | 23/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in saeros1984 Neoforum neoforum allows Reflected XSS.This issue affects Neoforum: from n/a through <= 1.0. | |
| Aplazada | Baja (1.3) | 0.40% | — | Neo4j Enterprise EditionAI | 22/1/2026 | 17/6/2026 | Neo4j Enterprise edition versions prior to 2025.11.2 and 5.26.17 are vulnerable to a potential information disclosure by an attacker who has some legitimate access to the database. The vulnerability allows attacker without read access to a property to infer information about its value by trying to enumerate all… | |
| Analizada | Media (6.3) | 0.36% | — | Neoteroi Blacksheep | 14/1/2026 | 17/6/2026 | BlackSheep is an asynchronous web framework to build event based web applications with Python. Prior to 2.4.6, the HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new header) or even create… | |
| Analizada | Alta (7.9) | 0.17% | — | ARM C1-ultra FirmwareARM C1-premium FirmwareARM Cortex-a710 FirmwareARM Cortex-x2 Firmware+7 | 14/1/2026 | 17/6/2026 | In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to the PE, either by the same PE or another PE in the shareability domain. In this case, the PE may retain stale TLB entries which should have been invalidated by the TLBI. | |
| Aplazada | Alta (8.1) | 0.48% | — | Elated-themes NEO OcularAI | 8/1/2026 | 7/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Neo Ocular neoocular allows PHP Local File Inclusion.This issue affects Neo Ocular: from n/a through < 1.2. | |
| Aplazada | Media (6.4) | 0.21% | — | Neofix Simple Downloads ListAI | 8/11/2025 | 17/6/2026 | The Simple Downloads List plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_neofix_sdl_edit' AJAX endpoint along with many others in all versions up to, and including, 1.4.3. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.3) | 0.32% | — | Neo4jAI | 31/10/2025 | 17/6/2026 | Potential information leak in bolt protocol handshake in Neo4j Enterprise and Community editions allows attacker to obtain one byte of information from previous connections. The attacker has no control over the information leaked in server responses. |