Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
102 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.51% | — | Pocketmine-mpAI | 7/9/2026 | 9/9/2026 | PocketMine-MP before 4.0.7 contains an unhandled exception vulnerability in the ModalFormResponsePacket handler when processing malformed JSON from clients. Attackers can send specially crafted form response packets with invalid JSON to trigger an uncaught InvalidArgumentException, causing server crashes. | |
| Aplazada | Alta (7.1) | 0.51% | — | Pocketmine-mpAI | 7/9/2026 | 14/9/2026 | PocketMine-MP versions before 4.2.3 fail to validate damage metadata values in tool and armor item NBT data received from clients. Attackers can send negative or out-of-range damage values in itemstack NBT to trigger unhandled exceptions in the Durable class, causing server crashes. | |
| Aplazada | Alta (7.1) | 0.51% | — | Pocketmine-mpAI | 7/9/2026 | 8/9/2026 | PocketMine-MP versions before 4.2.9 fail to properly validate NBT data types during deserialization of inventory transaction packets from clients. Attackers can send crafted inventory transactions with malformed NBT tags to trigger server crashes and cause denial of service. | |
| Aplazada | Media (5.3) | 0.43% | — | Pocketmine-mpAI | 7/9/2026 | 10/9/2026 | PocketMine-MP before 4.2.10 fails to validate the total length of incoming chat message blobs before splitting them by newline characters, allowing attackers to send large messages containing many newlines. Malicious clients can send megabyte-sized chat packets and bombard the server with thousands of such messages,… | |
| Aplazada | Alta (7.1) | 0.51% | — | Pocketmine-mpAI | 7/9/2026 | 8/9/2026 | PocketMine-MP versions before 4.4.2 fail to properly validate item IDs received from clients in itemstack NBT data. Attackers can send crafted item IDs outside the valid range to trigger an uncaught exception that crashes the server. | |
| Aplazada | Alta (8.7) | 0.34% | — | Pocketmine-mpAIAdhocore Json-commentAI | 6/9/2026 | 10/9/2026 | PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin packets with invalid geometry JSON to trigger an unhandled RuntimeException, causing server crash. | |
| Aplazada | Media (6.9) | 0.29% | — | Pocketmine-mpAI | 6/9/2026 | 8/9/2026 | PocketMine-MP before 4.12.3 fails to limit unauthenticated sessions, allowing attackers to exhaust player slots by creating sessions without sending LoginPacket. Attackers can flood the server with unauthenticated connections that occupy max-player slots, preventing legitimate players from joining. | |
| Aplazada | Alta (7.1) | 0.29% | — | Pocketmine-mpAI | 6/9/2026 | 9/9/2026 | PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields. Malicious clients can send crafted movement packets with invalid floating-point values to crash servers through unhandled mathematical operations or prevent clients from rendering other players. | |
| Aplazada | Alta (7.1) | 0.29% | — | Pocketmine-mpAI | 6/9/2026 | 8/9/2026 | PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send specially crafted InventoryTransactionPackets with multiple conflicting pathways to cause exponential processing complexity, freezing the server. | |
| Aplazada | Media (4.8) | 0.11% | — | Pocketmine-mpAI | 6/9/2026 | 18/9/2026 | PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt. The removeOp function lowercases the supplied name but only removes an exactly matching entry, so an operator name stored with non-lowercase letters cannot be revoked using the deop command, leaving the… | |
| Aplazada | Media (4.3) | 0.37% | — | Pocket-id Pocket IDAI | 28/8/2026 | 9/9/2026 | Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services. From 2.6.0 until 2.9.0, frontend/src/routes/authorize/+page.ts reads the redirect_uri query parameter and frontend/src/routes/authorize/+page.svelte uses the raw callbackURL in redirectWithError when prompt=none cannot… | |
| Aplazada | Crítica (9.2) | 0.44% | 💥 PoC | PocketAI | 28/8/2026 | 9/9/2026 | Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM. JavaScript code can alter the application state via native bridge methods. | |
| Aplazada | Media (6.8) | 0.35% | — | The-pocket PocketflowAI | 5/8/2026 | 28/8/2026 | The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a helper as a thin os.path.join(workdir, p) wrapper with no canonicalization or containment check, used unguarded by the ReadFile, ListFiles, PatchRead, and PatchApply file-access tools. Severity reflects that this affects an illustrative… | |
| Analizada | Media (6.1) | 0.32% | 💥 PoC | Pocketbase | 12/5/2026 | 17/6/2026 | Pocketbase is an open source web backend written in go. Prior to 0.22.42 and 0.37.4, in some situations, if an attacker knows the email address of the victim they can create and link an unverified PocketBase user in advance by authenticating with one of the OAuth2 app providers, e.g. "A". When the victim gets invited… | |
| Analizada | Alta (8.5) | 0.36% | — | Pocket-id Pocket ID | 12/5/2026 | 17/6/2026 | Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.6.0, The createTokenFromRefreshToken function (oidc_service.go) validates the refresh token's cryptographic integrity but does not re-validate the user's current authorization state before issuing new… | |
| Aplazada | Baja (1.9) | 0.16% | — | Thakeen Nathees PocketlangAI | 12/3/2026 | 17/6/2026 | A vulnerability was found in ThakeeNathees pocketlang up to cc73ca61b113d48ee130d837a7a8b145e41de5ce. The affected element is the function pkByteBufferAddString. The manipulation of the argument length with the input 4294967290 results in memory corruption. The attack requires a local approach. The exploit has been… | |
| Analizada | Alta (7.1) | 0.31% | — | Pocket-id Pocket ID | 10/3/2026 | 17/6/2026 | Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.4.0, the OIDC token endpoint rejects an authorization code only when both the client ID is wrong and the code is expired. This allows cross-client code exchange and expired code reuse. This vulnerability is… | |
| Analizada | Media (6.1) | 0.29% | — | Pocket-id Pocket ID | 10/3/2026 | 17/6/2026 | Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. From 2.0.0 to before 2.4.0, a flaw in callback URL validation allowed crafted redirect_uri values containing URL userinfo (@) to bypass legitimate callback pattern checks. If an attacker can trick a user into opening… | |
| Aplazada | Media (6.5) | 0.19% | — | Solax Power PocketAISolax CloudAI | 12/2/2026 | 17/6/2026 | When connecting to the Solax Cloud MQTT server the username is the "registration number", which is the 10 character string printed on the SolaX Power Pocket device / the QR code on the device. The password is derived from the "registration number" using a proprietary XOR/transposition algorithm. Attackers with the… | |
| Modificada | Alta (7.8) | 0.11% | 💥 PoC | Shirt-pocket Superduper! | 29/1/2026 | 5/7/2026 | An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary package that can run shell scripts with root privileges and Full Disk Access, thus bypassing macOS privacy controls. | |
| Aplazada | Alta (7.1) | 0.40% | — | Pocketmine-mpAI | 31/12/2025 | 15/7/2026 | PocketMine-MP versions prior to 4.18.1 contain an improper input validation vulnerability in inventory transaction handling. A remote attacker with a valid player session can request that the server drop more items than are available in the player's hotbar, triggering a server crash and resulting in denial of service. | |
| Modificada | Alta (7.8) | 0.13% | 💥 PoC | Shirt-pocket Superduper! | 1/12/2025 | 5/7/2026 | An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to execute an arbitrary preflight script with root privileges and Full Disk Access, thus bypassing macOS privacy controls. | |
| Modificada | Alta (7.8) | 0.11% | 💥 PoC | Shirt-pocket Superduper! | 1/12/2025 | 5/7/2026 | An issue in Shirt Pocket SuperDuper! V.3.10 and before allows a local attacker to execute arbitrary code via the software update mechanism | |
| Modificada | Alta (8.1) | 0.30% | 💥 PoC | Shirt-pocket Superduper! | 1/12/2025 | 5/7/2026 | Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows attackers to escalate privileges to root due to the improper use of a setuid binary. | |
| Analizada | Crítica (9.8) | 1.2% | — | Magdesign Pocketvj Control Panel Firmware | 5/11/2025 | 17/6/2026 | PocketVJ CP PocketVJ-CP-v3 pvj version 3.9.1 contains an unauthenticated remote code execution vulnerability in the submit_opacity.php component. The application fails to sanitize user input in the opacityValue POST parameter before passing it to a shell command, allowing remote attackers to execute arbitrary commands… |