Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
144 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.66% | — | LumiverseAI | 26/5/2026 | 23/7/2026 | Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the Spindle extension build pipeline calls bun install without the --ignore-scripts flag before running the static backend safety scan (assertSafeBackendBundle). A malicious extension that ships a package.json with a preinstall, postinstall, or prepare… | |
| Aplazada | Media (4.8) | 0.18% | — | LumiverseAI | 26/5/2026 | 20/7/2026 | Lumiverse is a full-featured AI chat application. Prior to 0.9.7, consumeNonce() only checks that the module-level variable is set and unexpired. It does not validate any value from the incoming HTTP request or bind the nonce to the admin's session. If the admin's auth.api.signUpEmail() call fails before the before… | |
| Aplazada | Media (6.4) | 0.26% | — | Jegstudio GutenverseAI | 5/5/2026 | 17/6/2026 | The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.5.3 via the import_images() function. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests… | |
| Aplazada | Media (6.4) | 0.26% | — | Jegstudio GutenverseAI | 5/5/2026 | 17/6/2026 | The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'separatorIconSVG' parameter in versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Analizada | Alta (7.7) | 0.51% | — | Quarkiverse Quarkus Openapi Generator | 10/4/2026 | 17/6/2026 | Quarkus OpenAPI Generator is Quarkus' extensions for generation of Rest Clients and server stubs generation. Prior to 2.16.0 and 2.15.0-lts, the unzip() method in ApicurioCodegenWrapper.java extracts ZIP entries without validating that the resolved file path stays within the intended output directory. At line 101, the… | |
| Analizada | Crítica (9.9) | 0.37% | — | Sonicverse Radio Audio Streaming Stack | 9/4/2026 | 17/6/2026 | Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audio Streaming Stack dashboard contains a Server-Side Request Forgery (SSRF) vulnerability in its API client (apps/dashboard/lib/api.ts). Installations created using the provided install.sh script (including the one‑liner… | |
| Aplazada | Media (6.4) | 0.26% | — | Jegstudio GutenverseAI | 4/4/2026 | 24/7/2026 | The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'imageLoad' parameter in versions up to, and including, 3.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Baja (2.1) | 0.26% | — | Microsoft DataverseAI | 1/4/2026 | 17/6/2026 | A vulnerability was detected in Harvard University IQSS Dataverse up to 6.8. This affects an unknown function of the file /ThemeAndWidgets.xhtml of the component Theme Customization. Performing a manipulation of the argument uploadLogo results in unrestricted upload. Remote exploitation of the attack is possible. The… | |
| Aplazada | Alta (8.1) | 0.58% | — | Themerex VerseAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Verse verse allows PHP Local File Inclusion.This issue affects Verse: from n/a through <= 1.7.0. | |
| Aplazada | Media (6.4) | 0.21% | — | Simple Bible Verse VIA ShortcodeAI | 7/2/2026 | 17/6/2026 | The Simple Bible Verse via Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `verse` shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (8.5) | 0.15% | — | Osas Traverse ExtensionAI | 21/1/2026 | 17/6/2026 | OSAS Traverse Extension 11 contains an unquoted service path vulnerability in the TravExtensionHostSvc service running with LocalSystem privileges. Attackers can exploit the unquoted path to inject and execute malicious code by placing executable files in the service's path, potentially gaining elevated system access. | |
| Analizada | Alta (7.9) | 0.17% | — | ARM C1-ultra FirmwareARM C1-premium FirmwareARM Cortex-a710 FirmwareARM Cortex-x2 Firmware+7 | 14/1/2026 | 17/6/2026 | In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to the PE, either by the same PE or another PE in the shareability domain. In this case, the PE may retain stale TLB entries which should have been invalidated by the TLBI. | |
| Aplazada | Media (6.4) | 0.30% | — | Gutenverse FormAI | 8/1/2026 | 30/9/2026 | The Gutenverse Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all versions up to, and including, 2.3.2. This is due to the plugin's framework component adding SVG to the allowed MIME types via the upload_mimes filter without implementing any sanitization of SVG file… | |
| Aplazada | Media (6.5) | 0.26% | — | Jegstudio Gutenverse FormAI | 24/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Jegstudio Gutenverse Form gutenverse-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutenverse Form: from n/a through <= 2.3.1. | |
| Aplazada | Media (6.5) | 0.25% | — | Jegstudio Gutenverse NewsAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Jegstudio Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons gutenverse-news allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons: from n/a through <=… | |
| Aplazada | Media (6.5) | 0.29% | — | Jegstudio Gutenverse FormAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in Jegstudio Gutenverse Form gutenverse-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutenverse Form: from n/a through <= 2.2.0. | |
| Aplazada | Media (6.5) | 0.24% | — | Jegstudio GutenverseAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in Jegstudio Gutenverse gutenverse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutenverse: from n/a through <= 3.2.1. | |
| Analizada | Media (5.3) | 0.30% | — | Reverse Proxy Header Project Reverse Proxy Header | 30/10/2025 | 17/6/2026 | Improper Validation of Consistency within Input vulnerability in Drupal Reverse Proxy Header allows Manipulating User-Controlled Variables.This issue affects Reverse Proxy Header: from 0.0.0 before 1.1.2. | |
| Analizada | Baja (1.9) | 0.28% | — | Ncsoft Universe | 29/8/2025 | 17/6/2026 | A vulnerability was identified in NCSOFT Universe App up to 1.3.0. Impacted is an unknown function of the file AndroidManifest.xml of the component com.ncsoft.universeapp. The manipulation leads to improper export of android application components. Local access is required to approach this attack. The exploit is… | |
| Aplazada | Baja (2.1) | 1.8% | — | AgentuniverseAI | 7/8/2025 | 17/6/2026 | A vulnerability was found in agentUniverse up to 0.0.18 and classified as critical. This issue affects the function StdioServerParameters of the component MCPSessionManager/MCPTool/MCPToolkit. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (6.4) | 0.31% | — | Jegstudio GutenverseAI | 6/8/2025 | 17/6/2026 | The Gutenverse plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Animated Text and Fun Fact blocks in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.5) | 0.13% | — | Nvidia Omniverse LauncherAI | 31/7/2025 | 17/6/2026 | NVIDIA Omniverse Launcher for Windows and Linux contains a vulnerability in the launcher logs, where a user could cause sensitive information to be written to the log files through proxy servers. A successful exploit of this vulnerability might lead to information disclosure. | |
| Analizada | Baja (1.9) | 0.21% | — | Lobbyuniverse Lobby | 28/7/2025 | 17/6/2026 | A vulnerability classified as problematic was found in Lobby Universe Lobby App up to 2.8.0 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.maverick.lobby. The manipulation leads to improper export of android application components. The attack… | |
| Aplazada | Alta (8.8) | 0.60% | — | Dataverse IntegrationAI | 24/7/2025 | 17/6/2026 | The Dataverse Integration plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks within its reset_password_link REST endpoint in versions 2.77 through 2.81. The endpoint’s handler accepts a client-supplied id, email, or login, looks up that user, and calls… | |
| Analizada | Media (5.4) | 0.25% | — | Jegstudio Gutenverse News | 19/6/2025 | 17/6/2026 | The Gutenverse News plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘elementId’ parameter in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… |