Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
–

23.688 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.21%—Openclaw MsteamsAIOpenclaw FeishuAIOpenclaw MatrixAIOpenclaw GooglechatAI26/9/202628/9/2026
OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) before 2026.8.1 do not enforce the configured channel read allowlist for caller-supplied explicit read targets in message, reaction, pin, member, and related metadata read actions. A lower-trust sender or a…
Pendiente de análisisMedia (6.9)0.27%💥 PoCMediawiki CargoAI25/9/202629/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.
Pendiente de análisisMedia (6.9)0.27%💥 PoCMediawiki CargoAI25/9/202629/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.
Pendiente de análisisMedia (6.9)0.27%💥 PoCMediawiki CargoAI25/9/202629/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.
Pendiente de análisisMedia (6.9)0.27%💥 PoCCargoAI25/9/202629/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Stored XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.
Pendiente de análisisAlta (8.8)0.36%—Golang PlaygroundAI25/9/202629/9/2026
A malicious txtar could escape the intended execution context and force arbitrary writes to the playground host's trusted filesystem. Disjointly, one of the three possible paths to invoke go vet on the playground host did not correctly restrict the execution environment. This permitted a Go process to make a read for…
Pendiente de análisisBaja (2.3)0.20%💥 PoCCargoAI25/9/202629/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in the Mediawiki - Cargo extension allows Stored XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.
AplazadaCrítica (9.1)0.30%—PiwigoAI25/9/202629/9/2026
Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earlier, when rating is enabled, an unauthenticated guest can call pwg.images.filteredSearch.create with a crafted ratings[] value and then open the returned search URL. include/ws_functions/pwg.images.php stores the…
AplazadaAlta (8.1)1.3%—PiwigoAI25/9/202625/9/2026
Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, check_upgrade_access_rights() in admin/include/functions_upgrade.php conditionally escapes the submitted username only when the removed get_magic_quotes_gpc function exists, so PHP 8 and later concatenate an unauthenticated…
AplazadaAlta (7.2)0.92%—PiwigoAI25/9/202625/9/2026
Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/element_set_ranks.php stores administrator-controlled image_order[] values without enforcing the existing sort-field whitelist. The stored album image_order expression is later concatenated into ORDER BY clauses by…
AplazadaAlta (7.2)0.37%—PiwigoAI25/9/202628/9/2026
Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/batch_manager.php accepts administrator-controlled dimension width, height, and ratio values and filesize values from the Batch Manager filter URL without numeric validation. The URL filter parser stores those values in…
AplazadaCrítica (9.1)0.53%💥 PoCPiwigoAI25/9/202628/9/2026
Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/themes_standard_pages.php validates uploaded logo content by MIME type but reuses the attacker-controlled extension from std_pgs_logo when constructing the stored filename. An authenticated administrator can upload…
Pendiente de análisisAlta (8.8)0.10%—Google GvisorAI25/9/202625/9/2026
Improper Exposure of Resource to Wrong Sphere in the host file helper (gofer) in Google gVisor prior to commit 573a9e73cf844f on Linux platforms with CUSE enabled allows a local attacker with container image deployment privileges to achieve root code execution on the host system. By including a /dev/cuse character…
AplazadaAlta (7.2)1.2%—PiwigoAI25/9/202625/9/2026
Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote code execution in image upload handling when using the Imagick library due to insufficient validation and unsafe processing of user-supplied image files. By abusing format confusion (e.g., disguising SVG content as PNG), an attacker can trigger…
AplazadaBaja (3.7)0.23%—Django-allauthAI25/9/202630/9/2026
django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of diacritics (e.g., accents) for a higher effective limit.
Pendiente de análisisAlta (7.5)0.13%—Mongodb PymongoAI24/9/202626/9/2026
An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusually large amount of caller-supplied data. Size arithmetic is performed in a signed 32-bit type, and the guard meant to catch the overflow is…
Pendiente de análisisAlta (8.3)0.26%—Mongodb PymongoAI24/9/202624/9/2026
PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an application places a hostname value supplied by an unauthenticated party into a connection string, that party may cause additional servers of their choosing to be…
Pendiente de análisisMedia (5.3)0.13%—Mongodb Python DriverAI24/9/202624/9/2026
The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix domain socket path rather than a remote host. A user with write access to the encryption key metadata stored in the database can cause an application using the driver…
AplazadaAlta (7.5)0.64%—Goauthentik AuthentikAI24/9/202629/9/2026
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an unauthenticated attacker can submit a malformed SAML message to an authentik deployment using SAML in either the identity-provider or SAML source role. The message can stop the worker handling /application/saml/* or…
AplazadaAlta (7.4)0.27%—Goauthentik AuthentikAI24/9/202624/9/2026
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an authentik SAML Source verifies an assertion's signature and validity period but does not ensure that the identity provider issued the assertion for that Source or in response to a login request from that Source. The SAML…
AplazadaAlta (8.1)0.33%—Goauthentik AuthentikAI24/9/202624/9/2026
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik API serializers return stored credentials when an account has view permission on an affected configuration, even when that account is not authorized to change the configuration or read its secrets. Affected…
AplazadaAlta (8.8)0.51%💥 PoCGoauthentik AuthentikAI24/9/202628/9/2026
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with delegated permission to manage a group, group membership, or a user can grant superuser status to an account or assign an existing role to a group without holding the permissions that gate those privileges. Group…
AplazadaAlta (8.9)0.49%—Goauthentik AuthentikAI24/9/20265/10/2026
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik email authenticator enrollment during an authentication or enrollment flow accepts a recipient address supplied in the setup request instead of using the address already established by the flow. An actor who knows a…
Pendiente de análisisAlta (7.3)0.19%—Mongodb CompassAI24/9/202625/9/2026
MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that database's view. A user with privileges to create databases on a server that a Compass user connects to may, under specific conditions, have content evaluated as…
Pendiente de análisisAlta (8.3)0.37%—Mongodb C DriverAI24/9/202624/9/2026
An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond the end of a heap buffer. This may cause the application using the driver to terminate…