Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
3322 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.7) | 0.98% | — | Amazon Research AND Engineering Studio | 6/4/2026 | 24/7/2026 | Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands on the cluster-manager EC2 instance via crafted input when using the FileBrowser functionality. To remediate this issue, users… | |
| Analizada | Alta (8.7) | 0.74% | — | Amazon Research AND Engineering Studio | 6/4/2026 | 24/7/2026 | Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 2026.03 could allow an authenticated remote user to escalate privileges, assume the virtual desktop host instance profile permissions, and interact with AWS resources and… | |
| Analizada | Alta (8.7) | 0.98% | — | Amazon Research AND Engineering Studio | 6/4/2026 | 24/7/2026 | Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as root on the virtual desktop host via a crafted session name. To remediate this issue,… | |
| Aplazada | Media (5.5) | 0.47% | — | Assafelovic Gpt-researcherAI | 6/4/2026 | 24/7/2026 | A vulnerability was determined in assafelovic gpt-researcher up to 3.4.3. Affected is an unknown function of the component ws Endpoint. Executing a manipulation of the argument source_urls can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been publicly disclosed and… | |
| Aplazada | Media (5.5) | 0.65% | — | Assafelovic Gpt-researcherAI | 6/4/2026 | 24/7/2026 | A vulnerability was found in assafelovic gpt-researcher up to 3.4.3. This impacts an unknown function of the component HTTP REST API Endpoint. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The project was… | |
| Aplazada | Media (5.5) | 0.52% | — | Assafelovic Gpt-researcherAI | 6/4/2026 | 24/7/2026 | A vulnerability has been found in assafelovic gpt-researcher up to 3.4.3. This affects the function extract_command_data of the file backend/server/server_utils.py of the component ws Endpoint. Such manipulation of the argument args leads to code injection. The attack may be performed from remote. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.45% | — | Assafelovic Gpt-researcherAI | 6/4/2026 | 24/7/2026 | A flaw has been found in assafelovic gpt-researcher up to 3.4.3. The impacted element is an unknown function of the file backend/server/app.py of the component Report API. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used.… | |
| Aplazada | Baja (2.1) | 0.45% | — | Assafelovic GPT ResearcherAI | 6/4/2026 | 24/7/2026 | A weakness has been identified in assafelovic gpt-researcher up to 3.4.3. This issue affects some unknown processing of the file gpt_researcher/skills/researcher.py of the component WebSocket Interface. Executing a manipulation of the argument task can lead to cross site scripting. The attack may be launched remotely.… | |
| Analizada | Alta (8.8) | 0.53% | — | Arcasolutions Edirectory | 5/4/2026 | 24/7/2026 | eDirectory contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to bypass administrator authentication and disclose sensitive files by injecting SQL code into parameters. Attackers can exploit the key parameter in the login endpoint with union-based SQL injection to authenticate as… | |
| Analizada | Media (5.1) | 0.25% | — | Mybb MY Arcade | 4/4/2026 | 21/7/2026 | MyBB My Arcade Plugin 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through arcade game score comments. Attackers can add crafted HTML and JavaScript payloads in the comment field that execute when other users view or edit the comment. | |
| Aplazada | Media (6.9) | 0.16% | — | ECO SearchAI | 4/4/2026 | 21/7/2026 | Eco Search 1.0.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string to the search functionality. Attackers can paste a buffer of 950 or more characters into the search bar and trigger a crash by initiating a search operation. | |
| Aplazada | Media (6.9) | 0.17% | — | ONE SearchAI | 4/4/2026 | 21/7/2026 | One Search 1.1.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting excessively long input strings to the search functionality. Attackers can paste a buffer of 950 or more characters into the search bar to trigger an unhandled exception that crashes the… | |
| Aplazada | Baja (2.1) | 0.35% | — | Mixelpixx Google Research MCPAI | 3/4/2026 | 24/7/2026 | A security vulnerability has been detected in mixelpixx Google-Research-MCP 1e062d7bd887bfe5f6e582b6cc288bb897b35cf2/ca613b736ab787bc926932f59cddc69457185a83. This issue affects the function extractContent of the file src/services/content-extractor.service.ts of the component Model Context Protocol Handler. The… | |
| Aplazada | Media (5.5) | 0.41% | — | Alejandroarciniegas Mcp-data-visAI | 2/4/2026 | 17/6/2026 | A vulnerability has been found in AlejandroArciniegas mcp-data-vis bc597e391f184d2187062fd567599a3cb72adf51/de5a51525a69822290eaee569a1ab447b490746d. This affects the function Request of the file src/servers/database/server.js of the component MCP Handler. The manipulation leads to sql injection. The attack may be… | |
| Analizada | Media (6.5) | 0.36% | — | Search-guard FLX | 31/3/2026 | 24/7/2026 | In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana. | |
| Analizada | Alta (8.1) | 0.33% | — | Search-guard FLX | 31/3/2026 | 24/7/2026 | In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary privileges to execute some management operations against data streams. | |
| Analizada | Media (4.3) | 0.29% | — | Search-guard FLX | 31/3/2026 | 24/7/2026 | In Search Guard FLX up to version 4.0.1, it is possible to use specially crafted requests to redirect the user to an untrusted URL. | |
| Modificada | Alta (7.5) | 1.4% | — | LibarchiveRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 30/3/2026 | 28/9/2026 | A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code… | |
| Analizada | Alta (8.6) | 0.19% | — | Kimtore Practical Music Search | 28/3/2026 | 7/10/2026 | PMS 0.42 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious values in the configuration file. Attackers can craft configuration files with oversized input that overflows the stack buffer and execute shell commands via… | |
| Analizada | Alta (8.6) | 0.21% | — | HNB Project Hierarchical Notebook | 28/3/2026 | 7/10/2026 | HNB Organizer 1.9.18-10 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized argument to the -rc command-line parameter. Attackers can craft a malicious input string exceeding 108 bytes containing shellcode and a return address to overwrite the… | |
| Aplazada | Alta (8.8) | 0.52% | — | Miguel Useche JS Archive ListAI | 25/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Miguel Useche JS Archive List jquery-archive-list-widget allows Object Injection.This issue affects JS Archive List: from n/a through <= 6.1.7. | |
| Aplazada | Media (5.4) | 0.24% | — | Edge-themes ArchiconAI | 25/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Edge-Themes Archicon archicon allows Object Injection.This issue affects Archicon: from n/a through < 1.7. | |
| Aplazada | Alta (7.1) | 0.25% | — | Eyecix JobsearchAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch wp-jobsearch allows Reflected XSS.This issue affects JobSearch: from n/a through <= 3.2.0. | |
| Aplazada | Crítica (9.3) | 0.28% | — | Eyecix Addon Jobsearch ChatAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eyecix Addon Jobsearch Chat addon-jobsearch-chat allows SQL Injection.This issue affects Addon Jobsearch Chat: from n/a through <= 3.0. | |
| Aplazada | Alta (7.1) | 0.18% | — | Eyecix Addon-jobsearch-chatAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix Addon Jobsearch Chat addon-jobsearch-chat allows Reflected XSS.This issue affects Addon Jobsearch Chat: from n/a through <= 3.0. |