Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2597▼ 310 respecto a la semana anterior
Críticas / altas1338▲ 74 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
401.400 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 0.29% | — | Vercel Next.js | 2/10/2026 | 5/10/2026 | Next.js is a React framework for building full-stack web applications. From 16.3.0 until 16.3.8, pending use cache fills for the same key are shared without separating Draft Mode requests from regular requests. An overlapping regular request can receive unauthenticated unpublished content from an editor's Draft Mode… | |
| Analizada | Media (6.3) | 0.27% | — | Vercel Next.js | 2/10/2026 | 5/10/2026 | Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated or Incremental Static Regeneration pages can key a response cache entry without sufficiently binding it to the source route. A request… | |
| Analizada | Baja (2.3) | 0.17% | — | Vercel Next.js | 2/10/2026 | 5/10/2026 | Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the next dev development server exposes a Model Context Protocol endpoint without reliably restricting cross-site requests. A malicious website visited by a developer can reach the endpoint and read the project's disk… | |
| Analizada | Media (6.3) | 0.17% | — | Vercel Next.js | 2/10/2026 | 5/10/2026 | Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the `next dev` development server exposes a Model Context Protocol endpoint without reliably restricting cross-site requests. A malicious website visited by a developer can reach the endpoint and read the project's disk… | |
| Analizada | Media (6.3) | 0.27% | — | Vercel Next.js | 2/10/2026 | 5/10/2026 | Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, applications with a root-level catch-all page and statically generated or Incremental Static Regeneration routes can use a shared response cache key that is insufficiently scoped to the source route. A single… | |
| Analizada | Alta (8.3) | 0.27% | — | Vercel Next.js | 2/10/2026 | 5/10/2026 | Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, Image Optimization can follow attacker-controlled DNS resolution for a remote URL that matches images.remotePatterns, allowing the optimized image fetch to reach private IP addresses after the URL passes the allow-list… | |
| Pendiente de análisis | Alta (7.5) | 0.34% | — | Crmne Ruby LLMAI | 2/10/2026 | 2/10/2026 | crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x | |
| Aplazada | Sin puntuar | 0.27% | — | Modelscope AgentscopeAI | 2/10/2026 | 2/10/2026 | agentscope v1.0.20 contains code injection in execute_shell_command (src/agentscope/tool/_coding/_shell.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution. | |
| Aplazada | Crítica (9.8) | 0.21% | — | FinrobotAI | 2/10/2026 | 5/10/2026 | FinRobot 1.0.0 contains code injection in CodingUtils.create_file_with_code (). | |
| Aplazada | Alta (7.3) | 0.21% | — | FinrobotAI | 2/10/2026 | 5/10/2026 | FinRobot v1.0.0 is vulnerable to Code Injection in CodingUtils.modify_code. | |
| Aplazada | Alta (7.5) | 0.43% | — | SuperagiAI | 2/10/2026 | 2/10/2026 | TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete_user_knowledge in superagi/controllers/knowledges.py. In affected source snapshots, POST /knowledges/delete/{knowledge_id} deletes the selected knowledge object without requiring authentication in the route and without… | |
| Aplazada | Sin puntuar | 0.23% | — | SuperagiAI | 2/10/2026 | 2/10/2026 | TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the tool controller. In affected source snapshots, get_tool and update_tool in superagi/controllers/tool.py accept a caller-supplied tool_id and fail to verify organization ownership through the associated toolkit. A remote authenticated… | |
| Aplazada | Alta (8.8) | 0.21% | — | SuperagiAI | 2/10/2026 | 5/10/2026 | TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the agent template controller. In affected source snapshots, save_agent_as_template and publish_template in superagi/controllers/agent_template.py accept caller-supplied agent_id or agent_execution_id values and do not verify that the… | |
| Aplazada | Crítica (9.8) | 0.36% | — | VannaAI | 2/10/2026 | 5/10/2026 | vanna v2.0.2 contains a code injection vulnerability in VannaBase.get_plotly_figure (src/vanna/legacy/base/base.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution. | |
| Aplazada | Alta (8.1) | 0.39% | — | Taskingai QR Code GeneratorAI | 2/10/2026 | 2/10/2026 | In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write image files to arbitrary locations on the server filesystem by manipulating the project_id parameter. | |
| Aplazada | Sin puntuar | 0.14% | — | TaskingaiAI | 2/10/2026 | 2/10/2026 | In TaskingAI v0.3.0 in the DALL-E 3 image generation tool save_url_image function, a path traversal vulnerability allows attackers to write downloaded images to arbitrary locations on the server filesystem by manipulating the project_id parameter. | |
| Aplazada | Crítica (9.8) | 0.19% | — | SuperagiAI | 2/10/2026 | 5/10/2026 | SuperAGI up to v0.0.14 contains an improper access control vulnerability in the agent execution controller. In affected source snapshots, create_agent_execution and create_agent_run in superagi/controllers/agent_execution.py accept a caller-supplied agent_id and fail to verify that the referenced agent belongs to the… | |
| Aplazada | Alta (8.1) | 0.16% | — | SuperagiAI | 2/10/2026 | 5/10/2026 | SuperAGI up to 0.0.14 is vulnerable to Incorrect Access Control. The agent execution controller endpoint /api/agentexecutions/schedule allows authenticated users from one organization to schedule existing agents belonging to a different organization without proper authorization checks. The endpoint accepts an agent_id… | |
| Aplazada | Media (4.3) | 0.19% | — | SuperagiAI | 2/10/2026 | 2/10/2026 | In SuperAGI v0.0.14 and prior, controller endpoints (/api/agents/create, /api/agents/schedule, /api/agents/delete, /api/agents/edit_schedule, /api/agents/stop_schedule) allow authenticated users from one organization to create, schedule, edit, stop, and delete agents belonging to a different organization's project.… | |
| Pendiente de análisis | Sin puntuar | 0.16% | — | Sinaptik AI Pandas-aiAI | 2/10/2026 | 2/10/2026 | sinaptik-ai pandas-ai 3.0.0 is vulnerable to Code Injection in CodeExecutor.execute. | |
| Aplazada | Media (5.3) | 0.21% | — | MispAI | 2/10/2026 | 2/10/2026 | MISP contains an improper access control vulnerability in its attribute search and paginated attribute view endpoints. When a user queries for soft-deleted attributes (e.g., via the deleted-attributes search or the paginated attribute listing), the application returned soft-deleted attributes belonging to events owned… | |
| Aplazada | Alta (7.1) | 0.21% | — | MispAI | 2/10/2026 | 3/10/2026 | MISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system authorized access to correlated attributes and events based on a stale distribution snapshot stored on the correlation row rather than the… | |
| Aplazada | Media (5.3) | 0.27% | — | MispAI | 2/10/2026 | 3/10/2026 | MISP contains an authorization bypass in the related events listing functionality. When a user requests the list of events correlated to a given event, the system retrieved related event metadata directly from the correlation table without re-validating the caller's access rights against each related event. The… | |
| Aplazada | Alta (7.1) | 0.29% | — | MispAI | 2/10/2026 | 2/10/2026 | MISP contains an improper input validation vulnerability in the decaying model import functionality. The import endpoint was intended to create a new decaying model belonging exclusively to the importing user's organisation, with the default flag forced to off. However, the application stripped only the top-level id… | |
| Aplazada | Media (4.8) | 0.35% | — | MispAI | 2/10/2026 | 2/10/2026 | MISP contains a cross-site scripting (XSS) vulnerability in the remote event preview page. When a linked (remote) MISP server is configured, the event preview renders tag identifiers inside an inline JavaScript onclick attribute. The tag ID value was HTML-escaped but not sanitized for the JavaScript string context,… |