Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
23.688 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.7) | 0.58% | — | Temporalio Ringpop-goAI | 21/9/2026 | 22/9/2026 | github.com/temporalio/ringpop-go enforces configured LabelOptions limits when an application changes the local node's labels, but affected versions do not apply those limits to label maps received in SWIM membership changes. A network peer that can reach a live Ringpop TChannel listener can repeatedly submit changes… | |
| Pendiente de análisis | Alta (8.7) | 0.71% | — | Temporalio Tchannel-goAI | 21/9/2026 | 22/9/2026 | github.com/temporalio/tchannel-go did not reject TChannel call fragments containing checksum metadata but no length-prefixed argument chunks. The fragment reader left its chunk slice empty and then unconditionally selected the first element. A network peer can supply such a malformed call fragment, including as a… | |
| Pendiente de análisis | Alta (8.7) | 0.71% | — | Temporalio Tchannel-goAI | 21/9/2026 | 22/9/2026 | github.com/temporalio/tchannel-go did not validate the one-byte checksum-type field in inbound TChannel call frames. A network peer that can reach a listener can complete the standard initialization handshake and send a call request with an unsupported checksum type. The parser uses that value as an index into a… | |
| Aplazada | Media (5.5) | 0.43% | — | DrogonAI | 21/9/2026 | 24/9/2026 | A flaw has been found in drogonframework drogon up to 1.9.13. This affects the function makeCriteria in the library orm_lib/src/Criteria.cc of the component ORM. Executing a manipulation of the argument filter can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be… | |
| Aplazada | Media (5.5) | 0.43% | — | DrogonAI | 21/9/2026 | 21/9/2026 | A vulnerability was detected in drogonframework drogon up to 1.9.13. Affected by this issue is the function Mapper::orderBy in the library Mapper.h of the component ORM Mapper. Performing a manipulation of the argument sort results in sql injection. The attack is possible to be carried out remotely. The exploit is now… | |
| Aplazada | Alta (7) | 0.91% | — | GopeedAI | 19/9/2026 | 22/9/2026 | Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers can craft malicious archives with entries containing directory traversal sequences that bypass validation, enabling file write operations… | |
| Pendiente de análisis | Alta (8.3) | 0.44% | — | Argo WorkflowsAI | 19/9/2026 | 22/9/2026 | Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Attackers with namespace-scoped list permissions can use a negated namespace field… | |
| Aplazada | Crítica (9.8) | 0.42% | — | Perl DBIAIPerl DBD DBMAIPerl MldbmAIPerl DBD GoferAI | 19/9/2026 | 22/9/2026 | DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a module. require treats a path-shaped string as a literal filename and does not… | |
| Aplazada | Media (6.5) | 0.58% | — | Wpgogo Custom Field TemplateAI | 19/9/2026 | 21/9/2026 | The Custom Field Template plugin for WordPress is vulnerable to generic SQL Injection via the 'post_ID' parameter in all versions up to, and including, 2.7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (4.9) | 0.44% | — | Gopay FOR WoocommerceAI | 19/9/2026 | 21/9/2026 | The GoPay for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'log_table_filter' parameter in all versions up to, and including, 1.0.36 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (6.1) | 0.33% | — | Gowebsolutions WP Customer ReviewsAI | 19/9/2026 | 21/9/2026 | The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' parameter in all versions up to, and including, 3.7.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Alta (7.5) | 0.43% | — | MgosyncAI | 19/9/2026 | 21/9/2026 | The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, including a read/write consumer key and secret, from a configured site. | |
| Analizada | Alta (7.1) | 0.15% | — | Mongodb Mongoid | 18/9/2026 | 24/9/2026 | Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema. Applications that enable this feature can therefore store values intended to be encrypted in readable form, with no error or warning. A party with routine read access to the database,… | |
| Analizada | Alta (7.1) | 0.15% | — | Mongodb Mongoid | 18/9/2026 | 24/9/2026 | A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written and kept in cleartext, without any error or warning. A party holding ordinary read access to the database can then read… | |
| Analizada | Crítica (9.2) | 0.57% | — | Mongodb Mongoid | 18/9/2026 | 24/9/2026 | Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored… | |
| Analizada | Alta (8.7) | 0.46% | — | Mongodb Mongoid | 18/9/2026 | 24/9/2026 | An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application process. Applications that place user-supplied text into a pattern-matching query condition on an… | |
| Analizada | Alta (8.3) | 0.53% | — | Mongodb Mongoid | 18/9/2026 | 24/9/2026 | Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter parameters in this way, a party with no credentials may influence how the database evaluates the query.… | |
| Analizada | Alta (8.8) | 0.43% | — | Mongodb Mongoid | 18/9/2026 | 24/9/2026 | Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application supplies as a query argument may cause code of their choosing to be evaluated by… | |
| Analizada | Alta (8.3) | 0.51% | — | Mongodb Mongoid | 18/9/2026 | 25/9/2026 | Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal method invocation instead of the intended array field update. This may result… | |
| Analizada | Alta (8.6) | 0.36% | — | Mongodb Mongoid | 18/9/2026 | 25/9/2026 | An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a request can cause that record to be looked up without the usual ownership or scoping… | |
| Aplazada | Media (6.9) | 0.65% | — | Forget-c Jellyfish AI Short Drama StudioAITiangolo FastapiAI | 18/9/2026 | 22/9/2026 | A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2. This affects an unknown function of the file backend/app/dependencies.py of the component FastAPI. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. The… | |
| Aplazada | Media (5.4) | 0.43% | — | Biggop LibraryAISigmative APIAI | 18/9/2026 | 18/9/2026 | The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in various versions due to insufficient output escaping. This makes it possible for attackers who can compromise the Sigmative API server to inject arbitrary web scripts in pages that will execute whenever a… | |
| Aplazada | Alta (8.4) | 0.20% | — | Django-page-cmsAI | 18/9/2026 | 22/9/2026 | django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify page content. Signed-in editors visiting a malicious page can be tricked into storing unescaped content that renders to all visitors, enabling stored… | |
| Aplazada | Alta (7.1) | 0.45% | — | Django-page-cmsAI | 18/9/2026 | 22/9/2026 | django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff account to read arbitrary page content and stored media paths. Attackers with low-privilege staff credentials can enumerate content identifiers and access unpublished drafts, page listings, and file… | |
| Aplazada | Alta (8.7) | 0.49% | 💥 PoC | SogoAI | 17/9/2026 | 22/9/2026 | SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains. Attackers can submit password recovery requests with a malicious Origin header to have valid password-reset tokens… |