Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2723▼ 319 respecto a la semana anterior
Críticas / altas1277▼ 191 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
23.894 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.32% | 💥 PoC | Aojiaoze AntarisAI | 12/7/2026 | 13/7/2026 | A vulnerability was detected in AojiaoZero Antaris 1.0. This affects the function _rewardPurchase of the file /ipn.php of the component PayPal IPN Payment Handler. The manipulation of the argument item_number results in sql injection. The attack may be performed from remote. The vendor was contacted early about this… | |
| Pendiente de análisis | Media (6.4) | 0.25% | — | Zephyrproject ZephyrAI | 11/7/2026 | 14/7/2026 | The Bluetooth BAP Broadcast Assistant GATT client in subsys/bluetooth/audio/bap_broadcast_assistant.c reassembled remote Broadcast Receive State data into a single file-static net_buf_simple (att_buf, BT_ATT_MAX_ATTRIBUTE_LEN = 512 bytes) shared by all connection instances, while the BUSY flag, long-read handle, and… | |
| Aplazada | Media (6.3) | 0.27% | — | Honojs HonoAI | 11/7/2026 | 14/7/2026 | Hono before 4.12.7 allows __proto__ key in parseBody with dot option enabled, permitting specially crafted form field names to create objects with __proto__ properties. When parsed results are merged into regular JavaScript objects using unsafe merge patterns, attackers can exploit this to achieve prototype pollution… | |
| Aplazada | Alta (7.5) | 0.76% | — | Saasproject Booking PackageAI | 11/7/2026 | 14/7/2026 | The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form<N>) in all versions up to, and including, 1.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Analizada | Media (5.4) | 0.23% | — | Colorbox Project Colorbox | 10/7/2026 | 14/7/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS). This issue affects Colorbox versions: from 0.0.0 to 2.1.5, from 0.0.0 to 2.2.0. | |
| Analizada | Media (5.4) | 0.23% | — | Flowdrop Project Flowdrop | 10/7/2026 | 14/7/2026 | Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0. | |
| Analizada | Media (5.4) | 0.23% | — | Flowdrop Project Flowdrop | 10/7/2026 | 14/7/2026 | Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0. | |
| Analizada | Media (6.1) | 0.26% | — | Drupal Canvas Project Drupal Canvas | 10/7/2026 | 21/7/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scripting (XSS). This issue affects Drupal Canvas versions: from 0.0.0 to 1.4.2, from 1.5.0 to 1.5.2, from 1.6.0 to 1.6.1, from 1.7.0 to 1.7.1. | |
| Analizada | Media (6.1) | 0.26% | — | Drupal Canvas Project Drupal Canvas | 10/7/2026 | 21/7/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scripting (XSS). This issue affects Drupal Canvas versions: from 0.0.0 to 1.4.2, from 1.5.0 to 1.5.2, from 1.6.0 to 1.6.1, from 1.7.0 to 1.7.1. | |
| Analizada | Alta (8.1) | 0.43% | — | Flag Attendance Field Project Flag Attendance Field | 10/7/2026 | 14/7/2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Flag attendance field allows Object Injection. This issue affects Flag attendance field versions: from 0.0.0 to 1.2. | |
| Analizada | Media (4.8) | 0.22% | — | Artificial Intelligence Project Artificial Intelligence | 10/7/2026 | 16/7/2026 | Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1. | |
| Analizada | Media (4.2) | 0.19% | — | Artificial Intelligence Project Artificial Intelligence | 10/7/2026 | 16/7/2026 | Missing Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents versions: from 0.0.0 to 1.1.4, from 1.2.0 to 1.2.5, from 1.3.0 to 1.3.1. | |
| Analizada | Baja (3.3) | 0.21% | — | Artificial Intelligence Project Artificial Intelligence | 10/7/2026 | 16/7/2026 | Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3. | |
| Analizada | Media (6.1) | 0.25% | — | Artificial Intelligence Project Artificial Intelligence | 10/7/2026 | 6/8/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI (Artificial Intelligence) allows Cross-Site Scripting (XSS). This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3. | |
| Analizada | Baja (3.3) | 0.21% | 💥 PoC | Openai Provider Project Openai Provider | 10/7/2026 | 6/8/2026 | Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows Server Side Request Forgery. This issue affects OpenAI Provider versions: from 0.0.0 to 1.1.1, from 1.2.0 to 1.2.2. | |
| Analizada | Alta (7.4) | 0.29% | — | Coturn Project Coturn | 10/7/2026 | 16/7/2026 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, coturn rejects loopback peers by default unless allow-loopback-peers is enabled, but the default loopback guard can be bypassed by using the IPv4-mapped IPv6 peer address ::ffff:127.0.0.1 in a TURN XOR-PEER-ADDRESS attribute.… | |
| Analizada | Media (6) | 0.21% | — | Coturn Project Coturn | 10/7/2026 | 16/7/2026 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, the psd print sessions dump CLI command in coturn takes a filename argument and directly passes it to fopen with no path validation. An authenticated admin with CLI access can overwrite arbitrary files writable by the coturn process… | |
| Analizada | Alta (7.2) | 0.70% | — | Coturn Project Coturn | 10/7/2026 | 16/7/2026 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.12.0, the coturn HTTPS admin panel passes HTTP query parameters directly into SQL queries via snprintf string interpolation without sanitization. The is_secure_string filter that protects the STUN protocol path is not applied to the admin… | |
| Analizada | Alta (7.5) | 0.66% | — | Decompress Project Decompress | 9/7/2026 | 13/7/2026 | decompress before 4.2.2 allows arbitrary symlink creation during archive extraction. When processing symlink entries (type === 'symlink'), the x.linkname field from the archive is passed directly to fs.symlink() without validation (index.js line 121). The preventWritingThroughSymlink check on line 98 only applies to… | |
| Analizada | Media (6.2) | 0.38% | — | Decompress Project Decompress | 9/7/2026 | 13/7/2026 | decompress before 4.2.2 contains an improper path containment check that enables directory traversal and arbitrary file write. The safeMakeDir function (index.js line 29) and the extraction path validation (index.js line 106) use String.indexOf() to verify the resolved path is within the output directory:… | |
| Analizada | Media (5.5) | 0.30% | — | Decompress Project Decompress | 9/7/2026 | 13/7/2026 | decompress before 4.2.2 allows arbitrary hardlink creation during archive extraction, enabling file read disclosure and file corruption. When processing hardlink entries (type === 'link'), the x.linkname field from the archive is passed directly to fs.link() without validation (index.js line 113). An attacker can… | |
| Analizada | Alta (8.4) | 2.9% | — | Gpsd Project Gpsd | 9/7/2026 | 14/7/2026 | gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from… | |
| Aplazada | Crítica (9.4) | 0.14% | — | Xenproject OxenstoredAI | 9/7/2026 | 9/7/2026 | When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When the domain ID is eventually reused, the new domain can create fewer nodes before beeing deemed to be over quota. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Interview Management SystemAI | 9/7/2026 | 9/7/2026 | A weakness has been identified in code-projects Interview Management System 1.0. This vulnerability affects unknown code of the file \inc\classes\View.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Online Food Order SystemAI | 9/7/2026 | 9/7/2026 | A security flaw has been discovered in code-projects Online Food Order System 1.0. This affects an unknown part of the file /edit_food_items.php. The manipulation of the argument update results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used… |