Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2769▼ 305 respecto a la semana anterior
Críticas / altas1294▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
23.898 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.43% | — | OpenprojectAI | 26/6/2026 | 26/6/2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historical field values without enforcing object and field visibility. This vulnerability is fixed in 17.3.3 and 17.4.1. | |
| Aplazada | Crítica (9.9) | 0.49% | — | OpenprojectAI | 26/6/2026 | 29/6/2026 | OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key. Combined with cookies_serializer = :marshal, this gives any logged-in user a deterministic Marshal-deserialization path… | |
| Aplazada | Media (6.5) | 0.39% | — | OpenprojectAI | 26/6/2026 | 27/6/2026 | OpenProject is open-source, web-based project management software. Prior to 17.4.0, the GET /api/v3/relations endpoint allows any authenticated user to retrieve relations — and the subject (title) of work packages they have no permission to view — by supplying an arbitrary work package ID in the involved, fromId, or… | |
| Aplazada | Media (6.5) | 0.37% | — | OpenprojectAI | 26/6/2026 | 29/6/2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the GET /api/v3/shares endpoint returns share details for ALL work packages in a project to any user with the view_shared_work_packages permission. The authorization check operates at the project level only — it does not… | |
| Aplazada | Media (6.5) | 0.33% | — | OpenprojectAI | 26/6/2026 | 27/6/2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, a Missing Authorization vulnerability exists in OpenProject's CostReportsController. The rename and update actions allow any authenticated user to modify the name, filters, and grouping of any Public cost report in the… | |
| Aplazada | Media (5.9) | 0.28% | — | OpenprojectAI | 26/6/2026 | 29/6/2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permits to bypass password requirements. A password validation flaw in the change password behavior allows attackers to change a user's password… | |
| Aplazada | Media (4.3) | 0.28% | — | OpenprojectAI | 26/6/2026 | 29/6/2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, OpenProject exposes a document update endpoint used to modify existing documents. The target document is loaded with visibility checks and then updated. During update, attacker-controlled attributes are applied to the… | |
| Aplazada | Media (4.3) | 0.29% | — | OpenprojectAI | 26/6/2026 | 29/6/2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the web application's meetings filter feature leaks whether a given user ID corresponds to a valid account and discloses the user's full name, allowing an attacker to enumerate all existing user accounts by probing user IDs… | |
| Aplazada | Media (5.7) | 0.30% | — | OpenprojectAI | 26/6/2026 | 27/6/2026 | OpenProject is open-source, web-based project management software. Prior to 17.4.0, OpenProject's rich text (markdown) rendering pipeline uses Sanitize::Config::RELAXED[:css] for inline style sanitization. This configuration permits essentially all CSS properties in style attributes on permitted HTML elements (figure,… | |
| Analizada | Alta (7.5) | 0.44% | — | Podman Project Podman | 26/6/2026 | 6/7/2026 | Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to… | |
| Analizada | Media (5.3) | 0.40% | — | Podman Project Podman | 26/6/2026 | 26/6/2026 | Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where the WORKDIR path contains a symlink can create a directory or modify ownership on the host filesystem. Modified ownership is less likely to happen as that requires help from an untrusted/malicious… | |
| Analizada | Alta (7.5) | 0.49% | — | Zephyrproject Zephyr | 25/6/2026 | 6/7/2026 | Zephyr's IPv6 network stack can be prevented from receiving or processing future incoming packets by sending a small number of maliciously fragmented IPv6 packets. When such a packet is handled by the fragment-header processing path, the associated RX network packet buffer (allocated from a memory slab) is not… | |
| Analizada | Alta (8.7) | 0.36% | — | Shell-quote Project Shell-quote | 25/6/2026 | 26/6/2026 | shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every iteration. As a result parse() runs in O(n^2) time relative to the number of input tokens. An attacker who can supply an attacker-controlled… | |
| Modificada | Media (4.6) | 0.24% | — | Zephyrproject Zephyr | 24/6/2026 | 14/7/2026 | The Zephyr PL011 UART driver (drivers/serial/uart_pl011.c) contains an unbounded software loop in pl011_irq_tx_enable() that repeatedly invokes the interrupt-driven application callback while the TX interrupt mask bit (PL011_IMSC_TXIM) is set, to work around the controller's level-transition TX-interrupt behavior.… | |
| Modificada | Alta (7.5) | 0.76% | — | Faraday Project Faraday | 24/6/2026 | 14/8/2026 | Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. From 1.0.0 until 1.10.6 and 2.14.3, Faraday::NestedParamsEncoder, the default nested query parameter encoder/decoder in Faraday, decodes nested query strings without enforcing a maximum nesting depth. A crafted… | |
| Aplazada | Alta (7.7) | 0.62% | — | MotioneyeAIMotion Project MotionAI | 24/6/2026 | 25/6/2026 | motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Versions prior to 0.44.0 contain an absolute path traversal vulnerability in multiple media file handlers that allows an attacker to read arbitrary files from the filesystem.… | |
| Analizada | Media (5.7) | 0.14% | — | Dhcpcd Project Dhcpcd | 23/6/2026 | 14/7/2026 | dhcpcd through 10.3.2, fixed in commit 78ea09e, contains a heap use-after-free vulnerability in the control socket handling within src/control.c that allows local unprivileged attackers to trigger memory corruption when privilege separation is disabled. Attackers can connect to the control socket and send a privileged… | |
| Analizada | Media (6) | 0.27% | — | Dhcpcd Project Dhcpcd | 23/6/2026 | 14/7/2026 | dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-byte stack out-of-bounds write vulnerability in dhcp6_makemessage() in src/dhcp6.c that allows unauthenticated same-link attackers to write beyond a fixed local buffer by serializing an oversized RFC6603 OPTION_PD_EXCLUDE option body. Attackers can send a… | |
| Analizada | Media (6) | 0.27% | — | Dhcpcd Project Dhcpcd | 23/6/2026 | 14/7/2026 | dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-after-free vulnerability that allows unauthenticated same-link attackers to crash the daemon by sending a crafted DHCPv6 RENEW reply with RFC6603 OPTION_PD_EXCLUDE and both preferred and valid lifetimes set to zero. Attackers acting as or… | |
| Analizada | Crítica (9.6) | 0.46% | — | Yt-dlp Project Yt-dlp | 23/6/2026 | 26/6/2026 | yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary file write. On Windows platforms, this… | |
| Analizada | Crítica (9.6) | 0.66% | — | Yt-dlp Project Yt-dlp | 23/6/2026 | 26/6/2026 | yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that allows a remote attacker to write arbitrary OS-shortcut files (such as .desktop, .url, .webloc) to the user's filesystem, bypassing the remediation for CVE-2024-38519. The allowlist explicitly included the… | |
| Analizada | Alta (7.4) | 0.32% | — | Yt-dlp Project Yt-dlp | 23/6/2026 | 26/6/2026 | yt-dlp is a command-line audio/video downloader. From 2023.09.24 until 2026.06.09, if curl is used as an external downloader for yt-dlp, cookies may be leaked to an unintended host upon HTTP redirect or when the host for download fragments differs from their parent manifest's. At the file download stage, the cookies… | |
| Analizada | Alta (7.1) | 0.29% | — | Dhcpcd Project Dhcpcd | 23/6/2026 | 8/10/2026 | dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling that allows an unauthenticated same-link attacker to cause denial of service by sending crafted Router Advertisements. Attackers can repeatedly send Router Advertisements… | |
| Aplazada | Crítica (9.1) | 0.52% | — | Mojolicious Plugin WEB Auth Oauth2AI | 23/6/2026 | 23/6/2026 | Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no state generator is specified in the constructor, the module defaults to using a SHA-1 hash of predictable and low-entropy sources, including the epoch time (which is leaked via the HTTP Date header)… | |
| Modificada | Alta (7.1) | 0.28% | — | Zephyrproject Zephyr | 23/6/2026 | 14/7/2026 | bt_iso_recv() in subsys/bluetooth/host/iso.c pulled the ISO SDU header (4 bytes) or, when the timestamp flag is set, the timestamped SDU header (8 bytes) from the inbound HCI ISO Data buffer via net_buf_pull_mem() without first checking buf->len. The upstream hci_iso() handler enforces buf->len == the… |