Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
736 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.55% | — | Filebrowser File BrowserAI | 25/6/2026 | 26/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, unchecked passwords maximums allow for an arbitrarily large password to be passed into the login API. This spikes CPU and memory, and after testing, crashes, heavily… | |
| Aplazada | Alta (7.5) | 0.52% | — | Filebrowser File BrowserAI | 25/6/2026 | 26/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, File Browser's public share handlers rebase the share owner's filesystem root to the shared directory and then evaluate descendant paths against the owner's global… | |
| Aplazada | Alta (8.7) | 0.44% | — | Filebrowser File BrowserAI | 25/6/2026 | 26/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.33.8, when a shell interpreter is configured (e.g. /bin/sh -c), the command allowlist can be bypassed through shell metacharacters. The allowlist validates only the first… | |
| Aplazada | Crítica (9.1) | 0.61% | — | FilebrowserAI | 25/6/2026 | 25/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Starting with 2.0.0-rc.1, when FileBrowser is configured with proxy authentication (auth.method=proxy), any unauthenticated attacker who can reach the server directly can impersonate… | |
| Aplazada | Crítica (9.3) | 0.76% | — | Filebrowser File BrowserAI | 25/6/2026 | 25/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, the Hook Authentication feature in File Browser allows administrators to delegate login verification to an external shell command. User-supplied credentials… | |
| Aplazada | Baja (1.9) | 0.16% | — | Browserbase SkillsAI | 22/6/2026 | 3/7/2026 | A security flaw has been discovered in Browserbase Skills up to 20260526. This impacts an unknown function of the component Autobrowse Trace Artifact Handler. The manipulation results in incorrect default permissions. The attack requires a local approach. The exploit has been released to the public and may be used for… | |
| Aplazada | Alta (8.5) | 0.18% | — | Comodo Dragon BrowserAI | 19/6/2026 | 29/9/2026 | Comodo Dragon Browser versions up to 52.15.25.663 contain a privilege escalation vulnerability in the DragonUpdater service due to an unquoted service path running with SYSTEM privileges. A local attacker can insert a malicious executable in the service path and execute arbitrary code with elevated privileges upon… | |
| Aplazada | Alta (8.5) | 0.18% | — | Comodo Chromodo BrowserAI | 19/6/2026 | 29/9/2026 | Comodo Chromodo Browser 52.15.25.664 contains an unquoted service path vulnerability in the ChromodoUpdater service that runs with SYSTEM privileges. A local attacker can insert a malicious executable in the service path and execute arbitrary code with elevated privileges upon service restart or system reboot. | |
| Aplazada | Crítica (9.3) | 0.52% | — | Filebrowser QuantumAI | 16/6/2026 | 17/6/2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable, 1.4.0-beta and 1.4.1-beta are vulnerable to Path Traversal through the publicPatchHandler in backend/http/public.go which joins user-controlled fromPath and toPath body fields with the trusted d.share.Path BEFORE the… | |
| Aplazada | Alta (7.8) | 0.91% | — | Browserstack Cypress CLIAI | 15/6/2026 | 17/6/2026 | The browserstack-cypress-cli is BrowserStack's CLI which allows users to run Cypress tests on BrowserStack. Versions prior to 1.36.4 are vulnerable to OS command injection via the cypress_config_file configuration parameter. In readCypressConfigUtil.js, the loadJsFile() function constructs a shell command by… | |
| Analizada | Alta (8.4) | 0.21% | — | Paloaltonetworks Idira Identity Browser Extension | 11/6/2026 | 22/6/2026 | Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification routines. If an authenticated user navigates to a specially crafted webpage, this interaction could potentially allow a remote attacker to trigger… | |
| Analizada | Crítica (9.5) | 0.77% | — | Apache Cordova Inappbrowser | 8/6/2026 | 23/7/2026 | ## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WKScriptMessage` body to `commandDelegate sendPluginResult:callbackId:` with no format validation (`CDVWKInAppBrowser.m:560–574`). Any web content loaded inside the InAppBrowser can fire any pending Cordova callback in the… | |
| Aplazada | Alta (7.1) | 0.30% | — | Browserstack RunnerAI | 2/6/2026 | 22/7/2026 | BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the _default HTTP handler in lib/server.js that allows unauthenticated network-adjacent attackers to read arbitrary files. Attackers can exploit the unauthenticated HTTP server bound on all interfaces to traverse outside the project root and… | |
| Aplazada | Alta (8.7) | 0.67% | — | Browserstack RunnerAI | 2/6/2026 | 22/7/2026 | BrowserStack Runner through 0.9.5 contains a remote code execution vulnerability in the /_log HTTP handler that allows unauthenticated network-adjacent attackers to execute arbitrary code by submitting crafted JSON request bodies to the handler, which passes user-supplied data to vm.runInNewContext() combined with… | |
| Aplazada | Alta (8.8) | 0.65% | — | Cloakbrowser CloakserveAI | 1/6/2026 | 22/7/2026 | CloakBrowser is a tool to bypass bot detection tests. Prior to version 0.3.28, the cloakserve CDP multiplexer uses the user-supplied fingerprint query parameter directly as a filesystem path component when creating Chrome profile directories. An unauthenticated attacker who can reach the cloakserve port can supply a… | |
| Analizada | Crítica (9.1) | 0.60% | — | Gtsteffaniak Filebrowser Quantum | 14/5/2026 | 17/6/2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-stable and 1.3.9-beta, attacker-controlled path input is joined with a trusted base path prior to sanitization, allowing traversal sequences (e.g., ../) to escape the intended shared directory. As a result, an unauthenticated attacker… | |
| Analizada | Alta (7.3) | 0.16% | — | Paloaltonetworks Prisma Browser | 13/5/2026 | 13/7/2026 | A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing a locally authenticated non-admin user to leverage this exposed Apple Event handler to send unauthorized commands to the browser. | |
| Analizada | Media (5.8) | 0.11% | — | Paloaltonetworks Prisma Browser | 13/5/2026 | 14/7/2026 | A race condition vulnerability in Palo Alto Networks Prisma® Browser enables a locally authenticated non-admin user to bypass certain access and data control policies. | |
| Analizada | Alta (7.3) | 0.15% | — | Paloaltonetworks Prisma Browser | 13/5/2026 | 14/7/2026 | An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allows a locally authenticated non-admin user to leverage an exposed communication channel to send unauthorized commands to the browser,… | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Aplazada | Media (4.7) | 0.28% | — | ZEN BrowserAI | 11/5/2026 | 17/6/2026 | Zen is a firefox-based browser. Prior to 1.19.12b, the ZEN Browser incorrectly truncates long hostnames in the address bar and shows only the attacker-controlled prefix of the subdomain, hiding the actual registrable domain (eTLD+1). As a result, an attacker can craft extremely long malicious subdomains that visually… | |
| Aplazada | Alta (8) | 0.27% | — | ZEN BrowserAI | 11/5/2026 | 17/6/2026 | Zen is a firefox-based browser. Prior to 1.19.9b, Zen Browser ships a Mozilla Application Resource (MAR) updater (org.mozilla.updater) that has had all MAR signature verification stripped from the Firefox codebase it was forked from. The MAR files served to users contain zero cryptographic signatures, and the updater… | |
| Aplazada | Media (5.5) | 0.59% | — | Browseroperator Browser-operator-coreAI | 28/4/2026 | 17/6/2026 | A weakness has been identified in BrowserOperator browser-operator-core up to 0.6.0. Affected is the function startsWith of the file scripts/component_server/server.js. Executing a manipulation of the argument request.url can lead to path traversal. The attack can be launched remotely. The exploit has been made… | |
| Aplazada | Media (5.5) | 2.6% | — | Agentdeskai Browser-tools-mcpAI | 26/4/2026 | 2/10/2026 | A flaw has been found in AgentDeskAI browser-tools-mcp up to 1.2.0. This issue affects some unknown processing of the file browser-tools-server/browser-connector.ts. Executing a manipulation can lead to os command injection. The attack may be performed from remote. The exploit has been published and may be used.… | |
| Aplazada | Media (5.1) | 0.26% | — | Deepl Chrome Browser ExtensionAI | 22/4/2026 | 17/6/2026 | DeepL Chrome browser extension versions from v1.22.0 to v.1.23.0 contain a cross-site scripting vulnerability, which allows an attacker to execute arbitrary script in a user's browser, and inject malicious HTML into web pages viewed by the user. |