Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
232 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.3) | 0.18% | — | MyscaledbAI | 29/6/2026 | 29/6/2026 | A security flaw has been discovered in MyScale MyScaleDB up to 1.8.0. This vulnerability affects the function SegmentId::getCacheKey in the library src/VectorIndex/Common/SegmentId.h. The manipulation results in insufficient verification of data authenticity. It is possible to launch the attack remotely. A high… | |
| Aplazada | Baja (2.3) | 0.35% | — | Authzed SpicedbAI | 10/6/2026 | 23/7/2026 | SpiceDB is an open source database system for creating and managing security-critical application permissions. From version 1.15.0 to before version 1.52.0, caveat structures with nested lists can result in improper cache reuse. This issue has been patched in version 1.52.0. | |
| Aplazada | Baja (2.9) | 0.41% | — | Unitedbyai DroidclawAI | 1/6/2026 | 22/7/2026 | A vulnerability was detected in unitedbyai droidclaw up to 0.5.3. The affected element is an unknown function of the file server/src/routes/pairing.ts of the component claim Endpoint. The manipulation results in improper restriction of excessive authentication attempts. The attack may be launched remotely. This attack… | |
| Aplazada | Crítica (9) | 0.43% | — | ArcadedbAI | 12/5/2026 | 3/8/2026 | ArcadeDB is a Multi-Model DBMS. Starting in version 21.10.1 and prior to version 26.4.2, authenticated users and API tokens scoped to a specific database could read, write, and mutate schema on any other database on the same server. Two distinct defects contributed: (1) ServerSecurityUser.getDatabaseUser() returned a… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Feedback SystemAI | 7/5/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Feedback System 1.0. Impacted is an unknown function of the file /admin/checklogin.php. Such manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. | |
| Analizada | Media (4.4) | 0.18% | — | Authzed Spicedb | 15/4/2026 | 17/6/2026 | SpiceDB is an open source database system for creating and managing security-critical application permissions. In versions 1.49.0 through 1.51.0, when SpiceDB starts with log level info, the startup "configuration" log will include the full datastore DSN, including the plaintext password, inside DatastoreConfig.URI.… | |
| Aplazada | Media (4.3) | 0.27% | — | Syedbalkhi User FeedbackAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Feedback: from n/a through <= 1.10.1. | |
| Aplazada | Alta (7.6) | 0.36% | — | Syedbalkhi User FeedbackAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Blind SQL Injection.This issue affects User Feedback: from n/a through <= 1.10.1. | |
| Aplazada | Media (5.5) | 0.41% | — | Sinaptik AI Pandasai LancedbAIGabrieleventuri PandasaiAI | 28/3/2026 | 17/6/2026 | A vulnerability was identified in Sinaptik AI PandasAI up to 0.1.4. Affected by this issue is the function delete_question_and_answers/delete_docs/update_question_answer/update_docs/get_relevant_question_answers_by_id/get_relevant_docs_by_id of the file extensions/ee/vectorstores/lancedb/pandasai_lancedb/lancedb.py of… | |
| Aplazada | Media (4.8) | 0.19% | — | Syedbalkhi WP Lightbox 2AI | 26/3/2026 | 17/6/2026 | The WP Lightbox 2 WordPress plugin before 3.0.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Pendiente de análisis | Crítica (9.3) | 0.80% | — | Speedbit Download Accelerator PlusAI | 24/3/2026 | 17/6/2026 | Download Accelerator Plus DAP 10.0.6.0 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by crafting malicious URLs. Attackers can create specially crafted URLs with overflowing buffer data that overwrites SEH pointers and executes embedded… | |
| Analizada | Media (6.9) | 0.18% | — | Pixarra Twistedbrush PRO Studio | 21/3/2026 | 17/6/2026 | TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability that allows local attackers to crash the application by importing a malformed .srp script file. Attackers can create a .srp file containing an excessively large buffer and import it through the Script Player interface to trigger an application… | |
| Analizada | Media (6.9) | 0.19% | — | Pixarra Twistedbrush PRO Studio | 21/3/2026 | 17/6/2026 | TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability in the Resize Image function that allows local attackers to crash the application by supplying an excessively long buffer. Attackers can paste a malicious string into the New Width or New Height field to trigger a buffer overflow that causes the… | |
| Analizada | Media (6.9) | 0.18% | — | Pixarra Twistedbrush PRO Studio | 21/3/2026 | 17/6/2026 | TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability in the Script Recorder component that allows local attackers to crash the application by supplying an excessively large buffer. Attackers can paste a malicious string containing 500,000 characters into the Description field of the Script Recorder… | |
| Aplazada | Baja (2.3) | 0.21% | — | Mendi Neurofeedback Headset V4AI | 7/3/2026 | 16/8/2026 | A vulnerability was detected in Mendi Neurofeedback Headset V4. Affected by this vulnerability is an unknown functionality of the component Bluetooth Low Energy Handler. Performing a manipulation results in cleartext transmission of sensitive information. The attack can only be performed from the local network. The… | |
| Analizada | Alta (8.8) | 0.20% | — | Timescaledb | 6/3/2026 | 17/6/2026 | TimescaleDB is a time-series database for high-performance real-time analytics packaged as a Postgres extension. From version 2.23.0 to 2.25.1, PostgreSQL uses the search_path setting to locate unqualified database objects (tables, functions, operators). If the search_path includes user-writable schemas a malicious… | |
| Aplazada | Alta (7.1) | 0.24% | — | Keeswolters Mopinion Feedback FormAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in keeswolters Mopinion Feedback Form mopinion-feedback-form allows DOM-Based XSS.This issue affects Mopinion Feedback Form: from n/a through <= 1.1.1. | |
| Aplazada | Baja (2.4) | 0.18% | — | Yugabytedb AnywhereAI | 5/2/2026 | 17/6/2026 | YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web UI. An authenticated user with access to the configuration view could obtain LDAP credentials, potentially enabling unauthorized access to external directory services. | |
| Aplazada | Media (4.3) | 0.22% | — | Syedbalkhi Sugar Calendar LiteAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Syed Balkhi Sugar Calendar (Lite) sugar-calendar-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sugar Calendar (Lite): from n/a through <= 3.9.1. | |
| Aplazada | Media (6.5) | 0.29% | — | Bosch Infotainment ECUAINissan Leaf ZE1AIRedbendAI | 22/1/2026 | 17/6/2026 | The Infotainment ECU manufactured by Bosch which is installed in Nissan Leaf ZE1 – 2020 uses a Redbend service for over-the-air provisioning and updates. HTTPS is used for communication with the back-end server. Due to usage of the default configuration for the underlying SSL engine, the server root certificate is not… | |
| Analizada | Media (4.8) | 0.23% | — | Enterprisedb Postgres Enterprise Manager | 16/1/2026 | 17/6/2026 | PEM versions prior to 9.8.1 are affected by a stored Cross-site Scripting (XSS) vulnerability that allows users with access to the Manage Charts menu to inject arbitrary JavaScript when creating a new chart, which is then executed by any user accessing the chart. By default only the superuser and users with pem_admin… | |
| Aplazada | Alta (7.6) | 0.47% | — | Syedbalkhi User FeedbackAI | 24/12/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Blind SQL Injection.This issue affects User Feedback: from n/a through <= 1.10.0. | |
| Aplazada | Media (5.3) | 0.25% | — | Syedbalkhi Feeds FOR YoutubeAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Syed Balkhi Feeds for YouTube feeds-for-youtube allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Feeds for YouTube: from n/a through <= 2.4.0. | |
| Analizada | Alta (7) | 0.23% | — | Enterprisedb Hybrid Manager | 15/12/2025 | 17/6/2026 | EDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints. This could allow an attacker to read potentially sensitive data or possibly cause a denial-of-service by writing malformed data to certain gRPC endpoints. This flaw has been remediated in EDB Hybrid… | |
| Aplazada | Media (5.3) | 0.90% | 💥 Exploit | Feedback Modal FOR WebsiteAI | 5/12/2025 | 17/6/2026 | The Feedback Modal for Website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'handle_export' function in all versions up to, and including, 1.0.1. This makes it possible for unauthenticated attackers to export all feedback data in CSV or JSON format via the… |