Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1319 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.26% | — | Next AI Draw.ioAI | 13/8/2026 | 9/9/2026 | Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site scripting vulnerability in the mcp query parameter that is interpolated without escaping into HTML and JavaScript. Attackers can craft malicious URLs to execute arbitrary JavaScript in the localhost origin, enabling exfiltration of diagram sessions… | |
| Aplazada | Alta (7.7) | 0.43% | — | Next AI Draw.ioAI | 13/8/2026 | 9/9/2026 | Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation that only checks string patterns without DNS resolution. Unauthenticated attackers can supply hostnames that bypass string validation but resolve to internal addresses,… | |
| Pendiente de análisis | Media (6.8) | 0.25% | — | Nextauth.js Next-authAICoreAI | 12/8/2026 | 9/9/2026 | NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in global cookies that are not bound to the provider that created them. On callback, a check value minted during a… | |
| Pendiente de análisis | Alta (7.5) | 0.88% | — | Nextauth @auth/coreAINextauth.js Next-authAI | 12/8/2026 | 9/9/2026 | NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the exported getToken() helper in the next-auth/jwt and @auth/core/jwt modules can throw an uncaught exception when it reads a malformed Authorization: Bearer header. When no session cookie is present,… | |
| Pendiente de análisis | Crítica (10) | 0.57% | — | IBM Doors NextAI | 12/8/2026 | 23/9/2026 | IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities. | |
| Aplazada | Alta (8.7) | 0.55% | — | Phoenixcontact Plcnext EngineerAI | 12/8/2026 | 29/9/2026 | An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted. | |
| Aplazada | Crítica (9.9) | 0.72% | — | Frappe ErpnextAI | 10/8/2026 | 9/9/2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py render subject, body, and pdf_name fields with unrestricted globals including… | |
| Aplazada | Alta (7.1) | 0.50% | — | Frappe ErpnextAI | 10/8/2026 | 9/9/2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, pause_job_for_doc, trigger_job_for_doc, change_release_date, and update_cost_center functions across erpnext/accounts/doctype/account/account.py,… | |
| Aplazada | Alta (7.1) | 0.47% | — | Frappe ErpnextAI | 10/8/2026 | 9/9/2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayableReport prepare_conditions path in erpnext/accounts/report/accounts_receivable/accounts_receivable.py does not apply Customer and Supplier user permissions to the Payment Ledger Entry dynamic-link… | |
| Aplazada | Media (6.5) | 0.51% | — | Frappe ErpnextAI | 10/8/2026 | 8/9/2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template function in erpnext/accounts/doctype/tax_rule/tax_rule.py constructs an SQL WHERE clause from request-influenced posting_date and args values, allowing an authenticated low-privilege user to inject… | |
| Aplazada | Media (6.5) | 0.44% | — | Frappe ErpnextAI | 10/8/2026 | 8/9/2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function in erpnext/accounts/utils.py accepts the ignore_permissions argument without enforcing Account create permission, allowing an authenticated limited user to create unauthorized accounting master… | |
| Aplazada | Media (4.3) | 0.35% | — | Frappe ErpnextAI | 10/8/2026 | 8/9/2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email function in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py lacks a Process Statement Of Accounts permission check, allowing an authenticated low-privilege… | |
| Aplazada | Baja (3.8) | 0.17% | — | Posimyth Nexter BlocksAI | 9/8/2026 | 26/8/2026 | The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor role to store arbitrary CSS that is rendered site-wide on the front end, enabling defacement, content hiding, and UI redressing. | |
| Aplazada | Alta (7.3) | 0.19% | — | Nextor IP ChangerAI | 7/8/2026 | 10/9/2026 | NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 execute privileged system commands using `sudo` and `shell=True` directly inside application logic. In environments where passwordless sudo (`NOPASSWD`) is enabled, privileged… | |
| Aplazada | Alta (7.8) | 0.23% | — | Nextor IP ChangerAI | 7/8/2026 | 10/9/2026 | NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 have a command execution vulnerability due to unsafe use of `shell=True` with commands that rely on executable resolution through the `PATH` environment variable. An attacker… | |
| Aplazada | Alta (7.1) | 0.47% | 💥 Exploit | Nextgen GalleryAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions. | |
| Aplazada | Media (6.1) | 0.25% | — | Posimyth Nexter BlocksAI | 6/8/2026 | 29/9/2026 | The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any user able to upload files (Author by default), allowing them to upload a file containing malicious JavaScript that executes when the file is accessed, leading to Stored Cross-Site Scripting. | |
| Aplazada | Alta (7.1) | 0.43% | — | Frappe ErpnextAI | 4/8/2026 | 28/8/2026 | An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method erpnext.crm.doctype.prospect.prospect.get_opportunities. This issue affects ERPNext: before 15.115.0, before 16.26.0. | |
| Aplazada | Alta (7.1) | 0.37% | — | FrappeAIFrappe ErpnextAI | 29/7/2026 | 30/7/2026 | SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application constructs SQL queries through direct string interpolation using `str.format()` without employing parameterized queries, allowing the name (docname) of a Supplier record containing SQL metacharacters to be interpreted as… | |
| Aplazada | Baja (2.1) | 0.39% | — | Nextlevelbuilder GoclawAI | 28/7/2026 | 28/7/2026 | A flaw has been found in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function ExecTool.Execute of the file goclaw/internal/http/tools_invoke.go of the component jq Handler. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. The exploit has… | |
| Analizada | Alta (8.3) | 0.46% | — | Vercel Next.js | 27/7/2026 | 29/7/2026 | Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the… | |
| Analizada | Media (6) | 0.34% | — | Vercel Next.js | 27/7/2026 | 29/7/2026 | Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. Confidential data in the POST's response body… | |
| Analizada | Media (6.3) | 0.32% | — | Vercel Next.js | 27/7/2026 | 29/7/2026 | Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. Confidential data in the POST's response body… | |
| Analizada | Media (6.3) | 0.52% | — | Vercel Next.js | 27/7/2026 | 29/7/2026 | Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge runtime. This… | |
| Analizada | Alta (8.3) | 0.41% | — | Vercel Next.js | 27/7/2026 | 29/7/2026 | Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's hostname… |