Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
534 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.13% | — | Cloud Foundry Bosh | 27/5/2026 | 17/6/2026 | When the director sends a long-running request (e.g. compile_package), the agent's reply JSON is consumed by AgentClient. inject_compile_log (line 332-339) reads response['value']['result']['compile_log_id'] and format_exception (line 318-325) reads exception['blobstore_id']; both pass the agent-supplied string… | |
| Aplazada | Media (4.3) | 0.20% | — | Patternsinthecloud Autoship Cloud FOR Woocommerce Subscription ProductsAI | 25/5/2026 | 24/7/2026 | Missing Authorization vulnerability in Patterns in the cloud Autoship Cloud for WooCommerce Subscription Products allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.14.0. | |
| Aplazada | Alta (7.3) | 0.31% | — | InnoshopAI | 19/5/2026 | 24/7/2026 | An authorization vulnerability exists in Innoshop 0.6.0. After logging into the frontend, an attacker can directly access backend application interfaces, leading to further dangerous operations. | |
| Analizada | Media (6.5) | 0.23% | — | Goshs | 4/5/2026 | 17/6/2026 | goshs is a SimpleHTTPServer written in Go. Prior to version 2.0.2, the PUT upload handler (httpserver/updown.go) lacks the CSRF token validation that was added to the POST upload handler during the CVE-2026-40883 fix. Combined with the unconditional Access-Control-Allow-Origin: * on the OPTIONS preflight handler… | |
| Aplazada | Media (5.5) | 0.69% | — | Innocommerce InnoshopAI | 2/5/2026 | 17/6/2026 | A vulnerability has been found in innocommerce InnoShop up to 0.7.8. The affected element is the function InstallServiceProvider::boot of the file innopacks/install/src/InstallServiceProvider.php of the component Installation Endpoint. The manipulation leads to improper authentication. Remote exploitation of the… | |
| Aplazada | Alta (8.7) | 0.39% | — | Cewe PhotoshowAI | 26/4/2026 | 17/6/2026 | CEWE Photoshow 6.3.4 contains a buffer overflow vulnerability in the login dialog that allows attackers to crash the application by submitting oversized input. Attackers can inject 4000 bytes of data into the email address and password fields to trigger a denial of service condition. | |
| Analizada | Crítica (9.1) | 0.43% | — | Goshs | 21/4/2026 | 17/6/2026 | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can lead to leakage of the GITHUB_TOKEN through workflow artifacts, even though the token is not present in the repository source code. This vulnerability is fixed in 2.0.0-beta.6. | |
| Analizada | Alta (7.7) | 0.45% | — | Goshs | 21/4/2026 | 17/6/2026 | goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs leaks file-based ACL credentials through its public collaborator feed when the server is deployed without global basic auth. Requests to .goshs-protected folders are logged before authorization is enforced, and the collaborator… | |
| Analizada | Crítica (9.8) | 0.65% | — | Goshs | 21/4/2026 | 17/6/2026 | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP authentication bypass when the documented empty-username basic-auth syntax is used. If the server is started with -b ':pass' together with -sftp, goshs accepts that configuration but does not install any SFTP password handler. As… | |
| Analizada | Media (6.1) | 0.19% | — | Goshs | 21/4/2026 | 17/6/2026 | goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs contains a cross-site request forgery issue in its state-changing HTTP GET routes. An external attacker can cause an already authenticated browser to trigger destructive actions such as ?delete and ?mkdir because goshs relies on HTTP… | |
| Analizada | Alta (8.7) | 0.59% | — | Goshs | 21/4/2026 | 17/6/2026 | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP root escape caused by prefix-based path validation. An authenticated SFTP user can read from and write to filesystem paths outside the configured SFTP root, which breaks the intended jail boundary and can expose or modify… | |
| Analizada | Alta (8.6) | 0.31% | — | Adobe Photoshop Installer | 15/4/2026 | 29/7/2026 | Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could have exploited this vulnerability by placing a malicious library in a directory searched by the installer. Exploitation… | |
| Pendiente de análisis | Media (6.5) | 0.69% | — | Mafintosh Protocol-buffers-schemaAI | 15/4/2026 | 17/6/2026 | JavaScript is vulnerable to prototype pollution in Mafintosh's protocol-buffers-schema Version 3.6.0, where an attacker may alter the application logic, bypass security checks, cause a DoS or achieve remote code execution. | |
| Analizada | Alta (7.8) | 0.29% | — | Adobe Photoshop | 14/4/2026 | 28/8/2026 | Photoshop Desktop versions 27.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this… | |
| Analizada | Crítica (9.3) | 0.66% | — | Goshs | 10/4/2026 | 17/6/2026 | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.4, goshs enforces the documented per-folder .goshs ACL/basic-auth mechanism for directory listings and file reads, but it does not enforce the same authorization checks for state-changing routes. An unauthenticated attacker can upload files with PUT,… | |
| Analizada | Alta (7.7) | 0.39% | — | Goshs | 10/4/2026 | 17/6/2026 | goshs is a SimpleHTTPServer written in Go. From 1.0.7 to before 2.0.0-beta.4, the SFTP command rename sanitizes only the source path and not the destination, so it is possible to write outside of the root directory of the SFTP. This vulnerability is fixed in 2.0.0-beta.4. | |
| Aplazada | Media (6.5) | 0.22% | — | Josh Kohlbach Advanced Coupons FOR WoocommerceAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Josh Kohlbach Advanced Coupons for WooCommerce Coupons advanced-coupons-for-woocommerce-free allows DOM-Based XSS.This issue affects Advanced Coupons for WooCommerce Coupons: from n/a through <= 4.7.1.1. | |
| Analizada | Crítica (9.8) | 0.69% | — | Goshs | 6/4/2026 | 24/7/2026 | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, tdeleteFile() missing return after path traversal check. This vulnerability is fixed in 2.0.0-beta.3. | |
| Analizada | Crítica (9.8) | 0.69% | — | Goshs | 6/4/2026 | 24/7/2026 | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, the POST multipart upload directory not sanitized. This vulnerability is fixed in 2.0.0-beta.3. | |
| Analizada | Crítica (9.8) | 0.69% | — | Goshs | 6/4/2026 | 24/7/2026 | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, PUT upload in httpserver/updown.go has no path sanitization. This vulnerability is fixed in 2.0.0-beta.3. | |
| Analizada | Alta (8.1) | 0.45% | — | Goshs | 2/4/2026 | 24/7/2026 | goshs is a SimpleHTTPServer written in Go. From version 1.1.0 to before version 2.0.0-beta.2, when using the Share Token it is possible to bypass the limited selected file download with all the gosh functionalities, including code exec. This issue has been patched in version 2.0.0-beta.2. | |
| Aplazada | Alta (7.1) | 0.12% | — | Joshuae1974 Flash Video PlayerAI | 20/3/2026 | 17/6/2026 | Cross-Site request forgery (CSRF) vulnerability in joshuae1974 Flash Video Player allows Cross Site Request Forgery.This issue affects Flash Video Player: from n/a through 5.0.4. | |
| Aplazada | Media (6.5) | 0.17% | — | Josh Kohlbach WOO Product Feed PROAI | 13/3/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Josh Kohlbach Product Feed PRO for WooCommerce woo-product-feed-pro allows Cross Site Request Forgery.This issue affects Product Feed PRO for WooCommerce: from n/a through <= 13.5.2. | |
| Aplazada | Media (4.3) | 0.27% | — | Josh Kohlbach Advanced Coupons FOR Woocommerce CouponsAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Josh Kohlbach Advanced Coupons for WooCommerce Coupons advanced-coupons-for-woocommerce-free allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Coupons for WooCommerce Coupons: from n/a through <= 4.7.1. | |
| Aplazada | Media (5.4) | 0.22% | — | 10up Autoshare FOR TwitterAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in 10up Autoshare for Twitter autoshare-for-twitter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Autoshare for Twitter: from n/a through <= 2.3.1. |