Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3340▲ 436 respecto a la semana anterior
Críticas / altas1491▲ 179 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)592▲ 119 respecto a la semana anterior
1012 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.4) | 1.0% | — | 9routerAI | 23/7/2026 | 28/7/2026 | 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL_ONLY network gate via a spoofed Host header, and unvalidated arguments passed to child_process.spawn() when registering MCP plugins. A remote,… | |
| Aplazada | Alta (8.3) | 0.46% | — | 9routerAI | 23/7/2026 | 28/7/2026 | 9Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The endpoint accepts a user-controlled url parameter and passes it to a configured external scraping provider (Firecrawl, Jina Reader, Tavily, or Exa) to fetch content. The URL is only validated as… | |
| Analizada | Alta (7.4) | 0.34% | — | Oracle Mysql Router | 21/7/2026 | 28/7/2026 | Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are affected are 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise MySQL Router. Successful attacks of this… | |
| Analizada | Alta (7.5) | 0.47% | — | Oracle Mysql Router | 21/7/2026 | 28/7/2026 | Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are affected are 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise MySQL Router. Successful attacks of this… | |
| Aplazada | Crítica (9.1) | 0.66% | — | Uz801 V2.1AI4G LTE RouterAI | 17/7/2026 | 23/7/2026 | An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component | |
| Aplazada | Alta (8.8) | 1.3% | — | 9routerAI | 15/7/2026 | 16/7/2026 | 9Router is an AI router & token saver. Prior to 0.5.2, 9Router allows a remote authenticated attacker to achieve arbitrary code execution on the host operating system by combining a Host header bypass of localhost-only routes with unvalidated MCP plugin args passed to child_process.spawn(), allowing malicious custom… | |
| Aplazada | Alta (8.7) | 0.52% | — | 9routerAI | 15/7/2026 | 16/7/2026 | 9Router is an AI router & token saver. Prior to 0.5.4, the PATCH /api/settings endpoint writes the entire request body to persistent settings without a field whitelist, allowing an authenticated user to set security-critical fields such as requireLogin and disable authentication for the whole application, exposing… | |
| Aplazada | Media (6.4) | 0.29% | — | 9routerAI | 15/7/2026 | 16/7/2026 | 9Router is an AI router & token saver. Prior to 0.5.6, the Kiro API-key validation endpoint POST /api/oauth/kiro/api-key builds an upstream URL using a user-controlled region value, allowing an authenticated attacker to supply a crafted region such as kiro-canary.local:8443# and cause 9Router to send the Kiro… | |
| Aplazada | Alta (7.5) | 0.36% | — | 9routerAI | 15/7/2026 | 16/7/2026 | 9Router is an AI router & token saver. In 0.4.45 and earlier, 9Router's src/dashboardGuard.js local-only access gate used Host and Origin headers in isLocalRequest() to protect /api/mcp/*, /api/tunnel/*, and /api/cli-tools/*, allowing header spoofing in reverse proxy or tunnel deployments to reach MCP child process… | |
| Aplazada | Crítica (9.8) | 0.60% | — | 9routerAI | 15/7/2026 | 16/7/2026 | 9Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-default-secret-change-me in src/app/api/auth/login/route.js, src/middleware.js, and later src/lib/auth/dashboardSession.js, allowing attackers to forge an auth_token cookie when JWT_SECRET was unset.… | |
| Aplazada | Crítica (10) | 3.4% | — | 9routerAI | 15/7/2026 | 16/7/2026 | 9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, allowing unauthenticated registration of customPlugins through src/app/api/cli-tools/cowork-settings/route.js and command execution through the MCP bridge. This… | |
| Aplazada | Crítica (9.5) | 0.14% | — | Asus Router FirmwareAI | 15/7/2026 | 29/7/2026 | An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router download and execute arbitrary command via a spoofed server. Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS… | |
| Aplazada | Media (5.9) | 0.50% | — | Asus RouterAI | 15/7/2026 | 15/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of certain ASUS router models allows a remote authenticated user to disclose confidential information via a crafted request that bypasses existing input validation Refer to the ' Security Update for… | |
| Analizada | Alta (8.1) | 0.47% | — | SAP Approuter | 14/7/2026 | 8/9/2026 | SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to… | |
| Analizada | Crítica (9.1) | 0.68% | — | SAP Approuter | 14/7/2026 | 8/9/2026 | Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on… | |
| Pendiente de análisis | Alta (8.4) | 0.21% | — | SaprouterAIMicrosoft WindowsAI | 14/7/2026 | 20/7/2026 | SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code on the system. This could enable the attacker to hijack the DLL loading process and achieve arbitrary code execution. This has high impact on… | |
| Aplazada | Alta (8.7) | 0.62% | — | 9routerAI | 13/7/2026 | 15/7/2026 | 9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attackers to access sensitive user data by sending requests to unprotected API endpoints. Attackers can enumerate paginated request logs and retrieve complete AI conversation histories including system… | |
| Aplazada | Crítica (9.3) | 0.64% | — | 9routerAI | 13/7/2026 | 14/7/2026 | 9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext API keys for all connected AI provider accounts by sending a single unauthenticated request to the /api/usage/stats endpoint. Attackers can exploit the missing… | |
| Aplazada | Crítica (9.3) | 2.9% | — | 9routerAI | 13/7/2026 | 14/7/2026 | 9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any credentials due to missing authentication middleware in the Next.js API routes under src/app/api/providers/*. Attackers can… | |
| Aplazada | Alta (7.5) | 0.58% | — | Mikrotik RouterosAI | 13/7/2026 | 15/7/2026 | An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4 and 7.22.x before v.7.22.2 allows a remote attacker to cause a denial of service via the unflatten() function in libumsg.so. | |
| Aplazada | Alta (8.3) | 0.50% | — | 9routerAI | 10/7/2026 | 10/7/2026 | 9Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* access without an API key, so a same-host reverse proxy that forwards public traffic to the backend through 127.0.0.1 causes src/dashboardGuard.js to misclassify external requests as local. A remote… | |
| Aplazada | Alta (8.2) | 0.32% | — | 9routerAI | 10/7/2026 | 10/7/2026 | 9Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by reading the client-controlled Host header, allowing a remote unauthenticated attacker to send Host: localhost and bypass API-key authentication. In the default configuration, this exposes the /v1 proxy… | |
| Aplazada | Alta (8.6) | 0.61% | — | 9routerAI | 10/7/2026 | 10/7/2026 | 9Router is an AI router & token saver. Prior to 0.5.2, 9router protects /v1, /v1beta, /api/v1, and /api/v1beta in src/dashboardGuard.js but omits /codex before next.config.mjs rewrites /codex/* to /api/v1/responses. A remote unauthenticated attacker can send requests to /codex/* to bypass the API-key gate and cause… | |
| Aplazada | Alta (7.4) | 0.26% | — | 9routerAIOpen-sse TranslatorAI | 10/7/2026 | 13/7/2026 | 9Router is an AI router & token saver. Prior to 0.5.2, 9router validates image URLs by resolving the host before fetching, but open-sse/translator/concerns/image.js performs the later server-side image fetch with a separate DNS resolution. An authenticated attacker with access to the LLM proxy can use a vision-capable… | |
| Aplazada | Alta (7.3) | 0.52% | — | 9routerAI | 10/7/2026 | 10/7/2026 | 9Router is an AI router & token saver. Prior to 0.4.80, the dashboard login rate limiter in src/lib/auth/loginLimiter.js derives the client identity from the attacker-controlled X-Forwarded-For HTTP header, and src/app/api/auth/login/route.js uses that spoofable value for checkLock and recordFail. A remote attacker… |