Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1330▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
23.711 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.29% | — | Google Android | 15/9/2026 | 21/9/2026 | In multiple locations, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (8.8) | 0.28% | — | Google Android | 15/9/2026 | 21/9/2026 | In Vp9DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (8.8) | 0.28% | — | Google Android | 15/9/2026 | 21/9/2026 | In Cellular Modem, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Pendiente de análisis | Alta (8.8) | 0.75% | — | OpencostAIGoogle Cloud PlatformAI | 15/9/2026 | 30/9/2026 | OpenCost provides cost monitoring for Kubernetes workloads and cloud costs. Prior to 1.121.0, the POST /serviceKey endpoint in pkg/costmodel/router.go allows a network client to invoke AddServiceKey without mandatory authentication and submit an arbitrary key form value that is written to the GCP service-account… | |
| Pendiente de análisis | Alta (7.7) | 0.52% | — | Google Cloud Gemini Enterprise Agent Platform SDK FOR PythonAI | 15/9/2026 | 21/9/2026 | Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft. | |
| Aplazada | Media (5.5) | 0.80% | — | DragonflyAI | 15/9/2026 | 30/9/2026 | Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4-rc.3, the scheduler's default unauthenticated v1 gRPC flow accepts attacker-controlled PeerHost.Ip and PeerHost.DownPort values through RegisterPeerTask and ReportPeerResult, storeHost copies those values into… | |
| Aplazada | Baja (2.9) | 0.48% | — | DragonflyAI | 15/9/2026 | 30/9/2026 | Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4, manager/router/router.go registers GET /api/v1/oauth and GET /api/v1/oauth/:id without jwt.MiddlewareFunc() or RBAC(), while manager/handlers/oauth.go returns models.Oauth records and manager/models/oauth.go exposes… | |
| Aplazada | Media (5.3) | 0.45% | — | Governikus AusweisappAI | 15/9/2026 | 16/9/2026 | A weakness has been identified in Governikus AusweisApp up to 2.5.4. Affected is an unknown function of the component StartPAOSResponse Handler. Executing a manipulation of the argument ResultMessage can lead to cross site scripting. The attack can be launched remotely. Upgrading to version 2.5.5 is able to address… | |
| Aplazada | Media (6.9) | 0.47% | — | GoproxyAI | 14/9/2026 | 23/9/2026 | goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements. Attackers can issue CONNECT requests to establish tunnels through the authenticated proxy without providing credentials, enabling arbitrary TCP traffic… | |
| Aplazada | Media (5.3) | 0.37% | — | Djangocrm Django-crmAI | 14/9/2026 | 14/9/2026 | A vulnerability has been found in DjangoCRM django-crm up to 1.2. This vulnerability affects the function BulkUpdateCasesView of the file backend/cases/bulk_views.py of the component Bulk Case Update. The manipulation leads to missing authorization. The attack is possible to be carried out remotely. Upgrading to… | |
| Aplazada | Alta (7.5) | 0.97% | — | AnyqueryAIHashicorp Go-getterAI | 14/9/2026 | 30/9/2026 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtual table modules such as csv_reader and log_reader through its MySQL-compatible server port without authentication, authorization, or directory restrictions. A remote attacker can use SQLite CREATE… | |
| Pendiente de análisis | Alta (7.7) | 0.53% | — | Langchain Langgraph-checkpoint-mongodbAILangchain Langgraph-store-mongodbAI | 14/9/2026 | 30/9/2026 | LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph. Prior to langgraph-checkpoint-mongodb 0.3.0 and langgraph-store-mongodb 0.4.0, MongoDBSaver.list(), MongoDBSaver.alist(), and MongoDBStore.search() incorporate filter dictionaries into MongoDB queries without recursively… | |
| Pendiente de análisis | Alta (8.7) | 0.64% | — | Grpc-goAI | 14/9/2026 | 25/9/2026 | gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host header, while RouteAndProcess in internal/xds/server/routing.go assumes that an… | |
| Aplazada | Alta (7.5) | 0.64% | — | ArgosAI | 14/9/2026 | 30/9/2026 | Argos JavaScript provides official Argos SDKs for JavaScript. Prior to Argos core package version 6.2.1, attacker-controlled CI branch or ref values from GITHUB_HEAD_REF or ARGOS_BRANCH can flow through config.branch and getMergeBaseCommitSha() when hasRemoteContentAccess is false. The gitFetch() and gitMergeBase()… | |
| Aplazada | Media (5.3) | 0.52% | — | Quic-go Webtransport-goAI | 14/9/2026 | 30/9/2026 | webtransport-go is an implementation of the WebTransport protocol. Prior to 0.11.1, Session.parseNextCapsule() in session.go skips an unknown WebTransport capsule on the HTTP/3 request stream by calling io.ReadAll on the capsule reader, retaining the complete declared capsule body in memory. A malicious peer can send… | |
| Pendiente de análisis | Alta (8.1) | 0.18% | — | Zscaler Client ConnectorAIGoogle AndroidAIGoogle ChromeosAI | 14/9/2026 | 18/9/2026 | An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls. | |
| Aplazada | Baja (2.1) | 0.32% | — | Gongshengyue OnlinebooksAI | 13/9/2026 | 16/9/2026 | A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerability affects unknown code of the file src/cn/ylcto/book/servlet/BooksServlet.java of the component listSplit Interface. The manipulation of the argument column results in sql injection. The attack may… | |
| Aplazada | Baja (2) | 0.33% | — | Fengoffice Feng OfficeAI | 13/9/2026 | 14/9/2026 | A vulnerability was determined in Fengoffice Feng Office up to 3.11.13.11. Affected by this vulnerability is the function getTitle of the file application/views/task/add_task.php of the component Task Title Output. Executing a manipulation of the argument og_objects.name can lead to cross site scripting. The attack… | |
| Aplazada | Baja (2) | 0.33% | — | Fengoffice Feng OfficeAI | 13/9/2026 | 16/9/2026 | A vulnerability was found in Fengoffice Feng Office up to 3.11.13.11. Affected is the function update_system_module_order/update_dimension_order of the file application/controllers/MoreController.class.php of the component Reorder Handlers. Performing a manipulation of the argument modules/dims results in sql… | |
| Aplazada | Media (5.5) | 0.41% | — | Fengoffice Feng OfficeAI | 13/9/2026 | 14/9/2026 | A vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11. This impacts the function Contacts::instance->findAll of the file application/models/CompanyWebsite.class.php of the component Legacy API. Such manipulation of the argument auth leads to sql injection. The attack can be launched remotely. The… | |
| Aplazada | Media (6.5) | 0.45% | — | E-goi Smart Marketing SMS AND Newsletters FormsAI | 12/9/2026 | 14/9/2026 | The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to generic SQL Injection via Parameter Name in all versions up to, and including, 5.1.24 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.10% | — | Google Site KITAI | 11/9/2026 | 11/9/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google <= 1.186.0 versions. | |
| Pendiente de análisis | Alta (8.2) | 0.30% | — | Amazon AWS SDK FOR GO V2AI | 11/9/2026 | 11/9/2026 | An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response frame containing a header value type outside the valid range. To remediate this… | |
| Analizada | Alta (7.7) | 0.32% | — | Mongodb | 11/9/2026 | 29/9/2026 | A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An authenticated user holding ordinary read-write privileges on a database may be able to trigger this condition over the… | |
| Aplazada | Alta (7.5) | 0.61% | — | Zju-fast-lab Ego-planner-v2AI | 11/9/2026 | 22/9/2026 | An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via thenteraction between traj_server, poscmd_2_odom, and the EGOReplanFSM emergency recovery logic |