Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2712▼ 359 respecto a la semana anterior
Críticas / altas1261▼ 231 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
23.384 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.46% | — | Misp-project Misp | 20/5/2026 | 23/7/2026 | El punto final de informes CSP tenía la intención de limitar los informes CSP registrados a 1 KB, pero permitió incorrectamente informes de hasta 1 MB antes del truncamiento. En implementaciones donde el punto final es accesible por clientes no confiables, esto podría permitir a los atacantes generar un volumen… | |
| Analizada | Alta (8.3) | 0.30% | — | Misp-project Misp | 20/5/2026 | 23/7/2026 | Una vulnerabilidad fue identificada en el flujo de trabajo de creación de propuestas de ShadowAttribute. La acción de añadir aceptaba datos de solicitud de ShadowAttribute controlados por el usuario sin eliminar el campo 'id' antes de guardar el registro. Debido a que el framework subyacente trata una clave primaria… | |
| Analizada | Crítica (9.8) | 0.49% | — | Date Ical Project Date Ical | 19/5/2026 | 23/7/2026 | Vulnerabilidad por falta de autorización en Drupal Date iCal permite la navegación forzada. Este problema afecta a Date iCal: desde 0.0.0 hasta antes de 4.0.15. | |
| Analizada | Media (5.4) | 0.23% | — | Colorbox Inline Project Colorbox Inline | 19/5/2026 | 23/7/2026 | La vulnerabilidad de Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') en Drupal Colorbox Inline permite cross-site scripting (XSS). Este problema afecta a Colorbox Inline: desde 0.0.0 hasta antes de 2.1.1. | |
| Analizada | Media (6.1) | 0.25% | — | Obfuscate Project Obfuscate | 19/5/2026 | 24/7/2026 | Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en Drupal Obfuscate permite cross-site scripting (XSS). Este problema afecta a Obfuscate: desde 0.0.0 anterior a 2.0.2. | |
| Analizada | Media (6.5) | 0.29% | — | Faraday Project Faraday | 19/5/2026 | 24/7/2026 | Faraday es una capa de abstracción de biblioteca cliente HTTP que proporciona una interfaz común sobre muchos adaptadores. Las versiones 2.0.0 a 2.14.1 aún permiten la anulación de host relativa al protocolo cuando el objetivo de la solicitud se pasa como un objeto URI (en lugar de una cadena) a… | |
| Modificada | Crítica (9.6) | 0.41% | — | Lfprojects Mlflow | 19/5/2026 | 15/7/2026 | In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints. This vulnerability allows a remote attacker to exploit cross-origin requests from a malicious webpage to interact with the MLflow Assistant running on a victim's local machine. By bypassing the… | |
| Analizada | Media (5.1) | 0.29% | — | Glpi-project Glpi | 19/5/2026 | 24/7/2026 | GLPI es un paquete de software gratuito de gestión de activos y TI. En las versiones 11.0.0 a la 11.0.6, un usuario autenticado con permiso de LECTURA de formularios puede exportar la estructura de formularios no autorizados. Este problema ha sido solucionado en la versión 11.0.7. | |
| Analizada | Alta (7.8) | 0.16% | — | Lfprojects Mlflow | 18/5/2026 | 24/7/2026 | En versiones de mlflow/mlflow anteriores a la 3.11.0, la función 'get_or_create_nfs_tmp_dir()' en 'mlflow/utils/file_utils.py' crea directorios temporales con permisos de escritura para todos (0o777), y la función '_create_model_downloading_tmp_dir()' en 'mlflow/pyfunc/__init__.py' crea directorios con permisos de… | |
| Aplazada | Media (5.5) | 0.41% | — | Projectworlds Hospital-management-system-in-phpAI | 18/5/2026 | 17/6/2026 | A flaw has been found in projectworlds hospital-management-system-in-php 1.0. Affected by this vulnerability is the function getAllPatientDetail of the file update_info.php of the component GET Parameter Handler. Executing a manipulation of the argument appointment_no can lead to sql injection. The attack may be… | |
| Aplazada | Crítica (9.8) | 0.55% | — | Crypt Openssl Pkcs12 Project Crypt Openssl Pkcs12AI | 17/5/2026 | 17/6/2026 | Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs. Password parameters in PKCS12.xs are declared char *, which routes through Perl's default typemap to SvPV_nolen. The Perl length is discarded. The C code (or OpenSSL internally) calls strlen() on the buffer. Any password… | |
| Modificada | Alta (7.5) | 0.68% | — | WS Project WS | 15/5/2026 | 11/9/2026 | ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1. | |
| Analizada | Alta (8.6) | 1.4% | 💥 Exploit | Lfprojects Mlflow | 15/5/2026 | 17/6/2026 | A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when the server is started with authentication enabled (`--app-name basic-auth`) and served via uvicorn (ASGI). The FastAPI permission middleware only enforces authentication on `/gateway/` routes,… | |
| Analizada | Baja (2.1) | 0.27% | — | Lfprojects MCP Registry | 14/5/2026 | 17/6/2026 | The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.6, the client-side and server-side GitHub OIDC flow is bound only to a global audience string, not to the specific registry instance being targeted. On the client side, the publisher always appends… | |
| Aplazada | Ninguna (0) | 0.44% | — | Lfprojects MCP RegistryAI | 14/5/2026 | 17/6/2026 | The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. From 1.1.0 to 1.7.4, the TrailingSlashMiddleware in internal/api/server.go is vulnerable to an open redirect attack. An attacker can craft a URL with a protocol-relative path (e.g., //evil.com/) that, after trailing… | |
| Aplazada | Baja (3.5) | 0.25% | — | Lfprojects MCP RegistryAI | 14/5/2026 | 17/6/2026 | The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.9, OCI ownership validation skips label-match check when upstream OCI registry returns HTTP 429, letting any authenticated publisher bind their io.github.<user>/* namespace to OCI images they do not… | |
| Modificada | Media (6.3) | 0.29% | — | Lfprojects MCP Registry | 14/5/2026 | 17/6/2026 | The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.7, the Registry's HTTP-based namespace verification (POST /v0/auth/http, POST /v0.1/auth/http) uses safeDialContext (internal/api/handlers/v0/auth/http.go:67-110) to refuse dialling private/internal… | |
| Analizada | Media (5.1) | 0.24% | — | Lfprojects MCP Registry | 14/5/2026 | 17/6/2026 | The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.7, the public catalogue UI served at GET / (file internal/api/handlers/v0/ui_index.html) is vulnerable to stored cross-site scripting via the server.websiteUrl field of any published server.json.… | |
| Aplazada | Media (5.1) | 0.44% | — | Glpi-project OrderAI | 14/5/2026 | 17/6/2026 | Stored Cross-Site Scripting (XSS) in Stel Order v3.25.1 and earlier, located at the ‘/app/FrontController’ endpoint via the ‘legalName’ and ‘employeeID’ parameters. The lack of proper input sanitization allows an attacker to inject malicious code that is persistently stored in the database. When other users or… | |
| Aplazada | Alta (8.2) | 0.85% | — | Plug Project PlugAI | 14/5/2026 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in plug_project plug allows denial of service via unbounded buffer accumulation in multipart header parsing. 'Elixir.Plug.Conn':read_part_headers/2 in lib/plug/conn.ex does not obey its :length parameter. There is no upper bound on the size of the… | |
| Analizada | Crítica (9.3) | 0.76% | 💥 Exploit | Misp-project Misp | 13/5/2026 | 22/6/2026 | MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed in the handling of user-controlled ordering parameters in the event and shadow attribute listing endpoints. The affected code accepted order or sort values from request parameters and incorporated… | |
| Analizada | Alta (8.6) | 0.58% | — | Misp-project Misp | 13/5/2026 | 22/6/2026 | MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, an improper access control vulnerability in the authentication key reset functionality allowed an authenticated organization administrator to reset authentication keys belonging to site administrator accounts within the same… | |
| Analizada | Media (5.3) | 0.29% | — | Misp-project Misp | 13/5/2026 | 22/6/2026 | MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, MISP Collections did not enforce RFC 4122 UUID validation on the uuid field. As a result, a user able to create or modify Collection records could submit malformed UUID values, potentially causing integrity issues or unexpected behaviour… | |
| Modificada | Crítica (9.8) | 0.90% | — | VM2 Project VM2 | 13/5/2026 | 7/9/2026 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield* expression inside an async generator. When the generator is closed using the return function, the value is awaited on and exceptions thrown in the then call will be caught by the runtime and passed… | |
| Modificada | Crítica (9.8) | 0.71% | — | VM2 Project VM2 | 13/5/2026 | 7/9/2026 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2. |