Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2712▼ 359 respecto a la semana anterior
Críticas / altas1261▼ 231 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
–

23.384 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.1)0.46%—Misp-project Misp20/5/202623/7/2026
El punto final de informes CSP tenía la intención de limitar los informes CSP registrados a 1 KB, pero permitió incorrectamente informes de hasta 1 MB antes del truncamiento. En implementaciones donde el punto final es accesible por clientes no confiables, esto podría permitir a los atacantes generar un volumen…
AnalizadaAlta (8.3)0.30%—Misp-project Misp20/5/202623/7/2026
Una vulnerabilidad fue identificada en el flujo de trabajo de creación de propuestas de ShadowAttribute. La acción de añadir aceptaba datos de solicitud de ShadowAttribute controlados por el usuario sin eliminar el campo 'id' antes de guardar el registro. Debido a que el framework subyacente trata una clave primaria…
AnalizadaCrítica (9.8)0.49%—Date Ical Project Date Ical19/5/202623/7/2026
Vulnerabilidad por falta de autorización en Drupal Date iCal permite la navegación forzada. Este problema afecta a Date iCal: desde 0.0.0 hasta antes de 4.0.15.
AnalizadaMedia (5.4)0.23%—Colorbox Inline Project Colorbox Inline19/5/202623/7/2026
La vulnerabilidad de Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') en Drupal Colorbox Inline permite cross-site scripting (XSS). Este problema afecta a Colorbox Inline: desde 0.0.0 hasta antes de 2.1.1.
AnalizadaMedia (6.1)0.25%—Obfuscate Project Obfuscate19/5/202624/7/2026
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en Drupal Obfuscate permite cross-site scripting (XSS). Este problema afecta a Obfuscate: desde 0.0.0 anterior a 2.0.2.
AnalizadaMedia (6.5)0.29%—Faraday Project Faraday19/5/202624/7/2026
Faraday es una capa de abstracción de biblioteca cliente HTTP que proporciona una interfaz común sobre muchos adaptadores. Las versiones 2.0.0 a 2.14.1 aún permiten la anulación de host relativa al protocolo cuando el objetivo de la solicitud se pasa como un objeto URI (en lugar de una cadena) a…
ModificadaCrítica (9.6)0.41%—Lfprojects Mlflow19/5/202615/7/2026
In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints. This vulnerability allows a remote attacker to exploit cross-origin requests from a malicious webpage to interact with the MLflow Assistant running on a victim's local machine. By bypassing the…
AnalizadaMedia (5.1)0.29%—Glpi-project Glpi19/5/202624/7/2026
GLPI es un paquete de software gratuito de gestión de activos y TI. En las versiones 11.0.0 a la 11.0.6, un usuario autenticado con permiso de LECTURA de formularios puede exportar la estructura de formularios no autorizados. Este problema ha sido solucionado en la versión 11.0.7.
AnalizadaAlta (7.8)0.16%—Lfprojects Mlflow18/5/202624/7/2026
En versiones de mlflow/mlflow anteriores a la 3.11.0, la función 'get_or_create_nfs_tmp_dir()' en 'mlflow/utils/file_utils.py' crea directorios temporales con permisos de escritura para todos (0o777), y la función '_create_model_downloading_tmp_dir()' en 'mlflow/pyfunc/__init__.py' crea directorios con permisos de…
AplazadaMedia (5.5)0.41%—Projectworlds Hospital-management-system-in-phpAI18/5/202617/6/2026
A flaw has been found in projectworlds hospital-management-system-in-php 1.0. Affected by this vulnerability is the function getAllPatientDetail of the file update_info.php of the component GET Parameter Handler. Executing a manipulation of the argument appointment_no can lead to sql injection. The attack may be…
AplazadaCrítica (9.8)0.55%—Crypt Openssl Pkcs12 Project Crypt Openssl Pkcs12AI17/5/202617/6/2026
Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs. Password parameters in PKCS12.xs are declared char *, which routes through Perl's default typemap to SvPV_nolen. The Perl length is discarded. The C code (or OpenSSL internally) calls strlen() on the buffer. Any password…
ModificadaAlta (7.5)0.68%—WS Project WS15/5/202611/9/2026
ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.
AnalizadaAlta (8.6)1.4%💥 ExploitLfprojects Mlflow15/5/202617/6/2026
A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when the server is started with authentication enabled (`--app-name basic-auth`) and served via uvicorn (ASGI). The FastAPI permission middleware only enforces authentication on `/gateway/` routes,…
AnalizadaBaja (2.1)0.27%—Lfprojects MCP Registry14/5/202617/6/2026
The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.6, the client-side and server-side GitHub OIDC flow is bound only to a global audience string, not to the specific registry instance being targeted. On the client side, the publisher always appends…
AplazadaNinguna (0)0.44%—Lfprojects MCP RegistryAI14/5/202617/6/2026
The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. From 1.1.0 to 1.7.4, the TrailingSlashMiddleware in internal/api/server.go is vulnerable to an open redirect attack. An attacker can craft a URL with a protocol-relative path (e.g., //evil.com/) that, after trailing…
AplazadaBaja (3.5)0.25%—Lfprojects MCP RegistryAI14/5/202617/6/2026
The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.9, OCI ownership validation skips label-match check when upstream OCI registry returns HTTP 429, letting any authenticated publisher bind their io.github.<user>/* namespace to OCI images they do not…
ModificadaMedia (6.3)0.29%—Lfprojects MCP Registry14/5/202617/6/2026
The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.7, the Registry's HTTP-based namespace verification (POST /v0/auth/http, POST /v0.1/auth/http) uses safeDialContext (internal/api/handlers/v0/auth/http.go:67-110) to refuse dialling private/internal…
AnalizadaMedia (5.1)0.24%—Lfprojects MCP Registry14/5/202617/6/2026
The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.7, the public catalogue UI served at GET / (file internal/api/handlers/v0/ui_index.html) is vulnerable to stored cross-site scripting via the server.websiteUrl field of any published server.json.…
AplazadaMedia (5.1)0.44%—Glpi-project OrderAI14/5/202617/6/2026
Stored Cross-Site Scripting (XSS) in Stel Order v3.25.1 and earlier, located at the ‘/app/FrontController’ endpoint via the ‘legalName’ and ‘employeeID’ parameters. The lack of proper input sanitization allows an attacker to inject malicious code that is persistently stored in the database. When other users or…
AplazadaAlta (8.2)0.85%—Plug Project PlugAI14/5/202617/6/2026
Allocation of Resources Without Limits or Throttling vulnerability in plug_project plug allows denial of service via unbounded buffer accumulation in multipart header parsing. 'Elixir.Plug.Conn':read_part_headers/2 in lib/plug/conn.ex does not obey its :length parameter. There is no upper bound on the size of the…
AnalizadaCrítica (9.3)0.76%💥 ExploitMisp-project Misp13/5/202622/6/2026
MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed in the handling of user-controlled ordering parameters in the event and shadow attribute listing endpoints. The affected code accepted order or sort values from request parameters and incorporated…
AnalizadaAlta (8.6)0.58%—Misp-project Misp13/5/202622/6/2026
MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, an improper access control vulnerability in the authentication key reset functionality allowed an authenticated organization administrator to reset authentication keys belonging to site administrator accounts within the same…
AnalizadaMedia (5.3)0.29%—Misp-project Misp13/5/202622/6/2026
MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, MISP Collections did not enforce RFC 4122 UUID validation on the uuid field. As a result, a user able to create or modify Collection records could submit malformed UUID values, potentially causing integrity issues or unexpected behaviour…
ModificadaCrítica (9.8)0.90%—VM2 Project VM213/5/20267/9/2026
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield* expression inside an async generator. When the generator is closed using the return function, the value is awaited on and exceptions thrown in the then call will be caught by the runtime and passed…
ModificadaCrítica (9.8)0.71%—VM2 Project VM213/5/20267/9/2026
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2.