Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2829▼ 255 respecto a la semana anterior
Críticas / altas1324▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
23.711 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.39% | — | CapgoAI | 10/9/2026 | 10/9/2026 | capgo.app (npm package `capgo`) through version 12.207.1 does not compare the caller's role rank against the requested role in the validateInvite() function of supabase/functions/_backend/private/invite_new_user_to_org.ts. The POST /private/invite_new_user_to_org endpoint only requires the org.update_user_roles… | |
| Aplazada | Crítica (9.3) | 0.37% | — | CapgoAISupabaseAISupabase PostgrestAI | 10/9/2026 | 30/9/2026 | Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST. A holder of an ordinary Capgo full API key can insert a row with status='active' and enforce_sso=true, bypassing the intended backend SSO provisioning route… | |
| Aplazada | Alta (8.7) | 0.44% | — | CapgoAI | 10/9/2026 | 30/9/2026 | Capgo (capgo.app) backend through 12.242.4 does not validate parent-child delegation when processing the x-limited-key-id header. checkKeyByIdPg() in supabase/functions/_backend/utils/hono_middleware.ts resolves the attacker-supplied numeric API key ID using only the key ID, its expiration state, and the… | |
| Aplazada | Alta (8.7) | 0.52% | 💥 PoC | CapgoAISupabaseAI | 10/9/2026 | 30/9/2026 | Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication). The Edge authorization path allows a password-only Supabase aal1 session to exercise privileged RBAC permissions even when the account has a verified MFA factor that has not been… | |
| Aplazada | Crítica (9.3) | 0.27% | — | CapgoAI | 10/9/2026 | 30/9/2026 | Capgo fails to clean up channel permission overrides when a user's last organization role binding is deleted, leaving stale overrides active. Attackers can retain channel-specific permissions after their base RBAC access has been revoked to perform unauthorized actions like changing production OTA versions. | |
| Aplazada | Media (6.4) | 0.42% | — | Easy Google FontsAI | 10/9/2026 | 10/9/2026 | The Easy Google Fonts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the control_selectors meta field in all versions up to, and including, 2.0.4. This is due to the plugin registering the control_selectors meta field with show_in_rest enabled but without a sanitize_callback, and subsequently… | |
| Aplazada | Alta (7.7) | 0.39% | — | Fortra Goanywhere MFTAI | 9/9/2026 | 10/9/2026 | In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read. | |
| Analizada | Media (6.9) | 0.15% | — | Google Common Expression Language | 9/9/2026 | 23/9/2026 | A user could provide an expression whose string length is longer than the ParserExpressionSizeLimit() configured on the CEL environment, and a memory allocation would occur proportional to the size of the input before the limit would be checked / enforced. | |
| Pendiente de análisis | Crítica (10) | 0.74% | — | Google Cloud Agent Development KITAIPythonAI | 9/9/2026 | 9/9/2026 | A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote attacker to execute arbitrary code using a crafted test session replay. | |
| Aplazada | Media (6.5) | 0.26% | — | Wpmr Google Feed Manager FOR WoocommerceAI | 9/9/2026 | 9/9/2026 | The WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping plugin for WordPress is vulnerable to time-based SQL Injection via the 'feed' parameter in all versions up to, and including, 2.23.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on… | |
| Analizada | Media (4.3) | 0.24% | — | Google Chrome | 9/9/2026 | 9/9/2026 | Information leak in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium) | |
| Analizada | Baja (3.1) | 0.23% | — | Google Chrome | 9/9/2026 | 9/9/2026 | Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (5.4) | 0.23% | — | Google Chrome | 9/9/2026 | 14/9/2026 | Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) | |
| Analizada | Media (5.4) | 0.24% | — | Google Chrome | 9/9/2026 | 9/9/2026 | Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Crítica (9.6) | 0.51% | — | Google Chrome | 9/9/2026 | 10/9/2026 | Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (5.4) | 0.26% | — | Google Chrome | 9/9/2026 | 9/9/2026 | UI misrepresentation in FullScreen in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | |
| Analizada | Baja (3.1) | 0.24% | — | Google Chrome | 9/9/2026 | 9/9/2026 | Incorrect authorization in PushAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Media (4.3) | 0.25% | — | Google Chrome | 9/9/2026 | 9/9/2026 | Incorrect authorization in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Crítica (9.6) | 0.46% | — | Google Chrome | 9/9/2026 | 10/9/2026 | Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Media (5.4) | 0.23% | — | Google Chrome | 9/9/2026 | 10/9/2026 | UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Alta (8.3) | 0.40% | — | Google Chrome | 9/9/2026 | 10/9/2026 | Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Baja (3.4) | 0.25% | — | Google Chrome | 9/9/2026 | 9/9/2026 | Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Crítica (9.6) | 0.53% | — | Google Chrome | 9/9/2026 | 10/9/2026 | Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Media (5.4) | 0.23% | — | Google Chrome | 9/9/2026 | 10/9/2026 | Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | |
| Analizada | Alta (8.3) | 0.39% | — | Google Chrome | 9/9/2026 | 10/9/2026 | Incorrect authorization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) |