Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2769▼ 305 respecto a la semana anterior
Críticas / altas1294▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
23.388 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.33% | — | Protobufjs Project Protobufjs | 13/5/2026 | 17/6/2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a minimal UTF-8 decoder that accepted overlong UTF-8 byte sequences and decoded them to their canonical characters instead of replacing them. An attacker who can provide protobuf binary data decoded… | |
| Analizada | Alta (7.8) | 0.19% | — | Protobufjs Project Protobufjs-cli | 13/5/2026 | 17/6/2026 | protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbts invoked JSDoc by building a shell command string from input file paths and executing it through child_process.exec. File paths containing shell metacharacters could therefore be interpreted by the shell instead of being passed to… | |
| Modificada | Media (6.5) | 0.46% | 💥 PoC | Openplcproject Openplc V3 Firmware | 13/5/2026 | 5/7/2026 | A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program compiled from glue_generator.cpp does not perform any validation on the file path parameters passed via the command line. The user-controlled input parameters are directly passed to the underlying file… | |
| Analizada | Media (6.5) | 0.16% | — | Warpgate Project Warpgate | 12/5/2026 | 17/6/2026 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.23.3, the SSO flow does not validate the state parameter, which makes it possible for an attacker to trick a user into logging into the attacker's account, possibly convincing them to perform sensitive actions on the attacker's account… | |
| Pendiente de análisis | Alta (8.8) | 0.68% | — | Cosyvoice Project CosyvoiceAIPytorchAI | 12/5/2026 | 17/6/2026 | The CosyVoice project thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its model loading process. When loading model files (.pt) from a user-specified directory (via the --model_dir argument), the code uses torch.load() without the… | |
| Analizada | Media (6.1) | 0.14% | — | Zephyrproject Zephyr | 12/5/2026 | 8/7/2026 | Issuing an ICMP ping via the `net ping` shell command to a device's own IPv4 address causes the network stack to recursively re-enter the input path on the same system work-queue stack. Because the destination is recognized as a local address, both the echo request and the resulting echo reply are processed inline… | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa💥 PoC | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Lfprojects Mlflow | 11/5/2026 | 28/8/2026 | A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 and earlier allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem. The issue arises when a `CreateModelVersion` request includes the tag… | |
| Analizada | Media (6.5) | 0.50% | — | Pyload-ng Project Pyload-ng | 11/5/2026 | 17/6/2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, when passing a folder name in the set_package_data() API function call inside the data object with key "_folder", there is no sanitization at all, allowing a user with Perms.MODIFY to specify arbitrary directories as download… | |
| Analizada | Media (6.5) | 0.42% | — | Pyload-ng Project Pyload-ng | 11/5/2026 | 17/6/2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, package folder names are sanitized using insufficient string replacement. The pattern ....// becomes .._ after replacement (partial removal), leaving .. which can be exploited when the path is later resolved by the OS. This… | |
| Analizada | Alta (8.3) | 0.39% | — | Pyload-ng Project Pyload-ng | 11/5/2026 | 17/6/2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/__init__.py gates security-sensitive options behind a hand-maintained allowlist ADMIN_ONLY_CORE_OPTIONS. The allowlist contains ("proxy",… | |
| Analizada | Media (6.8) | 0.19% | — | Pyload-ng Project Pyload-ng | 11/5/2026 | 17/6/2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/__init__.py gates security-sensitive options behind a hand-maintained allowlist ADMIN_ONLY_CORE_OPTIONS. The option ("general",… | |
| Analizada | Alta (7.1) | 0.29% | — | Lfprojects Mlflow | 11/5/2026 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in MLflow versions prior to 3.9.0. The `_create_webhook()` function in `mlflow/server/handlers.py` accepts a user-controlled `url` parameter without validation, and the `_send_webhook_request()` function in `mlflow/webhooks/delivery.py` sends HTTP POST requests… | |
| Analizada | Media (5.3) | 0.24% | — | Zephyrproject Zephyr | 11/5/2026 | 8/7/2026 | Zephyr sockets created with `IPPROTO_TLS_1_3` can still negotiate a TLS 1.2 connection when both TLS versions are enabled in Kconfig, because the socket-level protocol selection is not propagated to mbedTLS (e.g. via `mbedtls_ssl_conf_min_tls_version`). The ClientHello advertises both versions and the peer can… | |
| Aplazada | Media (6.5) | 0.48% | — | NET Cidr Lite Project NET Cidr LiteAI | 10/5/2026 | 24/7/2026 | Las versiones de Net::CIDR::Lite anteriores a 0.24 para Perl no consideran adecuadamente los caracteres cero superfluos en los valores de máscara CIDR, lo que puede permitir la omisión de ACL de IP. Formas de máscara como '/00' y '/01' pasan la validación y se analizan al mismo prefijo que su valor sin relleno. Véase… | |
| Aplazada | Media (6.5) | 0.48% | — | NET Cidr Lite Project NET Cidr LiteAI | 10/5/2026 | 24/7/2026 | Las versiones de Net::CIDR::Lite anteriores a la 0.24 para Perl no validan correctamente las entradas de dirección IP y máscara CIDR, lo que puede permitir la omisión de ACL de IP. Las entradas que contienen un salto de línea final o caracteres de dígitos no ASCII pasan los validadores, pero luego son recodificadas… | |
| Analizada | Media (5.1) | 0.24% | — | Avatar Uploader Project Avatar Uploader | 10/5/2026 | 24/7/2026 | Drupal avatar_uploader 7.x-1.0-beta8 contiene una vulnerabilidad de cross-site scripting reflejada que permite a atacantes no autenticados inyectar scripts maliciosos manipulando el parámetro file. Los atacantes pueden crear URL con cargas útiles de script en el parámetro file de avatar_uploader.pages.inc para… | |
| Aplazada | Media (5.1) | 0.20% | — | ProjectsendAI | 10/5/2026 | 25/7/2026 | Projectsend r1295 contiene una vulnerabilidad de cross-site scripting almacenado que permite a atacantes autenticados inyectar scripts maliciosos al enviar entradas manipuladas en el parámetro 'name' de files-edit.php. Los atacantes pueden inyectar cargas útiles de JavaScript a través del campo de nombre de archivo… | |
| Modificada | Alta (7.5) | 0.48% | — | Libexpat Project Libexpat | 10/5/2026 | 16/9/2026 | En libexpat antes de 2.8.1, la complejidad computacional de las comprobaciones de colisión de nombres de atributos permite una denegación de servicio a través de una entrada XML manipulada de tamaño moderado. | |
| Analizada | Alta (7.5) | 0.76% | — | Russh Project RusshWarpgate Project Warpgate | 8/5/2026 | 17/6/2026 | Russh is a Rust SSH client & server library. Prior to version 0.60.1, a pre-authentication denial-of-service vulnerability exists in the server's keyboard-interactive authentication handler. A malicious client can crash any russh-based server that implements keyboard-interactive auth (e.g., for 2FA/TOTP) with a single… | |
| Analizada | Alta (7.8) | 0.28% | — | Phpunit Project Phpunit | 8/5/2026 | 17/6/2026 | PHPUnit is a testing framework for PHP. In versions 12.5.21 and 13.1.5, PHPUnit forwards PHP INI settings to child processes (used for isolated/PHPT test execution) as -d name=value command-line arguments without neutralizing INI metacharacters. Because PHP's INI parser interprets " as a string delimiter, ; as the… | |
| Analizada | Alta (7.4) | 0.26% | — | Go-git Project Go-git | 8/5/2026 | 17/6/2026 | go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-git may leak HTTP authentication credentials when following redirects during smart-HTTP clone and fetch operations. This issue has been patched in versions 5.18.0 and 6.0.0-alpha.2. | |
| Analizada | Media (5.3) | 0.23% | — | Uriparser Project Uriparser | 8/5/2026 | 17/6/2026 | In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal. | |
| Analizada | Media (5.3) | 0.23% | — | Uriparser Project Uriparser | 8/5/2026 | 17/6/2026 | In uriparser before 1.0.2, there is pointer difference truncation to int in various places. | |
| Modificada | Crítica (9.4) | 0.65% | — | Electerm Project Electerm | 8/5/2026 | 17/6/2026 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before 3.8.15, electerm is vulnerable to arbitrary local code execution via deep links, CLI --opts, or crafted shortcuts. Exploit requires clicking a crafted electerm://... link or opening a crafted… |