Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
367 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5) | 0.43% | — | GhostAI | 4/8/2026 | 8/9/2026 | Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting in XSS in post content. This issue is fixed in version 6.54.1. | |
| Aplazada | Media (6.3) | 0.22% | — | Ghost CLIAINginxAI | 31/7/2026 | 9/9/2026 | Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rate-limiting controls by manipulating the X-Forwarded-For header through a misconfigured Nginx configuration. Attackers can append attacker-controlled values to the header chain using the… | |
| Aplazada | Media (5.4) | 0.26% | — | Wpplugins Hide MY WP GhostAI | 30/7/2026 | 30/7/2026 | The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does not verify that client IP information comes from a trusted proxy before trusting attacker-controllable HTTP headers, allowing unauthenticated attackers to spoof their IP address to bypass the WP Ghost (Hide My WP Ghost) WordPress plugin before… | |
| Pendiente de análisis | Baja (2) | 0.14% | — | Ghost Sqlite3AI | 28/7/2026 | 30/7/2026 | sqlite3 provides Ruby bindings for the SQLite3 embedded database. From 2.1.0 to 2.9.4, the callbacks used for SQLite aggregate functions can be freed while still referenced during aggregation, resulting in a use-after-free. This issue is fixed in version 2.9.5. | |
| Pendiente de análisis | Baja (2) | 0.14% | — | Ghost Sqlite3AI | 28/7/2026 | 30/7/2026 | sqlite3 provides Ruby bindings for the SQLite3 embedded database. In version 2.9.4 and earlier, redefining a SQLite function with a different arity frees the previously registered function handler while SQLite may still reference it, resulting in a use-after-free. This issue is fixed in version 2.9.5. | |
| Aplazada | Alta (7.4) | 0.39% | — | Wpplugins Hide MY WP GhostAI | 27/7/2026 | 27/7/2026 | Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions. | |
| Aplazada | Alta (8.7) | 0.22% | — | Ghostrobotics Vision 60AI | 27/7/2026 | 27/7/2026 | The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Vision 60 robot (APK v5.5.0) exposes the system to man-in-the-middle attacks. An attacker located on the local network can use ARP spoofing and selective traffic blocking techniques to intercept and… | |
| Aplazada | Alta (7.7) | 0.19% | — | Ghostrobotics Vision 60AI | 27/7/2026 | 27/7/2026 | An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run without proper client validation or session integrity checks. An attacker with a modified version of the app can connect to the robot during an active, legitimate session.… | |
| Aplazada | Alta (8.7) | 0.31% | — | Ghostrobotics Vision 60AIGhostrobotics Vision 60 Mobile APPAI | 27/7/2026 | 27/7/2026 | A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated attacker connected to the device's internal Wi-Fi network to gain unrestricted access to the web administration interface and the HTTP API. Due to the lack of authorization mechanisms, the attacker can… | |
| Aplazada | Media (5.3) | 0.40% | — | GhostAI | 9/7/2026 | 14/7/2026 | Ghost is a Node.js content management system. From 6.27.0 before 6.44.0, Ghost's public donation checkout flow allowed an unauthenticated attacker to control donation checkout metadata and obtain full paid gift memberships for a minimal payment without exposing customer or member data or stealing money from a site or… | |
| Aplazada | Alta (8.7) | 0.59% | — | GhostfolioAI | 7/7/2026 | 17/9/2026 | The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeUserId filtering, allowing unauthenticated access to full portfolio data. Attackers with a private access ID can retrieve sensitive portfolio information including holdings, quantities, buy prices,… | |
| Aplazada | Media (5.3) | 0.34% | — | GhostfolioAI | 7/7/2026 | 17/9/2026 | Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field when processing the Impersonation-Id header, allowing read-only access grantees to modify portfolio holding tags. Attackers with valid read-only share tokens can assign or remove tags on victim… | |
| Aplazada | Media (6.5) | 0.22% | — | Ghost KITAI | 26/6/2026 | 26/6/2026 | Contributor Cross Site Scripting (XSS) in Ghost Kit <= 3.6.0 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Ghost ActivitypubAI | 24/6/2026 | 25/6/2026 | @tryghost/activitypub is Ghost’s social/federation client app. Prior to 3.1.0, the ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server. This vulnerability is fixed in 3.1.0. | |
| Aplazada | Media (5.3) | 0.36% | — | GhostAINodejsAISqliteAIMysqlAI | 24/6/2026 | 25/6/2026 | Ghost is a Node.js content management system. From 5.46.1 until 6.21.2, the validation applied to filters on the public API endpoints could be partially bypassed, making it possible to reveal private fields via a brute force attack. If SQLite was used as the database password hashes were fully accessible. If MySQL was… | |
| Aplazada | Media (5.4) | 0.23% | — | GhostAI | 24/6/2026 | 25/6/2026 | Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, insufficient validation of the client-supplied Content-Type on Ghost's Admin API file upload endpoint allowed uploaded files to be served from the site with an attacker-chosen content type on S3/GCS storage backends. On installations that serve… | |
| Aplazada | Media (5.3) | 0.34% | — | GhostAI | 24/6/2026 | 25/6/2026 | Ghost is a Node.js content management system. From 5.18.0 until 6.21.1, a discrepancy in responses from the members signin endpoints made it possible for an unauthenticated attacker to determine whether a given email address belongs to a registered member of a Ghost site. This vulnerability is fixed in 6.21.1. | |
| Aplazada | Media (5.4) | 0.21% | — | GhostAI | 24/6/2026 | 25/6/2026 | Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, when re-rendering posts, Ghost would refetch missing image dimensions by issuing an outbound HTTP request to the URL stored on an image card — without restricting that URL to trusted image hosts. An authenticated staff user able to create or edit… | |
| Aplazada | Media (4) | 0.21% | — | GhostAI | 24/6/2026 | 25/6/2026 | Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, Ghost’s private-IP check for outbound HTTP requests could be bypassed via DNS rebinding, allowing an attacker to coerce the Ghost server into reaching hosts on internal networks through features that issue external fetches. This vulnerability is… | |
| Aplazada | Media (5.8) | 0.33% | — | GhostAI | 24/6/2026 | 25/6/2026 | Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, when making an external request, it is possible to bypass the IP filter that ensures the request isn't going to an internal service using an IPv6 literal which maps to a private IPv4 address. This vulnerability is fixed in 6.21.1. | |
| Aplazada | Crítica (9.6) | 0.45% | — | GhostAI | 24/6/2026 | 25/6/2026 | Ghost is a Node.js content management system. From until 6.37.0, when Ghost is behind a shared caching layer that results in cached content being shared between different visitors, an unauthenticated user could send an x-ghost-preview header that altered the rendered frontend response. In affected cache… | |
| Aplazada | Media (4.7) | 0.28% | — | Wpplugins Hide MY WP GhostAI | 8/4/2026 | 24/7/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in John Darrel Hide My WP Ghost hide-my-wp allows Phishing.This issue affects Hide My WP Ghost: from n/a through < 7.0.00. | |
| Analizada | Alta (8.8) | 0.51% | — | Ghostty | 10/3/2026 | 17/6/2026 | Ghostty is a cross-platform terminal emulator. Ghostty allows control characters such as 0x03 (Ctrl+C) in pasted and dropped text. These can be used to execute arbitrary commands in some shell environments. This attack requires an attacker to convince the user to copy and paste or drag and drop malicious text. The… | |
| Analizada | Alta (8.8) | 0.19% | — | Ghost | 7/3/2026 | 17/6/2026 | Ghost is a Node.js content management system. From version 5.101.6 to 6.19.2, incomplete CSRF protections around /session/verify made it possible to use OTCs in login sessions different from the requesting session. In some scenarios this might have made it easier for phishers to take over a Ghost site. This issue has… | |
| Analizada | Crítica (9.3) | 0.63% | — | Ghostfolio | 6/3/2026 | 17/6/2026 | Ghostfolio is an open source wealth management software. Prior to version 2.244.0, by bypassing symbol validation, an attacker can execute arbitrary SQL commands via the getHistorical() method, potentially allowing them to read, modify, or delete sensitive financial data for all users in the database. This issue has… |