Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
1062 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.50% | — | Ddfourtwo Sentry-selfhosted-mcpAI | 27/8/2026 | 28/8/2026 | A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element is an unknown function of the component raw_sentry_api. The manipulation of the argument endpoint results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the… | |
| Aplazada | Alta (8.8) | 2.0% | — | Teamviewer Full ClientAITeamviewer HostAI | 26/8/2026 | 1/9/2026 | A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to version 15.81.5 allows a remote attacker to execute arbitrary commands in the context of the current user via a specially crafted URL sent through the out-of-session chat feature. Exploitation requires user interaction by clicking… | |
| Aplazada | Media (5.3) | 0.30% | — | GhostwriterAI | 24/8/2026 | 26/8/2026 | Ghostwriter through 7.2.6 does not apply per-object authorization on its report template lint endpoints. RoleBasedAccessControlMixin.test_func returns only request.user.is_active unless a view overrides it, and neither the endpoint that lints a report template nor the endpoint that returns stored lint results provides… | |
| Aplazada | Alta (7.1) | 0.37% | — | GhostwriterAI | 24/8/2026 | 26/8/2026 | Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap endpoint, allowing attackers to attach client-scoped templates from other clients to their own reports. Attackers can exploit sequential template primary keys to enumerate and attach foreign templates, then generate reports to… | |
| Aplazada | Alta (7.3) | 0.12% | — | Remote Utilities HostAI | 21/8/2026 | 26/8/2026 | Remote Utilities Host <=7.7.3.0 sets insecure ACLs on all DLL files in the installation directory (C:\Program Files (x86)\Remote Utilities - Host\), granting FULL CONTROL (F) to the built-in Everyone group (BUILTIN\Everyone, S-1-1-0). A Windows service running as NT AUTHORITY\SYSTEM loads DLLs from this directory. The… | |
| Aplazada | Baja (2.9) | 0.58% | — | Localhostlabs KarakeepAI | 18/8/2026 | 20/8/2026 | A vulnerability was determined in karakeep-app karakeep up to 0.32.0. The impacted element is an unknown function of the file apps/web/server/auth.ts of the component OAuth Sign-In. This manipulation causes improper authentication. It is possible to initiate the attack remotely. The complexity of an attack is rather… | |
| Aplazada | Baja (2.9) | 0.65% | — | Localhostlabs KarakeepAI | 18/8/2026 | 20/8/2026 | A vulnerability was found in karakeep-app karakeep up to 0.32.0. The affected element is the function authorize of the file apps/web/server/auth.ts of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts. The attack may be performed from remote. This… | |
| Aplazada | Alta (8.1) | 0.38% | — | GhostAI | 11/8/2026 | 28/8/2026 | A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author-role users to delete posts owned by other users. The post model permissible() cascade is missing the branch that handles the combined isAuthor and isDestroy condition, causing the authorization check to fall through and… | |
| Aplazada | Media (6.5) | 0.34% | — | GhostfolioAI | 7/8/2026 | 9/9/2026 | Ghostfolio is an open source wealth management software. Prior to version 3.4.0, Ghostfolio's Stripe checkout success-URL handler at `GET /api/v1/subscription/stripe/callback?checkoutSessionId=<id>` retrieves the Stripe Checkout Session by ID and unconditionally grants a Premium subscription to the session's… | |
| Aplazada | Media (4.3) | 0.32% | — | GhostAI | 5/8/2026 | 8/9/2026 | Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user to create a post with content in feature_image_caption that could be used to hijack another staff user's Ghost Admin session, resulting in privilege escalation. This issue is fixed in 6.54.1. | |
| Aplazada | Media (4) | 0.28% | — | GhostAI | 5/8/2026 | 8/9/2026 | Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network. A successful attack would not result in any response data… | |
| Aplazada | Media (6.7) | 0.24% | — | GhostAI | 4/8/2026 | 8/9/2026 | Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another vulnerability on the same domain where Ghost Admin was hosted. This issue is fixed… | |
| Aplazada | Media (6.6) | 0.41% | — | GhostAI | 4/8/2026 | 8/9/2026 | Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user to write files outside of the uploads directory. This could be used to alter the behavior of the installation through custom theme upload path traversal in LocalStorageBase and theme storage… | |
| Aplazada | Media (5.5) | 0.44% | — | GhostAI | 4/8/2026 | 8/9/2026 | Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the filesystem through the database backup filename, leading to integrity and availability issues. The database export endpoint failed to reject path separators in the… | |
| Aplazada | Media (4.1) | 0.37% | — | GhostAI | 4/8/2026 | 8/9/2026 | Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to perform a blind HTTP GET request against internal hosts. No output was returned, but this could have been used to probe open ports on internal hosts. This… | |
| Aplazada | Media (4.8) | 0.32% | — | GhostAI | 4/8/2026 | 8/9/2026 | Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. An offline password-guessing attack against the hashes could lead to account takeover if successful, but Device Verification should have prevented… | |
| Aplazada | Media (4.8) | 0.27% | — | GhostAI | 4/8/2026 | 8/9/2026 | Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offers that were no longer active. This issue is fixed in version 6.54.1. | |
| Aplazada | Media (5) | 0.43% | — | GhostAI | 4/8/2026 | 8/9/2026 | Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting in XSS in post content. This issue is fixed in version 6.54.1. | |
| Aplazada | Media (6.3) | 0.22% | — | Ghost CLIAI | 31/7/2026 | 9/9/2026 | Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rate-limiting controls by manipulating the X-Forwarded-For header through a misconfigured Nginx configuration. Attackers can append attacker-controlled values to the header chain using the… | |
| Aplazada | Media (5.4) | 0.26% | — | Wpplugins Hide MY WP GhostAI | 30/7/2026 | 30/7/2026 | The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does not verify that client IP information comes from a trusted proxy before trusting attacker-controllable HTTP headers, allowing unauthenticated attackers to spoof their IP address to bypass the WP Ghost (Hide My WP Ghost) WordPress plugin before… | |
| Aplazada | Alta (8) | 0.40% | — | Teamviewer Full ClientAITeamviewer HostAI | 29/7/2026 | 30/7/2026 | TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenticated attacker to bypass a configured 2FA for Connections approval flow via Unattended Access and establish a remote connection to an affected macOS host. | |
| Pendiente de análisis | Baja (2) | 0.14% | — | Ghost Sqlite3AI | 28/7/2026 | 30/7/2026 | sqlite3 provides Ruby bindings for the SQLite3 embedded database. From 2.1.0 to 2.9.4, the callbacks used for SQLite aggregate functions can be freed while still referenced during aggregation, resulting in a use-after-free. This issue is fixed in version 2.9.5. | |
| Pendiente de análisis | Baja (2) | 0.14% | — | Ghost Sqlite3AI | 28/7/2026 | 30/7/2026 | sqlite3 provides Ruby bindings for the SQLite3 embedded database. In version 2.9.4 and earlier, redefining a SQLite function with a different arity frees the previously registered function handler while SQLite may still reference it, resulting in a use-after-free. This issue is fixed in version 2.9.5. | |
| Aplazada | Alta (7.4) | 0.39% | — | Wpplugins Hide MY WP GhostAI | 27/7/2026 | 27/7/2026 | Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions. | |
| Aplazada | Alta (8.7) | 0.22% | — | Ghostrobotics Vision 60AI | 27/7/2026 | 27/7/2026 | The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Vision 60 robot (APK v5.5.0) exposes the system to man-in-the-middle attacks. An attacker located on the local network can use ARP spoofing and selective traffic blocking techniques to intercept and… |