Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1016 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.54% | — | DolibarrAI | 24/8/2026 | 8/9/2026 | Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete any payment record by bypassing the intended payment-issuance rights check. Attackers can exploit this misconfigured… | |
| Aplazada | Alta (7.1) | 0.41% | — | DolibarrAI | 24/8/2026 | 8/9/2026 | Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site account write routes that allows authenticated attackers with third-party creation rights to overwrite the WebPortal password of any company by bypassing per-object access checks that are only enforced on… | |
| Aplazada | Alta (8.6) | 0.46% | — | DolibarrAI | 24/8/2026 | 8/9/2026 | Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers with only member-creation rights to reset the password of any user account, including the system administrator, without verifying password-change permissions. Attackers can supply an arbitrary user… | |
| Aplazada | Media (5.1) | 0.37% | — | DolibarrAI | 24/8/2026 | 8/9/2026 | Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration template where the type request parameter is echoed without JavaScript-context encoding into an inline script block and no Content-Security-Policy header is emitted. An unauthenticated attacker can cause… | |
| Aplazada | Media (6.9) | 0.58% | — | Alibaba Fusion NextAI | 24/8/2026 | 24/8/2026 | A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the function ConfigProvider.getContextProps of the file components/dialog/index.tsx of the component deepMerge. Performing a manipulation of the argument locale results in improperly controlled modification of object prototype… | |
| Aplazada | Baja (2.1) | 0.39% | — | Dolibarr ERPAI | 24/8/2026 | 24/8/2026 | A vulnerability has been found in Dolibarr ERP up to 18.0.10/22.0.5/23.0.3. This issue affects some unknown processing of the file /user/note.php of the component User Notes Handler. The manipulation of the argument ID leads to authorization bypass. The attack can be initiated remotely. Upgrading to version 23.0.4 and… | |
| Aplazada | Baja (2.1) | 0.48% | — | DolibarrAI | 21/8/2026 | 24/8/2026 | A weakness has been identified in Dolibarr up to 23.0.4. This affects an unknown part of the file htdocs/user/card.php of the component Account Handler. This manipulation of the argument ID causes improper authorization. The attack may be initiated remotely. The exploit has been made available to the public and could… | |
| Aplazada | Alta (8.5) | 0.28% | — | BudibaseAI | 17/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.40.0, packages/backend-core/src/utils/outboundFetch.ts pinned a validated address through a Node agent, but the REST integration used getDispatcher from packages/backend-core/src/utils/fetch.ts, causing undici to ignore that agent and resolve the hostname again.… | |
| Aplazada | Alta (8.4) | 0.45% | — | BudibaseAI | 17/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.39.19, the PostgreSQL datasource connector in packages/server/src/integrations/postgres.ts interpolates the user-controlled schema configuration field into a SET search_path statement without escaping embedded double quotes, allowing an authenticated… | |
| Aplazada | Alta (7.1) | 0.35% | 💥 PoC | BudibaseAI | 17/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/url in packages/server/src/api/routes/static.ts and packages/server/src/api/controllers/static/index.ts allows an authenticated published-app user with the BASIC role to supply attacker-controlled bucket and key values… | |
| Aplazada | Alta (7.1) | 0.46% | — | BudibaseAI | 17/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.41.3, automation steps in packages/server/src/automations/steps/outgoingWebhook.ts, packages/server/src/automations/steps/zapier.ts, packages/server/src/automations/steps/n8n.ts, packages/server/src/automations/steps/slack.ts, and… | |
| Aplazada | Alta (8.7) | 0.57% | — | ScribanAI | 16/8/2026 | 31/8/2026 | Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does not enforce a default expression depth limit (the ExpressionDepthLimit property in ParserOptions defaults to null/disabled), so an attacker who controls template input can supply a deeply nested… | |
| Aplazada | Alta (8.7) | 0.49% | — | ScribanAI | 16/8/2026 | 31/8/2026 | Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property defaults to unlimited. Attackers can supply circular reference objects to the template context, exhausting stack space and triggering an uncatchable StackOverflowException that terminates the… | |
| Aplazada | Alta (8.7) | 0.53% | — | ScribanAI | 16/8/2026 | 8/9/2026 | Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing. Deeply nested array initializers recurse through a path (ParseArrayInitializer → ParseExpression → ParseArrayInitializer) that is not covered by the ExpressionDepthLimit counter added in the… | |
| Aplazada | Crítica (9.2) | 0.43% | — | ScribanAI | 16/8/2026 | 31/8/2026 | Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations to access previously authorized template content from earlier renders without… | |
| Aplazada | Crítica (9.3) | 0.47% | — | ScribanAI | 16/8/2026 | 31/8/2026 | Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by reusing a TemplateContext after tightening its MemberFilter, bypassing sandbox… | |
| Aplazada | Alta (8.7) | 0.60% | — | ScribanAI | 16/8/2026 | 31/8/2026 | Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed inside built-in operators and functions. As a result, a single expression such as {{ 1..1000000 | array.size }} — or a memory-amplification expression such as {{ 'A' *… | |
| Aplazada | Alta (8.7) | 0.49% | — | ScribanAI | 16/8/2026 | 31/8/2026 | Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_left and string.pad_right template functions, which perform no validation on the width parameter before delegating to .NET's String.PadLeft/PadRight. When an application exposes Scriban to… | |
| Aplazada | Alta (8.7) | 0.49% | — | ScribanAI | 16/8/2026 | 8/9/2026 | Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger unbounded recursion, causing a StackOverflowException that fatally terminates the… | |
| Aplazada | Alta (7.1) | 0.48% | — | ScribanAI | 16/8/2026 | 31/8/2026 | Scriban before 7.0.0 (affected versions <= 6.6.0) contains a denial-of-service vulnerability in which the LimitToString safety limit (default 1MB) can be bypassed because ObjectToString resets the per-call length counter (_currentToStringLength) on every top-level call and StringBuilderOutput enforces no cumulative… | |
| Aplazada | Alta (7.1) | 0.48% | — | ScribanAI | 16/8/2026 | 31/8/2026 | Scriban before 7.0.0 contains three distinct denial-of-service vulnerabilities in expression evaluation that bypass existing safety controls through unbounded string multiplication, uncontrolled BigInteger shift operations, and LoopLimit bypass via range enumeration in builtin functions. Attackers who can supply… | |
| Aplazada | Alta (8.7) | 0.45% | — | ScribanAI | 16/8/2026 | 31/8/2026 | Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that allocates unbounded null entries without respecting LoopLimit or LimitToString constraints. Attackers can supply a large index parameter to trigger OutOfMemoryException and crash the host process in under a second. | |
| Aplazada | Crítica (9.3) | 0.54% | — | ScribanAI | 16/8/2026 | 31/8/2026 | Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init-only setters, and perform mass assignment on public-setter properties,… | |
| Aplazada | Alta (8.7) | 0.34% | — | ScribanAI | 16/8/2026 | 30/9/2026 | Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initializers, object initializers, or unary operators to trigger an uncatchable… | |
| Aplazada | Alta (8.7) | 0.49% | — | ScribanAI | 16/8/2026 | 30/9/2026 | Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer multiplier in a template to force multi-gigabyte memory allocations, causing… |