Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
1319 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 0.67% | — | Vercel Next.js | 27/7/2026 | 29/7/2026 | Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 through 16.2.10, when self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain… | |
| Analizada | Media (6.3) | 0.51% | — | Vercel Next.js | 27/7/2026 | 29/7/2026 | Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, Next.js applications using App Router, Server Actions (use server) or use cache endpoints can be disclosed bypassing any authentication on the pages where these endpoints are usually… | |
| Analizada | Alta (8.3) | 0.64% | — | Vercel Next.js | 27/7/2026 | 29/7/2026 | Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router built with Turbopack and a single entry in config.i18n.locales can bypass middleware/proxy based authentication. This issue has been fixed in… | |
| Analizada | Alta (8.2) | 0.86% | — | Vercel Next.js | 27/7/2026 | 29/7/2026 | Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same… | |
| Aplazada | Media (4.3) | 0.86% | — | Posimyth Nexter BlocksAI | 24/7/2026 | 24/7/2026 | The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.0.0 via the 'plus_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary… | |
| Aplazada | Crítica (10) | 1.4% | 💥 PoC | Vercel Next.jsAICalcom Cal.diyAI | 23/7/2026 | 29/9/2026 | Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attacker can send a crafted RSC request to the server and cause arbitrary code to be… | |
| Aplazada | Alta (8.1) | 0.72% | — | Dayuanjiang Next-ai-draw-ioAI | 21/7/2026 | 22/7/2026 | Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp parameter | |
| Aplazada | Alta (7.8) | 0.63% | — | Dayuanjiang Next-ai-draw-ioAI | 21/7/2026 | 22/7/2026 | Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-server | |
| Aplazada | Alta (7.5) | 0.51% | — | Dayuanjiang Next-ai-draw-ioAI | 21/7/2026 | 22/7/2026 | An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component | |
| Aplazada | Crítica (9.8) | 0.62% | — | Dayuanjiang Next-ai-draw-ioAI | 21/7/2026 | 22/7/2026 | An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value | |
| Aplazada | Alta (7.1) | 0.34% | — | NextcrmAI | 20/7/2026 | 21/7/2026 | NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide business object. Normal application server actions restrict product creation, update, and deletion to `manager` and `admin` roles. However, in version 0.12.1, the MCP product tools expose the same… | |
| Aplazada | Alta (7.6) | 0.31% | — | NextcrmAI | 20/7/2026 | 22/7/2026 | NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose campaign read and write operations over the network using user-generated Bearer API tokens (`nxtc__...`). The application has an authorization model that restricts normal users to campaigns they… | |
| Aplazada | Alta (7.1) | 0.28% | — | NextcrmAI | 20/7/2026 | 22/7/2026 | NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Object Level Authorization (BOLA/IDOR) vulnerability exists in the CRM contact and target update endpoints. The application fails to verify if the authenticated user has ownership of the specific resource… | |
| Aplazada | Alta (8.1) | 0.40% | — | NextcrmAI | 20/7/2026 | 22/7/2026 | NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Access Control (BAC) vulnerability in the `activateUser` and `deactivateUser` Next.js Server Actions of NextCRM. The application fails to verify if the requesting user holds the `admin` role. Consequently,… | |
| Aplazada | Media (5.4) | 0.23% | — | Bifra Engineering Consulting LTD Q-smart Next PollAI | 20/7/2026 | 20/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering Consulting Ltd. Q-smart NexT Poll allows Stored XSS. This issue affects Q-smart NexT Poll: before 1.8.7. | |
| Aplazada | Baja (2.1) | 0.37% | — | Nextlevelbuilder GoclawAI | 19/7/2026 | 20/7/2026 | A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This affects the function ExecTool.Execute of the file goclaw/internal/tools/credentialed_exec.go. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been published and may be used. | |
| Aplazada | Baja (2.1) | 0.46% | — | Nextlevelbuilder GoclawAI | 18/7/2026 | 20/7/2026 | A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.15.0-beta.32. This affects the function CheckSSRF/isPrivateIP of the file internal/tools/web_shared.go of the component web_fetch. Such manipulation leads to server-side request forgery. The attack can be launched remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.37% | — | Nextlevelbuilder GoclawAI | 18/7/2026 | 22/7/2026 | A weakness has been identified in nextlevelbuilder GoClaw up to 3.13.2. Affected by this issue is the function ToolsInvokeHandler.ServeHTTP of the file internal/http/tools_invoke.go of the component Invoke Endpoint. This manipulation causes missing authorization. The attack can be initiated remotely. The exploit has… | |
| Aplazada | Baja (1.9) | 0.31% | — | Nextlevelbuilder GoclawAI | 18/7/2026 | 20/7/2026 | A security flaw has been discovered in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function extractBin/RequestApproval/matchesAllowlist of the file internal/tools/exec_approval.go. The manipulation results in incorrect authorization. The exploit has been released to the public and may… | |
| Aplazada | Baja (2.1) | 0.37% | — | Nextlevelbuilder GoclawAI | 18/7/2026 | 20/7/2026 | A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.2. Affected is the function isSafeBin of the file internal/tools/exec_approval.go. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. | |
| Aplazada | Baja (2.1) | 0.40% | — | Nextlevelbuilder GoclawAI | 18/7/2026 | 20/7/2026 | A vulnerability was determined in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This impacts the function matchesAllowlist/extractBin of the file internal/tools/exec_approval.go. Executing a manipulation can lead to incorrectly-resolved name. The attack may be performed from remote. The exploit has been publicly… | |
| Aplazada | Baja (2.1) | 0.40% | — | Nextlevelbuilder GoclawAI | 18/7/2026 | 21/7/2026 | A vulnerability was found in nextlevelbuilder GoClaw up to 3.13.2. This affects the function RequestApproval of the file internal/tools/exec_approval.go of the component WebSocket Approval Endpoint. Performing a manipulation results in incorrect authorization. The attack is possible to be carried out remotely. The… | |
| Aplazada | Media (6.5) | 0.41% | — | Quiz Master NextAI | 16/7/2026 | 16/7/2026 | The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up to, and including, 11.2.0. This is due to insufficient escaping on the user-supplied 'pages' parameter persisted by the qsm_ajax_save_pages() AJAX handler (sanitize_text_field only) and lack of sufficient… | |
| Aplazada | Alta (8.8) | 0.20% | — | Frappe ErpnextAI | 15/7/2026 | 15/7/2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated user with a standard operational role can trigger server-side template injection through a configuration field, resulting in unauthorized disclosure of data outside the user's normal permission scope.… | |
| Analizada | Alta (8.7) | 0.57% | — | F5 Big-ip Next Cloud-native Network FunctionsF5 Big-ip Next FOR KubernetesF5 Big-ip Next Service Proxy FOR Kubernetes | 15/7/2026 | 6/8/2026 | When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Impact: System performance can degrade until the TMM process is either forced to restart or is manually restarted. This vulnerability allows a remote, unauthenticated attacker to cause a… |