Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2759▼ 357 respecto a la semana anterior
Críticas / altas1278▼ 254 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
21.069 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.3) | 0.24% | — | Datadog Android ApplicationAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts an attacker-supplied session (including OAuth tokens) from Intent extras with no permission guard, and signs the app into that session without validating it against the backend. This requires a… | |
| Pendiente de análisis | Media (4.6) | 0.24% | — | Datadog Android ApplicationAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive content in plaintext: LocalNotificationDatabase (notification title, message, recipient, service, tags, and on-call/incident deep links) and SearchRecentDatabase (the user's full in-app search history).… | |
| Pendiente de análisis | Media (6.4) | 0.29% | — | Datadog Android ApplicationAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported with no permission guard and accepts a SEND intent with a caller-supplied conversation_id. When the activity closes and no in-process session matches that ID, it unconditionally cancels notification ID 9201 (the Bits AI… | |
| Pendiente de análisis | Media (5.5) | 0.16% | — | Datadog Android ApplicationAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities (IncidentWidgetActivity, MonitorSavedViewWidgetActivity, OnCallShiftsWidgetActivity, OnCallPagesWidgetActivity, SloWidgetActivity, DashboardWidgetActivity) are exported with no permission guard. Each accepts a… | |
| Aplazada | Media (5.3) | 0.48% | — | FrappeAI | 7/8/2026 | 8/9/2026 | Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, a field-level permissions bypass exposes restricted DocType fields. This issue is fixed in versions 16.23.0 and 15.112.0. | |
| Aplazada | Media (5.4) | 0.23% | — | Meowapps Meow GalleryAI | 7/8/2026 | 26/8/2026 | The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an attribute of the link it builds for linked galleries, allowing users with the Author role or above to store a JavaScript payload that executes in the browser of any visitor (including administrators)… | |
| Modificada | Crítica (9.3) | 0.72% | — | Microsoft Power Apps | 7/8/2026 | 11/8/2026 | Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.6) | 0.69% | — | Microsoft Azure Logic Apps | 7/8/2026 | 7/8/2026 | Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 1.0% | — | Microsoft Application Insights Profiler | 7/8/2026 | 17/8/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 1.7% | ⚠ Explotación activa💥 PoC | Apple Macos | 6/8/2026 | 15/9/2026 | An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials. | |
| Aplazada | Media (5.1) | 0.47% | — | FrappeAI | 6/8/2026 | 8/9/2026 | Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, Data Import does not escape imported column headers before rendering previews and results, allowing an authenticated importer to persist script content that executes when another user views the import interface. This issue is fixed in… | |
| Aplazada | Crítica (9.4) | 0.38% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the route `POST /api/tenants/{tenantId}/staff/{staffId}/crypto` accepts and stores attacker-controlled ML-KEM-768 public keys against any tenant on the platform without authentication.… | |
| Aplazada | Crítica (9.8) | 0.57% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration handler at `POST /api/auth/register/{userId}` validates the relationship between the WebAuthn challenge and the registration cookie's email but never validates that the… | |
| Aplazada | Crítica (9.9) | 0.44% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN through a single PUT request. The role-update handler accepts the `GLOBAL_ADMIN` enum value from any tenant admin updating… | |
| Aplazada | Alta (7.4) | 0.39% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Versions prior to 1.0.2 don't throttle failed passphrase login attempts. An attacker can submit unlimited wrong passphrase guesses against any known email address, capped only by the Argon2 verification cost… | |
| Aplazada | Media (6.5) | 0.36% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `/api/log` endpoint accepts unauthenticated POST requests, applies no schema validation to the message body, writes attacker-controlled content directly into the application's stdout… | |
| Aplazada | Baja (3.7) | 0.39% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.6, the bootstrap challenge endpoint at `/api/tenants/{id}/appointments/bootstrap-challenge` issues a SHA-256 proof-of-work with `difficulty=4` hex zeros, equivalent to 16 bits of work.… | |
| Aplazada | Alta (8.1) | 0.24% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN can store `javascript:` URLs in the tenant `links` configuration (`website`, `imprint`, `privacyStatement`). These values are returned to the patient-facing landing page… | |
| Aplazada | Alta (8) | 0.47% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `GET /api/tenants/{id}` endpoint returns the full tenant record to any authenticated `TENANT_ADMIN` of that tenant, including the `databaseUrl` field. This field contains the live… | |
| Aplazada | Alta (7.4) | 0.50% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, when a user navigates to the `/logout` page, the page's server-side load handler deletes the `access_token` cookie before calling `/api/auth/logout` via an internal `event.fetch()`. The… | |
| Aplazada | Media (5.3) | 0.34% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the unauthenticated `/api/tenants/{id}/schedule` endpoint returns every non-archived channel for a tenant regardless of the channel's `isPublic` flag. Channels marked `isPublic = false`… | |
| Aplazada | Media (5.3) | 0.43% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.1.0, the GET handler at `/api/tenants/{id}/appointments/{appointmentId}` performs no authorization check before returning the appointment record. Any party who knows or obtains a valid… | |
| Aplazada | Media (6.5) | 0.33% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-client booking flow in versions 1.0.1 and prior consists of three calls: `bootstrap-challenge` (returns a 16-bit PoW challenge with `difficulty=4` leading hex zeroes), `bootstrap-verify` (validates the… | |
| Aplazada | Media (6.5) | 0.42% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the `add-to-tunnel` endpoint creates a new appointment row in any client tunnel without any caller authentication. A request that supplies any valid `tunnelId` and any valid `emailHash`… | |
| Aplazada | Baja (2.7) | 0.29% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.6, when a TENANT_ADMIN deletes an existing staff user, the underlying `StaffService.deleteStaffMember()` runs an additional invite cleanup that deletes from the central `user_invite` table… |