Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
367 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 0.36% | — | Ghostfolio | 6/3/2026 | 17/6/2026 | Ghostfolio is an open source wealth management software. Prior to version 2.245.0, an attacker can exploit the manual asset import feature to perform a full-read SSRF, allowing them to exfiltrate sensitive cloud metadata (IMDS) or probe internal network services. This issue has been patched in version 2.245.0. | |
| Analizada | Crítica (9.8) | 5.0% | 💥 Exploit | Ghost | 5/3/2026 | 17/6/2026 | Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the server running Ghost. This issue has been patched in version 6.19.1. | |
| Aplazada | Media (4) | 0.27% | — | Akamai GhostAIAkamai CDNAI | 23/2/2026 | 17/6/2026 | Akamai Ghost on Akamai CDN edge servers before 2026-02-06 mishandles processing of custom hop-by-hop HTTP headers, where an incoming request containing the header "Connection: Transfer-Encoding" could result in a forward request with invalid message framing, depending on the Akamai processing path. This could result… | |
| Aplazada | Alta (7.5) | 0.25% | — | Ghostpool GaugeAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in GhostPool Gauge gauge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gauge: from n/a through <= 6.56.4. | |
| Aplazada | Alta (7.5) | 0.25% | — | Ghostpool Aardvark PluginAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in GhostPool Aardvark Plugin aardvark-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Aardvark Plugin: from n/a through <= 2.19. | |
| Aplazada | Alta (7.1) | 0.24% | — | Ghostpool AardvarkAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhostPool Aardvark aardvark allows Reflected XSS.This issue affects Aardvark: from n/a through <= 4.6.3. | |
| Modificada | Alta (7.5) | 5.0% | 💥 Exploit | Ghost | 20/2/2026 | 17/6/2026 | Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed in version 6.19.1. | |
| Analizada | Media (6.1) | 0.29% | — | GhostGhost Portal | 27/1/2026 | 17/6/2026 | Ghost is an open source content management system. In Ghost versions 5.43.0 through 5.12.04 and 6.0.0 through 6.14.0, an attacker was able to craft a malicious link that, when accessed by an authenticated staff user or member, would execute JavaScript with the victim's permissions, potentially leading to account… | |
| Analizada | Media (5.1) | 0.30% | — | Ghost | 10/1/2026 | 17/6/2026 | Ghost is a Node.js content management system. In versions 5.38.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost’s media inliner mechanism allows staff users in possession of a valid authentication token for the Ghost Admin API to exfiltrate data from internal systems via SSRF. This issue has been… | |
| Analizada | Alta (7.2) | 0.47% | — | Ghost | 10/1/2026 | 17/6/2026 | Ghost is a Node.js content management system. In versions 5.90.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's /ghost/api/admin/members/events endpoint allows users with authentication credentials for the Admin API to execute arbitrary SQL. This issue has been patched in versions 5.130.6 and… | |
| Analizada | Alta (8.1) | 0.54% | — | Ghost | 10/1/2026 | 17/6/2026 | Ghost is a Node.js content management system. In versions 5.121.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's handling of Staff Token authentication allowed certain endpoints to be accessed that were only intended to be accessible via Staff Session authentication. External systems that have… | |
| Analizada | Alta (8.1) | 1.3% | 💥 Exploit | Ghost | 10/1/2026 | 17/6/2026 | Ghost is a Node.js content management system. In versions 5.105.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's 2FA mechanism allows staff users to skip email 2FA. This issue has been patched in versions 5.130.6 and 6.11.0. | |
| Analizada | Media (4.8) | 0.26% | — | Akamaighost | 4/12/2025 | 17/6/2026 | Akamai Ghost on Akamai CDN edge servers before 2025-11-17 has a chunked request body processing error that can result in HTTP request smuggling. When Akamai Ghost receives an invalid chunked body that includes a chunk size different from the actual size of the following chunk data, under certain circumstances, Akamai… | |
| Aplazada | Media (5.5) | 0.33% | — | Serdar Bayram Ghost HOT SpotAI | 28/10/2025 | 17/6/2026 | A flaw has been found in Serdar Bayram Ghost Hot Spot up to 20251014. The affected element is an unknown function of the file /Auth.php of the component Login. This manipulation causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was… | |
| Analizada | Alta (7) | 0.25% | — | Ghostrobotics Vision 60 Firmware | 22/10/2025 | 17/6/2026 | Encrypted WiFi and SSH credentials were found in the Ghost Robotics Vision 60 v0.27.2 APK. This vulnerability allows an attacker to connect to the robot's WiFi and view all its data, as it runs on ROS 2 without default authentication. In addition, the attacker can connect via SSH and gain full control of the robot,… | |
| Analizada | Alta (8.7) | 0.63% | — | Ghostrobotics Vision 60 Firmware | 22/10/2025 | 17/6/2026 | Ghost Robotics Vision 60 v0.27.2 includes, among its physical interfaces, three RJ45 connectors and a USB Type-C port. The vulnerability is due to the lack of authentication mechanisms when establishing connections through these ports. Specifically, with regard to network connectivity, the robot's internal router… | |
| Analizada | Crítica (9.2) | 0.31% | — | Ghostrobotics Vision 60 Firmware | 22/10/2025 | 17/6/2026 | The communication protocol implemented in Ghost Robotics Vision 60 v0.27.2 could allow an attacker to send commands to the robot from an external attack station, impersonating the control station (tablet) and gaining unauthorised full control of the robot. The absence of encryption and authentication mechanisms in the… | |
| Analizada | Media (6.5) | 0.36% | — | Ghostxbh Uzy-ssm-mall | 8/10/2025 | 17/6/2026 | A fastjson deserialization vulnerability in uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying a crafted input. | |
| Analizada | Media (6.5) | 0.35% | — | Ghostxbh Uzy-ssm-mall | 8/10/2025 | 17/6/2026 | An XML External Entity (XXE) vulnerability in the /mall/wxpay/pay component of uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying crafted XML data. | |
| Analizada | Media (5.5) | 0.18% | — | Artifex Ghostscript | 22/9/2025 | 17/6/2026 | In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer overflow in ocr_line8. | |
| Modificada | Media (5.5) | 0.20% | — | Artifex Ghostscript | 22/9/2025 | 17/6/2026 | Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdfmark_coerce_dest in devices/vector/gdevpdfm.c via a large size value. | |
| Modificada | Media (5.5) | 0.20% | — | Artifex Ghostscript | 22/9/2025 | 17/6/2026 | Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c. | |
| Aplazada | Media (4.3) | 0.20% | — | Artifex GhostxpsAI | 22/9/2025 | 30/9/2026 | In Artifex GhostXPS before 10.06.0, there is a stack-based buffer overflow in xps_unpredict_tiff in xpstiff.c because the samplesperpixel value is not checked. | |
| Aplazada | Media (6.4) | 0.19% | — | Ghost KITAI | 18/9/2025 | 17/6/2026 | The Ghost Kit – Page Builder Blocks, Motion Effects & Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS field in all versions up to, and including, 3.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.1) | 0.52% | — | Ghost | 17/9/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Ghost allows an attacker to access internal resources.This issue affects Ghost: from 6.0.0 through 6.0.8, from 5.99.0 through 5.130.3. |