Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1062 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.7) | 0.19% | — | Ghostrobotics Vision 60AI | 27/7/2026 | 27/7/2026 | An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run without proper client validation or session integrity checks. An attacker with a modified version of the app can connect to the robot during an active, legitimate session.… | |
| Aplazada | Alta (8.7) | 0.31% | — | Ghostrobotics Vision 60AIGhostrobotics Vision 60 Mobile APPAI | 27/7/2026 | 27/7/2026 | A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated attacker connected to the device's internal Wi-Fi network to gain unrestricted access to the web administration interface and the HTTP API. Due to the lack of authorization mechanisms, the attacker can… | |
| Analizada | Media (5.4) | 0.35% | — | Nhost CLI | 21/7/2026 | 30/7/2026 | Nhost is an open source Firebase alternative with GraphQL. In versions of Nhost CLI prior to 1.46.0, the hidden `nhost configserver` used by `nhost dev` exposes the Mimir GraphQL API with dummy authorization directives and permissive CORS. When a developer is running the local development environment, any process that… | |
| Aplazada | Media (6.4) | 0.42% | — | Kibokolabs HostelAI | 10/7/2026 | 10/7/2026 | The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wphostel-book' shortcode in all versions up to and including 1.1.7. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. Specifically, the second shortcode attribute (used as… | |
| Aplazada | Media (5.3) | 0.40% | — | GhostAI | 9/7/2026 | 14/7/2026 | Ghost is a Node.js content management system. From 6.27.0 before 6.44.0, Ghost's public donation checkout flow allowed an unauthenticated attacker to control donation checkout metadata and obtain full paid gift memberships for a minimal payment without exposing customer or member data or stealing money from a site or… | |
| Aplazada | Alta (8.7) | 0.59% | — | GhostfolioAI | 7/7/2026 | 17/9/2026 | The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeUserId filtering, allowing unauthenticated access to full portfolio data. Attackers with a private access ID can retrieve sensitive portfolio information including holdings, quantities, buy prices,… | |
| Aplazada | Media (5.3) | 0.34% | — | GhostfolioAI | 7/7/2026 | 17/9/2026 | Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field when processing the Impersonation-Id header, allowing read-only access grantees to modify portfolio holding tags. Attackers with valid read-only share tokens can assign or remove tags on victim… | |
| Analizada | Alta (7.1) | 0.47% | — | W1.fi Hostapd | 30/6/2026 | 2/7/2026 | In hostapd before 2.12, a missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.11be) Multi-Link Operation (MLO) association request processing allows an unauthenticated attacker within wireless range to send a crafted management frame containing a malformed Multi-Link Element or Per-STA Profile subelement. In… | |
| Aplazada | Alta (8.6) | 0.71% | — | SzafirhostAI | 29/6/2026 | 29/6/2026 | SzafirHost verifies the downloaded native library archive with one JarFile parser (reading the Central Directory) but extracts native libraries with JarInputStream parser (reading sequentially from local file headers). An attacker who controls the served archive can insert a malicious DLL/SO/DYLIB as a… | |
| Aplazada | Media (6.5) | 0.22% | — | Ghost KITAI | 26/6/2026 | 26/6/2026 | Contributor Cross Site Scripting (XSS) in Ghost Kit <= 3.6.0 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Ghost ActivitypubAI | 24/6/2026 | 25/6/2026 | @tryghost/activitypub is Ghost’s social/federation client app. Prior to 3.1.0, the ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server. This vulnerability is fixed in 3.1.0. | |
| Aplazada | Media (5.3) | 0.36% | — | GhostAINodejsAI | 24/6/2026 | 25/6/2026 | Ghost is a Node.js content management system. From 5.46.1 until 6.21.2, the validation applied to filters on the public API endpoints could be partially bypassed, making it possible to reveal private fields via a brute force attack. If SQLite was used as the database password hashes were fully accessible. If MySQL was… | |
| Aplazada | Media (5.4) | 0.23% | — | GhostAI | 24/6/2026 | 25/6/2026 | Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, insufficient validation of the client-supplied Content-Type on Ghost's Admin API file upload endpoint allowed uploaded files to be served from the site with an attacker-chosen content type on S3/GCS storage backends. On installations that serve… | |
| Aplazada | Media (5.3) | 0.34% | — | GhostAI | 24/6/2026 | 25/6/2026 | Ghost is a Node.js content management system. From 5.18.0 until 6.21.1, a discrepancy in responses from the members signin endpoints made it possible for an unauthenticated attacker to determine whether a given email address belongs to a registered member of a Ghost site. This vulnerability is fixed in 6.21.1. | |
| Aplazada | Media (5.4) | 0.21% | — | GhostAI | 24/6/2026 | 25/6/2026 | Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, when re-rendering posts, Ghost would refetch missing image dimensions by issuing an outbound HTTP request to the URL stored on an image card — without restricting that URL to trusted image hosts. An authenticated staff user able to create or edit… | |
| Aplazada | Media (4) | 0.21% | — | GhostAI | 24/6/2026 | 25/6/2026 | Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, Ghost’s private-IP check for outbound HTTP requests could be bypassed via DNS rebinding, allowing an attacker to coerce the Ghost server into reaching hosts on internal networks through features that issue external fetches. This vulnerability is… | |
| Aplazada | Media (5.8) | 0.33% | — | GhostAI | 24/6/2026 | 25/6/2026 | Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, when making an external request, it is possible to bypass the IP filter that ensures the request isn't going to an internal service using an IPv6 literal which maps to a private IPv4 address. This vulnerability is fixed in 6.21.1. | |
| Aplazada | Crítica (9.6) | 0.45% | — | GhostAI | 24/6/2026 | 25/6/2026 | Ghost is a Node.js content management system. From until 6.37.0, when Ghost is behind a shared caching layer that results in cached content being shared between different visitors, an unauthenticated user could send an x-ghost-preview header that altered the rendered frontend response. In affected cache… | |
| Aplazada | Alta (8.5) | 0.17% | — | Matrix42 Remote Control HostAI | 19/6/2026 | 29/9/2026 | Matrix42 Remote Control Host 3.20.0031 contains an unquoted service path vulnerability in the FastViewerRemoteService and FastViewerRemoteProxy services that allows local users to execute arbitrary code with SYSTEM privileges. Attackers can place a malicious executable in the Program Files directory with a crafted… | |
| Aplazada | Media (5.3) | 0.46% | — | 2download Connector FOR 2DL Hosted CheckoutAI | 19/6/2026 | 22/6/2026 | The 2Download Connector for 2DL Hosted Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 0.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to view arbitrary… | |
| Aplazada | Baja (2.1) | 0.21% | — | Lakshayd02 Hostel-management-system-phpAI | 4/6/2026 | 22/7/2026 | A vulnerability was found in LakshayD02 Hostel-Management-System-PHP up to f87e67c283bab6f718faf2fec6ae39a13bd7036b. This issue affects some unknown processing of the file hostel/index.php of the component Admin Dashboard Page. The manipulation of the argument ID results in missing authorization. The attack can be… | |
| Aplazada | Alta (7.6) | 0.38% | — | Localhostlabs KarakeepAI | 26/5/2026 | 24/7/2026 | Karakeep is a elf-hostable bookmark-everything app. A Server-Side Request Forgery (SSRF) protection bypass vulnerability was identified in versions prior to 0.32.0 affecting redirect-following processing components. Although the application implements protections intended to prevent requests toward internal/private… | |
| Aplazada | Alta (8.6) | 0.71% | — | SzafirhostAI | 15/5/2026 | 17/6/2026 | SzafirHost verifies the signature of the downloaded JAR file using class JarInputStream (reading from the beginning of the file), but loads classes using class JarFile/URLClassLoader (reading the Central Directory from the end). It can lead to remote code execution by allowing an attacker to combine a genuine, signed… | |
| Aplazada | Media (5.3) | 0.38% | — | Hostinger ReachAI | 13/5/2026 | 17/6/2026 | The Hostinger Reach – AI-Powered Email Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'handle_ajax_action' function in all versions up to, and including, 1.3.8. This makes it possible for authenticated attackers, with… | |
| Analizada | Crítica (9.3) | 0.91% | — | Nhost/auth | 8/5/2026 | 17/6/2026 | Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.49.1, Nhost automatically links an incoming OAuth identity to an existing Nhost account when the email addresses match. This is only safe when the email has been verified by the OAuth provider. Nhost's controller trusts a… |