Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2771▲ 6 respecto a la semana anterior
Críticas / altas1285▼ 246 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)242▲ 224 respecto a la semana anterior
9658 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa💥 PoC | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Aplazada | Alta (7.3) | 0.40% | — | Quickjs-ngAI | 11/5/2026 | 17/6/2026 | An issue in QuickJS-NG v.0.12.1 allows an attacker to execute arbitrary code via the js_mapped_arguments_mark function | |
| Aplazada | Baja (2) | 0.21% | — | Squirrel-lang SquirrelAI | 11/5/2026 | 23/7/2026 | Se determinó una vulnerabilidad en Squirrel hasta 3.2. Esto afecta la función SQFunctionProto::Load del archivo squirrel/sqobject.cpp. Esta manipulación causa desbordamiento de búfer basado en montículo. El ataque está restringido a ejecución local. El exploit ha sido divulgado públicamente y puede ser utilizado. El… | |
| Aplazada | Baja (1.9) | 0.17% | — | Squirrel-lang SquirrelAI | 11/5/2026 | 23/7/2026 | Se ha encontrado un fallo en Squirrel hasta la versión 3.2. La función afectada es validate_format en la biblioteca sqstdlib/sqstdstring.cpp. La ejecución de una manipulación puede conducir a un desbordamiento de búfer basado en pila. El ataque solo puede ejecutarse localmente. El exploit ha sido publicado y puede ser… | |
| Aplazada | Media (5.1) | 0.21% | — | Wordpress Contact Form BuilderAI | 10/5/2026 | 24/7/2026 | WordPress Contact Form Builder 1.6.1 contiene una vulnerabilidad de cross-site scripting reflejado que permite a atacantes no autenticados inyectar scripts maliciosos explotando el parámetro form_id. Los atacantes pueden crear URLs maliciosas hacia code_generator.PHP con cargas útiles de script en el parámetro form_id… | |
| Aplazada | Crítica (9.3) | 0.59% | — | Inspireui Mstore APIAI | 10/5/2026 | 25/7/2026 | WordPress MStore API 2.0.6 contiene una vulnerabilidad de carga arbitraria de archivos que permite a atacantes no autenticados cargar archivos maliciosos enviando solicitudes POST al endpoint de la API REST. Los atacantes pueden cargar archivos PHP con nombres arbitrarios al endpoint config_file para lograr la… | |
| Aplazada | Alta (8.8) | 0.31% | — | Balbooa Joomla Forms BuilderAI | 10/5/2026 | 25/7/2026 | Balbooa Joomla Forms Builder 2.0.6 contiene una vulnerabilidad de inyección SQL no autenticada en el gestor de envío de formularios que permite a atacantes remotos ejecutar consultas SQL arbitrarias. Los atacantes pueden enviar solicitudes POST al componente com_baforms con cargas útiles JSON maliciosas en el… | |
| Aplazada | Media (5.1) | 0.24% | — | Tecnoteca CmdbuildAI | 10/5/2026 | 6/10/2026 | CMDBuild 3.3.2 contiene múltiples vulnerabilidades de cross-site scripting almacenado que permiten a atacantes autenticados inyectar scripts web o HTML arbitrarios a través de entradas manipuladas en los puntos finales de creación de tarjetas y carga de archivos. Los atacantes pueden inyectar cargas útiles de XSS a… | |
| Analizada | Media (5.3) | 0.18% | — | Hcltech Bigfix Webui APIHcltech Bigfix Webui Application AdministrationHcltech Bigfix Webui CmepHcltech Bigfix Webui Common+17 | 9/5/2026 | 25/7/2026 | Una vulnerabilidad de falta de autorización en HCL BigFix WebUI permite a un usuario autenticado sin los permisos adecuados ver información ambiental sensible mediante acceso directo a la URL de la página no autorizada. | |
| Analizada | Media (5.3) | 0.22% | — | Hcltech Bigfix Webui APIHcltech Bigfix Webui Application AdministrationHcltech Bigfix Webui CmepHcltech Bigfix Webui Common+17 | 9/5/2026 | 25/7/2026 | Una vulnerabilidad de autorización impropia en HCL BigFix WebUI permite a un usuario autenticado sin privilegios de Operador Maestro acceder a datos internos (nombres de sitios, versiones y variables de configuración) y eludir los requisitos de privilegios a través de puntos finales desprotegidos que carecen de… | |
| Analizada | Media (6.5) | 0.59% | — | Liquidjs | 9/5/2026 | 24/7/2026 | LiquidJS es un motor de plantillas compatible con Shopify / GitHub Pages en JavaScript puro. Antes de la versión 10.25.7, una referencia de bloque circular en {% layout %} / {% block %} causa un bucle recursivo infinito, consumiendo toda la memoria disponible (~4GB) y bloqueando el proceso de Node.js con FATAL ERROR:… | |
| Aplazada | Media (5.1) | 0.41% | — | Akuity KargoAI | 8/5/2026 | 24/7/2026 | Kargo gestiona y automatiza la promoción de artefactos de software. Antes de las versiones 1.7.10, 1.8.13, 1.9.8 y 1.10.2, Kargo es vulnerable a una redirección abierta en el flujo de inicio de sesión OIDC de la interfaz de usuario a través del parámetro de consulta redirectTo. Este problema ha sido parcheado en las… | |
| Aplazada | Media (5.5) | 0.47% | — | Lasuite PeopleAI | 8/5/2026 | 17/6/2026 | People is an application to handle users and teams, and distribute permissions across La Suite. Prior to version 1.25.0, a user holding the Administrator role on a mail domain could send a crafted invitation request to promote any existing user (including users with no current domain access) to the Owner role. The… | |
| Pendiente de análisis | Alta (7.3) | 3.9% | 💥 Exploit | Byob Build Your OWN BotnetAI | 8/5/2026 | 17/6/2026 | A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbitrary commands on the server via a crafted build parameter. This occurs in freeze in core/generators.py. | |
| Aplazada | Alta (7.1) | 0.25% | — | Bricks BuilderAI | 7/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricks Builder allows Reflected XSS. This issue affects Bricks Builder: from n/a through 1.9.2 to 2.2. | |
| Aplazada | Crítica (9.3) | 0.55% | — | Eclipse EquinoxAI | 5/5/2026 | 30/9/2026 | Eclipse Equinox OSGi 3.7.2 and earlier contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending payloads to the console interface. Attackers can connect to the OSGi console port and send base64-encoded bash commands wrapped in fork directives to… | |
| Aplazada | Crítica (9.3) | 0.46% | — | Eclipse EquinoxAI | 5/5/2026 | 30/9/2026 | Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface that allows unauthenticated attackers to execute arbitrary code by exploiting the fork command functionality. Attackers can establish a telnet connection to the OSGi console, perform a telnet… | |
| Analizada | Crítica (9) | 0.83% | — | Nginxui Nginx UI | 4/5/2026 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint (POST /api/restore) that is completely unauthenticated during the first 10 minutes after process startup on any fresh installation. An unauthenticated remote attacker can upload a crafted… | |
| Analizada | Media (6.5) | 0.41% | — | Nginxui Nginx UI | 4/5/2026 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, the GetSettings API handler (api/settings/settings.go:24-65) serializes all settings structs to JSON and returns them to authenticated users. Many sensitive fields are tagged with protected:"true" - however, this tag is only enforced… | |
| Analizada | Crítica (9.8) | 0.47% | — | Nginxui Nginx UI | 4/5/2026 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the initial installation window exposed by POST /api/install. At time of publication no public patches are available. | |
| Analizada | Crítica (9.8) | 1.6% | 💥 Exploit | Nginxui Nginx UI | 4/5/2026 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to before version 2.3.8, an unauthenticated network attacker can claim the initial administrator account on a fresh nginx-ui instance during the first-run setup window. The public /api/install endpoint is reachable without authentication,… | |
| Analizada | Media (6.5) | 0.40% | — | Nginxui Nginx UI | 4/5/2026 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, an authenticated user can call GET /api/settings and retrieve sensitive configuration values, including node.secret. The same node.secret is accepted by AuthRequired() through the X-Node-Secret header (or node_secret query parameter),… | |
| Aplazada | Baja (2.1) | 0.52% | — | Kerwincui FastbeeAI | 3/5/2026 | 17/6/2026 | A vulnerability was found in kerwincui FastBee up to 1.2.1. The affected element is the function ToolController.download of the file springboot/fastbee-open-api/src/main/java/com/fastbee/data/controller/ToolController.java of the component Tool Download Endpoint. The manipulation of the argument fileName results in… | |
| Aplazada | Baja (2.1) | 1.8% | — | R-huijts Mcp-server-rijksmuseumAI | 2/5/2026 | 17/6/2026 | A security flaw has been discovered in r-huijts mcp-server-rijksmuseum up to 1.0.4. Affected is the function open_image_in_browser of the file src/index.ts of the component MCP Interface. Performing a manipulation of the argument imageUrl results in os command injection. The attack is possible to be carried out… | |
| Aplazada | Media (5.8) | 0.37% | — | Ays-pro Quiz MakerAI | 2/5/2026 | 17/6/2026 | The Quiz Maker by AYS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rate_reason' parameter in all versions up to, and including, 6.7.1.29 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… |