Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
2676 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.9) | 0.37% | — | Broadcom Reactor Core | 27/8/2026 | 4/9/2026 | In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.5.0 - 3.7.19 Reactor Core 3.4.41 and earlier | |
| Aplazada | Crítica (9.8) | 1.2% | — | Senaite CoreAI | 26/8/2026 | 9/9/2026 | SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-request chain involving missing authorization and unsafe evaluation. The state-changing routes in… | |
| Pendiente de análisis | Media (6.9) | 0.26% | — | Nagios XIAINagios CoreAI | 26/8/2026 | 24/9/2026 | Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a CSRF vulnerability in cmd.cgi. When no Cookie header is present, the double-submit cookie protection can be bypassed by supplying matching NagFormId and nagFormId values in the POST body, allowing a cross-site request to execute Nagios commands as a… | |
| Aplazada | Media (6.9) | 0.21% | — | Nagios CoreAI | 26/8/2026 | 24/9/2026 | Nagios Core before 4.5.12 contains a cross-site request forgery vulnerability in cmd.cgi where the CSRF protection mechanism passes validation when the NagFormId cookie is absent. Attackers can craft a malicious cross-site POST request to execute arbitrary Nagios commands as a currently authenticated user without… | |
| Pendiente de análisis | Media (5.4) | 0.23% | — | Drupal CoreAI | 25/8/2026 | 28/8/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*. | |
| Pendiente de análisis | Media (4.7) | 0.13% | — | Drupal CoreAI | 25/8/2026 | 28/8/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.2.*. | |
| Pendiente de análisis | Media (4.2) | 0.12% | — | Drupal CoreAI | 25/8/2026 | 28/8/2026 | Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*. | |
| Aplazada | Crítica (9.3) | 0.77% | — | Rconfig CoreAI | 24/8/2026 | 24/9/2026 | rConfig Core 8.0.0 before 8.2.10 contains an authentication bypass vulnerability that allows unauthenticated attackers to self-register accounts with full Administrator privileges due to a duplicate bare Auth::routes() call in routes/web.php that re-enables the POST /register route after it was explicitly disabled.… | |
| Pendiente de análisis | Alta (7.1) | 0.72% | — | Rconfig CoreAI | 24/8/2026 | 23/9/2026 | rConfig Core 8.0.0 before 8.2.13 contains a path traversal vulnerability that allows authenticated users to read arbitrary files by supplying crafted filenames containing directory traversal sequences to the export download endpoint. Attackers can manipulate the filename parameter with traversal sequences to escape… | |
| Aplazada | Alta (8.1) | 0.47% | — | Verdure CoreAI | 24/8/2026 | 24/8/2026 | Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions. | |
| Aplazada | Alta (8.1) | 0.47% | — | Tonda CoreAI | 24/8/2026 | 24/8/2026 | Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions. | |
| Aplazada | Media (4.4) | 0.25% | — | Xapian-coreAI | 20/8/2026 | 9/9/2026 | A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because of a missed corner case of CVE-2018-0499. | |
| Aplazada | Media (4.7) | 0.29% | — | Dicebear CoreAIDicebear InitialsAI | 20/8/2026 | 18/9/2026 | DiceBear is an avatar library for designers and developers. Prior to 9.4.3, @dicebear/core interpolates the rotate option into an SVG transform attribute without XML escaping in addRotate in packages/@dicebear/core/src/utils/svg.ts, while @dicebear/initials similarly emits fontSize and fontWeight without escaping in… | |
| Aplazada | Alta (8.7) | 0.96% | — | Coreweave MarimoAI | 19/8/2026 | 16/9/2026 | marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary commands by supplying a crafted MCP server entry with an attacker-controlled command value embedded in a notebook. When the notebook is opened in edit mode, marimo launches the… | |
| Aplazada | Alta (8.5) | 0.46% | — | Grav Shortcode CoreAI | 19/8/2026 | 9/9/2026 | Grav Shortcode Core Plugin allows for the development shortcode plugins that utilize the common format utilized by WordPress and BBCode. Prior to 6.2.2, Grav Shortcode Core passes shortcode syntax through Security::detectXss() because it contains no literal less-than character, then ColorShortcode.php and related… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Nikstore CoreAI | 19/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Mayosis CoreAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions. | |
| Aplazada | Alta (8.1) | 0.47% | — | Vavo CoreAI | 18/8/2026 | 20/8/2026 | Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions. | |
| Aplazada | Media (6.3) | 0.43% | — | Flyto2 CoreAI | 13/8/2026 | 9/9/2026 | Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that allows attackers to reach internal services by supplying URLs using the unblocked IPv6 address `::` which the kernel routes to loopback identically to `0.0.0.0`. Attackers can submit requests or trigger 302 redirects to `… | |
| Pendiente de análisis | Crítica (9.1) | 0.73% | — | Nextauth.js Next-authAICoreAI | 13/8/2026 | 18/9/2026 | NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the defaultNormalizer used by the email and magic-link sign-in flow validates an address before applying Unicode normalization. An address can contain a Unicode character such as U+FF20 FULLWIDTH… | |
| Aplazada | Alta (8.1) | 0.47% | — | Biagiotti CoreAI | 13/8/2026 | 14/8/2026 | Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions. | |
| Aplazada | Alta (8.1) | 0.47% | — | Foton CoreAI | 13/8/2026 | 14/8/2026 | Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions. | |
| Aplazada | Media (6) | 0.21% | — | Vehica CoreAI | 13/8/2026 | 14/8/2026 | Subscriber Server Side Request Forgery (SSRF) in Vehica Core <= 1.0.104 versions. | |
| Pendiente de análisis | Media (6.8) | 0.25% | — | Nextauth.js Next-authAICoreAI | 12/8/2026 | 9/9/2026 | NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in global cookies that are not bound to the provider that created them. On callback, a check value minted during a… | |
| Pendiente de análisis | Alta (7.5) | 0.88% | — | Nextauth @auth/coreAINextauth.js Next-authAI | 12/8/2026 | 9/9/2026 | NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the exported getToken() helper in the next-auth/jwt and @auth/core/jwt modules can throw an uncaught exception when it reads a malformed Authorization: Bearer header. When no session cookie is present,… |