Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
1062 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.76% | — | Hostbillapp HostbillAI | 24/4/2026 | 17/6/2026 | An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of service via the Checkout Authentication Flow component | |
| Aplazada | Baja (3.8) | 0.57% | — | Hostbillapp HostbillAI | 24/4/2026 | 17/6/2026 | An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of service via the Client Balance component | |
| Aplazada | Media (4.9) | 0.86% | — | Hostbillapp HostbillAI | 24/4/2026 | 17/6/2026 | Cross Site Scripting vulnerability in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code | |
| Aplazada | Media (6.1) | 0.32% | — | Kibokolabs HostelAI | 18/4/2026 | 17/6/2026 | The Hostel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode_id' parameter in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Crítica (9.8) | 1.2% | — | Hostbillapp HostbillAI | 14/4/2026 | 17/6/2026 | An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privileges via the CSV registration field | |
| Analizada | Crítica (9.3) | 0.61% | — | Codefuture Image Hosting Script | 12/4/2026 | 17/6/2026 | CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by accessing the imgdb.db file in the upload/data directory. Attackers can extract delete IDs stored in plaintext from the deserialized database and use them to delete all pictures via the d parameter. | |
| Aplazada | Media (4.7) | 0.28% | — | Wpplugins Hide MY WP GhostAI | 8/4/2026 | 24/7/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in John Darrel Hide My WP Ghost hide-my-wp allows Phishing.This issue affects Hide My WP Ghost: from n/a through < 7.0.00. | |
| Analizada | Baja (2.3) | 0.37% | — | Nhost/auth | 6/4/2026 | 17/6/2026 | Nhost is an open source Firebase alternative with GraphQL. Prior to 0.48.0, the auth service's OAuth provider callback flow places the refresh token directly into the redirect URL as a query parameter. Refresh tokens in URLs are logged in browser history, server access logs, HTTP Referer headers, and proxy/CDN logs.… | |
| Aplazada | Alta (8.7) | 0.22% | — | SzafirhostAI | 2/4/2026 | 17/6/2026 | SzafirHost downloads necessary files in the context of the initiating web page. When called, SzafirHost updates its dynamic library. JAR files are correctly verified based on a list of trusted file hashes, and if a file was not on that list, it was checked to see if it had been digitally signed by the vendor. The… | |
| Analizada | Alta (7.7) | 0.60% | 💥 PoC | Nhost CLI | 31/3/2026 | 24/7/2026 | Nhost is an open source Firebase alternative with GraphQL. Prior to version 1.41.0, The Nhost CLI MCP server, when explicitly configured to listen on a network port, applies no inbound authentication and does not enforce strict CORS. This allows a malicious website visited on the same machine to issue cross-origin… | |
| Analizada | Alta (8.1) | 0.42% | — | Solarwinds Observability Self-hosted | 26/3/2026 | 17/6/2026 | SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution. | |
| Analizada | Alta (8.7) | 0.45% | — | Solarwinds Observability Self-hosted | 26/3/2026 | 17/6/2026 | SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution. | |
| Aplazada | Alta (7.1) | 0.18% | — | Whmc Sdes Phox HostingAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WHMCSdes Phox Hosting phox-host allows Reflected XSS.This issue affects Phox Hosting: from n/a through <= 2.0.8. | |
| Analizada | Baja (2.1) | 0.20% | — | Nhost Storage | 20/3/2026 | 17/6/2026 | Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.12.0, the storage service's file upload handler trusts the client-provided Content-Type header without performing server-side MIME type detection. This allows an attacker to upload files with an arbitrary MIME type, bypassing any… | |
| Analizada | Alta (8.8) | 0.51% | — | Ghostty | 10/3/2026 | 17/6/2026 | Ghostty is a cross-platform terminal emulator. Ghostty allows control characters such as 0x03 (Ctrl+C) in pasted and dropped text. These can be used to execute arbitrary commands in some shell environments. This attack requires an attacker to convince the user to copy and paste or drag and drop malicious text. The… | |
| Analizada | Alta (8.8) | 0.19% | — | Ghost | 7/3/2026 | 17/6/2026 | Ghost is a Node.js content management system. From version 5.101.6 to 6.19.2, incomplete CSRF protections around /session/verify made it possible to use OTCs in login sessions different from the requesting session. In some scenarios this might have made it easier for phishers to take over a Ghost site. This issue has… | |
| Analizada | Crítica (9.3) | 0.63% | — | Ghostfolio | 6/3/2026 | 17/6/2026 | Ghostfolio is an open source wealth management software. Prior to version 2.244.0, by bypassing symbol validation, an attacker can execute arbitrary SQL commands via the getHistorical() method, potentially allowing them to read, modify, or delete sensitive financial data for all users in the database. This issue has… | |
| Analizada | Crítica (9.3) | 0.36% | — | Ghostfolio | 6/3/2026 | 17/6/2026 | Ghostfolio is an open source wealth management software. Prior to version 2.245.0, an attacker can exploit the manual asset import feature to perform a full-read SSRF, allowing them to exfiltrate sensitive cloud metadata (IMDS) or probe internal network services. This issue has been patched in version 2.245.0. | |
| Analizada | Crítica (9.8) | 5.0% | 💥 Exploit | Ghost | 5/3/2026 | 17/6/2026 | Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the server running Ghost. This issue has been patched in version 6.19.1. | |
| Analizada | Media (6.1) | 0.39% | — | Localhostlabs Karakeep | 25/2/2026 | 17/6/2026 | Karakeep is a elf-hostable bookmark-everything app. In version 0.30.0, when the Reddit metascraper plugin returns `readableContentHtml`, the HTML parsing subprocess uses it directly without running it through DOMPurify. Every other content source in the crawler goes through Readability + DOMPurify, but the Reddit path… | |
| Aplazada | Media (4) | 0.27% | — | Akamai GhostAIAkamai CDNAI | 23/2/2026 | 17/6/2026 | Akamai Ghost on Akamai CDN edge servers before 2026-02-06 mishandles processing of custom hop-by-hop HTTP headers, where an incoming request containing the header "Connection: Transfer-Encoding" could result in a forward request with invalid message framing, depending on the Akamai processing path. This could result… | |
| Aplazada | Alta (8.1) | 0.34% | — | Ancorahemes UnlimhostAI | 20/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes UnlimHost unlimhost allows PHP Local File Inclusion.This issue affects UnlimHost: from n/a through <= 1.2.3. | |
| Aplazada | Alta (7.5) | 0.25% | — | Ghostpool GaugeAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in GhostPool Gauge gauge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gauge: from n/a through <= 6.56.4. | |
| Aplazada | Alta (7.5) | 0.25% | — | Ghostpool Aardvark PluginAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in GhostPool Aardvark Plugin aardvark-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Aardvark Plugin: from n/a through <= 2.19. | |
| Aplazada | Alta (7.1) | 0.24% | — | Ghostpool AardvarkAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhostPool Aardvark aardvark allows Reflected XSS.This issue affects Aardvark: from n/a through <= 4.6.3. |