Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2844▲ 206 respecto a la semana anterior
Críticas / altas1323▼ 110 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
21.079 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.26% | — | Home-assistant IOS Companion APPAI | 29/6/2026 | 30/6/2026 | Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The iOS companion app ignores the SSID allowlist for internal networks. The app uses SSID to detect when to use the internal URL, but whenever the app cannot find any other URL to be used, it fallbacks… | |
| Aplazada | Baja (0.9) | 0.18% | — | Chess Play AND Learn APPAI | 29/6/2026 | 29/6/2026 | A weakness has been identified in Chess Play and Learn App up to 4.9.42 on Android. This issue affects some unknown processing of the file AndroidManifest.xml of the component com.chess. This manipulation causes exposure of backup file to an unauthorized control sphere. It is feasible to perform the attack on the… | |
| Aplazada | Baja (2.1) | 0.43% | — | RagappAI | 28/6/2026 | 29/6/2026 | A vulnerability has been found in RAGapp up to 0.1.5. Affected is the function FileHandler.upload_file/FileHandler.remove_file of the file src/ragapp/backend/controllers/files.py of the component Knowledge File Handler. Such manipulation leads to path traversal. The attack can be executed remotely. The exploit has… | |
| Analizada | Alta (8.6) | 0.53% | 💥 PoC | Max-mapper Extract-zip | 26/6/2026 | 6/7/2026 | extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip will extract the symlink without validation, allowing it to point outside the extraction directory. Depending on how… | |
| Aplazada | Alta (7.1) | 0.23% | — | Simply Schedule AppointmentsAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions. | |
| Aplazada | Alta (7.1) | 0.25% | 💥 PoC | Mappress MapsAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions. | |
| Aplazada | Crítica (9.2) | 0.41% | — | Setracker2 Android Companion APPAI | 26/6/2026 | 3/8/2026 | Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access. | |
| Analizada | Media (5.3) | 0.31% | — | Apple Swiftnio Http/2 | 25/6/2026 | 30/6/2026 | swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control characters before placing them into the translated HTTP/1.1 message. swift-nio-http2 1.44.1 adds validation of all pseudo-header values (:path, :authority, :scheme, :method, and :status) at both the HPACK header validation… | |
| Aplazada | Alta (7.4) | 0.28% | — | Bootstrapped Visual Link PreviewAI | 25/6/2026 | 26/6/2026 | Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions. | |
| Analizada | Media (5.3) | 0.39% | — | Appsmith | 24/6/2026 | 26/6/2026 | Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the outbound HTTP host filter applied by WebClientUtils (used by the REST API and GraphQL datasource plugins) validates hosts against an exact-match string denylist. The comprehensive address-class check (loopback, any-local,… | |
| Analizada | Crítica (9.9) | 0.60% | — | Appsmith | 24/6/2026 | 26/6/2026 | Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-proxy's admin API — which has no authentication by default — is bound on 0.0.0.0:2019 inside the container. While this listener is not directly published to the host by docker-compose.yml, it is… | |
| Analizada | Alta (8.9) | 0.49% | — | Appsmith | 24/6/2026 | 26/6/2026 | Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, Appsmith's bundled supervisord exposes an XML-RPC interface on port 9001, reachable from outside the container via a Caddy reverse-proxy route at /supervisor/* on the public ingress. Combined with the… | |
| Analizada | Media (5.1) | 0.37% | — | Appsmith | 24/6/2026 | 29/6/2026 | Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.99, the POST /api/v1/admin/send-test-email endpoint accepts attacker-controlled smtpHost and smtpPort values and establishes a raw JavaMail TCP connection without any IP validation. This completely bypasses… | |
| Aplazada | Media (4.8) | 0.40% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.ui.Tree component | |
| Aplazada | Media (4.6) | 0.43% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Number Card component. | |
| Aplazada | Media (4.6) | 0.43% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to unsafe evaluation of user-controlled data in the Number Card component. | |
| Aplazada | Media (4.8) | 0.40% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Notifications > Events panel. | |
| Aplazada | Media (4.8) | 0.40% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the MultiSelectDialog component. | |
| Aplazada | Media (4.6) | 0.43% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of untrusted input in the Form Dashboard headline renderer. | |
| Aplazada | Media (4.6) | 0.43% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the File View breadcrumb renderer. | |
| Aplazada | Media (4.8) | 0.40% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Desk desktop icon renderer. | |
| Aplazada | Media (5.1) | 0.45% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the dashboard-view component. | |
| Aplazada | Media (4.6) | 0.43% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.get_avatar function. | |
| Pendiente de análisis | Alta (8.6) | 0.42% | — | Apple M1 GPUAI | 24/6/2026 | 25/6/2026 | Apple M1 GPUs retain register file data between compute shader dispatches from different processes. A sandboxed Metal attacker app can run a GPU reader shader that reads stale register values left by a separate sandboxed victim app. In the proof of concept, GPUVictim.app generates a fresh random 128-bit secret using… | |
| Aplazada | Media (4.6) | 0.53% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev. An authenticated attacker with write access to Auto Repeat can persist HTML/JavaScript in reference_document using a whitelisted write path and trigger script execution when users open the affected Auto Repeat form. |