Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2844▲ 206 respecto a la semana anterior
Críticas / altas1323▼ 110 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

21.079 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.26%—Home-assistant IOS Companion APPAI29/6/202630/6/2026
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The iOS companion app ignores the SSID allowlist for internal networks. The app uses SSID to detect when to use the internal URL, but whenever the app cannot find any other URL to be used, it fallbacks…
AplazadaBaja (0.9)0.18%—Chess Play AND Learn APPAI29/6/202629/6/2026
A weakness has been identified in Chess Play and Learn App up to 4.9.42 on Android. This issue affects some unknown processing of the file AndroidManifest.xml of the component com.chess. This manipulation causes exposure of backup file to an unauthorized control sphere. It is feasible to perform the attack on the…
AplazadaBaja (2.1)0.43%—RagappAI28/6/202629/6/2026
A vulnerability has been found in RAGapp up to 0.1.5. Affected is the function FileHandler.upload_file/FileHandler.remove_file of the file src/ragapp/backend/controllers/files.py of the component Knowledge File Handler. Such manipulation leads to path traversal. The attack can be executed remotely. The exploit has…
AnalizadaAlta (8.6)0.53%💥 PoCMax-mapper Extract-zip26/6/20266/7/2026
extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip will extract the symlink without validation, allowing it to point outside the extraction directory. Depending on how…
AplazadaAlta (7.1)0.23%—Simply Schedule AppointmentsAI26/6/202626/6/2026
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions.
AplazadaAlta (7.1)0.25%💥 PoCMappress MapsAI26/6/202626/6/2026
Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions.
AplazadaCrítica (9.2)0.41%—Setracker2 Android Companion APPAI26/6/20263/8/2026
Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. This could allow an attacker, who knows the hash, to authenticate and gain full access.
AnalizadaMedia (5.3)0.31%—Apple Swiftnio Http/225/6/202630/6/2026
swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control characters before placing them into the translated HTTP/1.1 message. swift-nio-http2 1.44.1 adds validation of all pseudo-header values (:path, :authority, :scheme, :method, and :status) at both the HPACK header validation…
AplazadaAlta (7.4)0.28%—Bootstrapped Visual Link PreviewAI25/6/202626/6/2026
Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions.
AnalizadaMedia (5.3)0.39%—Appsmith24/6/202626/6/2026
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the outbound HTTP host filter applied by WebClientUtils (used by the REST API and GraphQL datasource plugins) validates hosts against an exact-match string denylist. The comprehensive address-class check (loopback, any-local,…
AnalizadaCrítica (9.9)0.60%—Appsmith24/6/202626/6/2026
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-proxy's admin API — which has no authentication by default — is bound on 0.0.0.0:2019 inside the container. While this listener is not directly published to the host by docker-compose.yml, it is…
AnalizadaAlta (8.9)0.49%—Appsmith24/6/202626/6/2026
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, Appsmith's bundled supervisord exposes an XML-RPC interface on port 9001, reachable from outside the container via a Caddy reverse-proxy route at /supervisor/* on the public ingress. Combined with the…
AnalizadaMedia (5.1)0.37%—Appsmith24/6/202629/6/2026
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.99, the POST /api/v1/admin/send-test-email endpoint accepts attacker-controlled smtpHost and smtpPort values and establishes a raw JavaMail TCP connection without any IP validation. This completely bypasses…
AplazadaMedia (4.8)0.40%—Frappe FrameworkAI24/6/202625/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.ui.Tree component
AplazadaMedia (4.6)0.43%—Frappe FrameworkAI24/6/202625/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Number Card component.
AplazadaMedia (4.6)0.43%—Frappe FrameworkAI24/6/202625/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to unsafe evaluation of user-controlled data in the Number Card component.
AplazadaMedia (4.8)0.40%—Frappe FrameworkAI24/6/202625/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Notifications > Events panel.
AplazadaMedia (4.8)0.40%—Frappe FrameworkAI24/6/202625/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the MultiSelectDialog component.
AplazadaMedia (4.6)0.43%—Frappe FrameworkAI24/6/202625/6/2026
A Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of untrusted input in the Form Dashboard headline renderer.
AplazadaMedia (4.6)0.43%—Frappe FrameworkAI24/6/202625/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the File View breadcrumb renderer.
AplazadaMedia (4.8)0.40%—Frappe FrameworkAI24/6/202625/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Desk desktop icon renderer.
AplazadaMedia (5.1)0.45%—Frappe FrameworkAI24/6/202625/6/2026
A Reflected Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the dashboard-view component.
AplazadaMedia (4.6)0.43%—Frappe FrameworkAI24/6/202625/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.get_avatar function.
Pendiente de análisisAlta (8.6)0.42%—Apple M1 GPUAI24/6/202625/6/2026
Apple M1 GPUs retain register file data between compute shader dispatches from different processes. A sandboxed Metal attacker app can run a GPU reader shader that reads stale register values left by a separate sandboxed victim app. In the proof of concept, GPUVictim.app generates a fresh random 128-bit secret using…
AplazadaMedia (4.6)0.53%—Frappe FrameworkAI24/6/202625/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev. An authenticated attacker with write access to Auto Repeat can persist HTML/JavaScript in reference_document using a whitelisted write path and trigger script execution when users open the affected Auto Repeat form.