Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2861▲ 226 respecto a la semana anterior
Críticas / altas1331▼ 99 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
14.300 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.2) | 0.48% | — | Kidocode Crawl4ai | 22/6/2026 | 30/6/2026 | Crawl4AI before 0.8.7 contains a server-side request forgery vulnerability in the /crawl, /crawl/stream, /md, and /llm endpoints that fetch arbitrary user-supplied URLs without validation. Unauthenticated attackers can bypass the internal-address blocklist using IPv6-mapped IPv4 addresses to reach internal services… | |
| Analizada | Alta (7.5) | 0.29% | — | Chimurai Http-proxy-middleware | 22/6/2026 | 24/6/2026 | http-proxy-middleware is node.js http-proxy middleware. From 3.0.4 until 3.0.7 and 4.1.1, fixRequestBody() is the library's documented helper for re-emitting a request body that was already consumed by a body parser. When the outgoing Content-Type is multipart/form-data, it rebuilds the body with… | |
| Aplazada | Alta (7.6) | 0.31% | — | Mmaitre314 PicklescanAI | 22/6/2026 | 5/10/2026 | picklescan en versiones anteriores a la 0.0.29 no logra detectar archivos pickle maliciosos que explotan la función idlelib.autocomplete.AutoComplete.get_entity en métodos reduce. Los atacantes pueden incrustar código no detectado en archivos pickle que ejecuta comandos arbitrarios cuando son cargados por las víctimas… | |
| Aplazada | Alta (7.6) | 0.47% | — | Mmaitre314 PicklescanAI | 22/6/2026 | 5/10/2026 | picklescan antes de la versión 0.0.30 (versiones afectadas 0.0.26 y anteriores) no detecta la función incorporada ensurepip._run_pip al escanear archivos pickle, permitiendo a los atacantes ejecutar código arbitrario. Los archivos pickle maliciosos que incrustan llamadas a ensurepip._run_pip en métodos __reduce__… | |
| Aplazada | Alta (7.6) | 0.38% | — | Numpy F2pyAIMmaitre314 PicklescanAI | 22/6/2026 | 5/10/2026 | Picklescan anterior a la versión 0.0.33 no detecta el gadget numpy.f2py.crackfortran._eval_length en los métodos __reduce__ de pickle, permitiendo la ejecución de código arbitrario. Los atacantes pueden crear archivos pickle maliciosos que ejecutan código Python arbitrario cuando son cargados por víctimas que confían… | |
| Analizada | Media (5.5) | 0.21% | — | Langchain | 22/6/2026 | 26/6/2026 | LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths or expand search patterns do not consistently confine the resolved path to the intended root directory. Affected behaviors include: a file-search agent middleware that… | |
| Analizada | Media (6.9) | 0.38% | — | Chimurai Http-proxy-middleware | 22/6/2026 | 26/6/2026 | http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middleware documents router proxy-table entries as host, path, or host+path selectors, but the host+path implementation uses unanchored substring matching on attacker-controlled request metadata. As a result,… | |
| Analizada | Baja (1.7) | 0.46% | — | Aiohttp | 22/6/2026 | 16/9/2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or similar limited resource, then an attacker may be able to cause resource starvation… | |
| Analizada | Baja (1.3) | 0.49% | — | Aiohttp | 22/6/2026 | 26/6/2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their host-only status. This vulnerability is fixed in 3.14.1. | |
| Analizada | Media (6.6) | 0.49% | — | Aiohttp | 22/6/2026 | 26/6/2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a compressed payload in specific situations that could be decompressed into memory,… | |
| Analizada | Media (6.6) | 0.56% | — | Aiohttp | 22/6/2026 | 30/6/2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, it is possible to bypass the max_line_size check in parts of an HTTP request in the C parser. If using the optimised C parser (the default in pre-built wheels), then an attacker may be able to send oversized lines through… | |
| Analizada | Media (6.3) | 0.31% | — | Aiohttp | 22/6/2026 | 17/9/2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This likely requires an open redirect vulnerability or similar on the target domain for an attacker to be able to execute.… | |
| Analizada | Baja (2.7) | 0.47% | — | Aiohttp | 22/6/2026 | 26/6/2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS SNI check can be bypassed when an existing connection is reused. If an application makes multiple requests to the same domain, but with different per-request server_hostname parameters, then the… | |
| Analizada | Media (6.6) | 0.54% | — | Aiohttp | 22/6/2026 | 26/6/2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large incomplete websocket frame payloads, it may be possible to bypass the usual size limits on memory use. This vulnerability is fixed in 3.14.1. | |
| Analizada | Media (6.6) | 0.49% | — | Aiohttp | 22/6/2026 | 26/6/2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on the number of pipelined requests that could be queued. An attacker may be able to use pipelined requests to use excessive amounts of memory, potentially leading to DoS. This vulnerability is fixed… | |
| Analizada | Baja (2.7) | 0.53% | — | Aiohttp | 22/6/2026 | 26/6/2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled input included into multipart/payload headers can be used to modify a request to inject additional headers or similar. In the unlikely situation that an application is passing user-controlled strings… | |
| Analizada | Media (5.9) | 0.53% | — | Redhat Openshift Container PlatformRedhat Enterprise LinuxThekelleys Dnsmasq | 22/6/2026 | 31/8/2026 | A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may… | |
| Aplazada | Media (5.1) | 0.58% | — | AILAI | 22/6/2026 | 22/6/2026 | AIL did not restrict repeated failed attempts to verify a two-factor authentication (OTP) code. An attacker who had reached the 2FA verification step, such as after successfully completing the password-authentication stage, could submit an unlimited number of OTP guesses. This could enable brute-force guessing of a… | |
| Aplazada | Alta (8.3) | 0.44% | — | Circl AIL FrameworkAI | 22/6/2026 | 22/6/2026 | A path traversal vulnerability exists in AIL Framework before the release containing commit 0041456af25da0cdea1c1c4624e46baff2731d8f. An authenticated AIL user can supply crafted object identifiers through the investigation workflow to cause file paths to resolve outside the intended image, favicon, or screenshot… | |
| Modificada | Alta (8.3) | 0.30% | — | Redhat Openshift Container PlatformRedhat Windows Machine Config Operator | 22/6/2026 | 9/9/2026 | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An adjacent-network attacker who can intercept or redirect WMCO's SSH session can capture WICD and kubelet… | |
| Modificada | Alta (8.8) | 0.11% | — | Redhat Openshift Container PlatformRedhat Windows Machine Config Operator | 22/6/2026 | 9/9/2026 | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows… | |
| Aplazada | Alta (8.8) | 0.42% | — | ChainlitAI | 22/6/2026 | 8/10/2026 | Chainlit before 2.10.1 contains a session hijacking vulnerability that allows unauthenticated attackers to restore and inherit authenticated user sessions by presenting a valid sessionId during WebSocket session restoration without ownership verification. Attackers can exploit the restore_existing_session path to… | |
| Aplazada | Baja (2.1) | 0.49% | — | Flowiseai FlowiseAI | 22/6/2026 | 22/6/2026 | A vulnerability was determined in FlowiseAI Flowise up to 3.1.2. The impacted element is an unknown function of the file packages/components/nodes/documentloaders/S3/S3.ts of the component S3 Document Loader. Executing a manipulation can lead to path traversal. It is possible to launch the attack remotely. The vendor… | |
| Aplazada | Baja (2.1) | 0.50% | — | Kortix-ai SunaAI | 21/6/2026 | 23/6/2026 | A weakness has been identified in kortix-ai suna up to 0.8.38. Affected by this issue is the function router.replace/router.push of the file apps/frontend/src/app/auth/page.tsx of the component Auth Endpoint. Executing a manipulation of the argument returnURL can lead to cross site scripting. The attack may be… | |
| Analizada | Crítica (9.3) | 2.6% | 💥 Exploit | Kidocode Crawl4ai | 21/6/2026 | 26/6/2026 | Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers who know the default key can forge valid authentication tokens for any user, bypassing authentication and gaining full access to protected functionality. |