Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
23.893 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.31% | — | Ss-proj ShirasagiAI | 10/9/2026 | 10/9/2026 | An authorization bypass vulnerability exists in SHIRASAGI through a user-controlled key, which may allow an unauthorized attacker to retrieve files from the groupware's shared file feature. | |
| Aplazada | Media (5.1) | 0.24% | — | Ss-proj ShirasagiAI | 10/9/2026 | 10/9/2026 | A cross-site scripting vulnerability exists in SHIRASAGI, which may allow an attacker to execute an arbitrary script in the web browser of a user who accesses a website using the affected product. | |
| Pendiente de análisis | Media (5.4) | 0.16% | — | Zephyrproject ZephyrAI | 9/9/2026 | 10/9/2026 | The Bluetooth Classic (BR/EDR) L2CAP receive handler bt_l2cap_br_recv() in subsys/bluetooth/host/classic/l2cap_br.c dispatched inbound data PDUs based only on the destination channel ID, without checking that the target channel had reached the BT_L2CAP_CONNECTED state. A dynamic channel is assigned its RX CID and… | |
| Analizada | Alta (7.1) | 0.41% | — | Gitpython Project Gitpython | 9/9/2026 | 16/9/2026 | GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover… | |
| Analizada | Alta (8.7) | 0.40% | — | Gitpython Project Gitpython | 9/9/2026 | 16/9/2026 | GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim… | |
| Analizada | Alta (8.7) | 0.52% | — | Gitpython Project Gitpython | 9/9/2026 | 18/9/2026 | GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containing an unterminated angle bracket to cause quadratic backtracking, exhausting CPU… | |
| Aplazada | Media (6.1) | 0.26% | — | Html Formhandler Project Html FormhandlerAI | 8/9/2026 | 10/9/2026 | HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping. The Table form layout and the Bootstrap 2 and 3 wrappers splice each error string straight into the surrounding markup. Version 0.410000, the fix for CVE-2026-19872, escaped the equivalent values in the other… | |
| Aplazada | Alta (8.6) | 0.47% | — | Lfprojects MlflowAI | 8/9/2026 | 9/9/2026 | Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Springboot-projectAI | 8/9/2026 | 9/9/2026 | Incorrect access control in the SellerAuthorizeAspect component of springboot-project v1.0.0 allows unauthenticated attackers to access all seller management interfaces and list all products/orders, put products on/off sale, finish/cancel orders, and modify categories without authentication. | |
| Aplazada | Media (6.4) | 0.33% | — | Zephyr Project ManagerAI | 8/9/2026 | 8/9/2026 | The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 3.3.205 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Custom-level access and above, to… | |
| Aplazada | Media (5.5) | 0.53% | — | Code-projects Student Crud OperationAI | 8/9/2026 | 11/9/2026 | A vulnerability was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the file /card_activation.sql of the component Backup File Handler. The manipulation results in information disclosure. The attack can be launched remotely. The exploit has been made public and could be used. | |
| Aplazada | Baja (2.1) | 0.33% | — | Code-projects Student Crud OperationAI | 8/9/2026 | 28/9/2026 | A vulnerability has been found in code-projects Student Crud Operation 1.0. This affects an unknown function of the file /edit.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Baja (2.3) | 0.66% | — | Ash-project Usage RulesAI | 8/9/2026 | 8/9/2026 | Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project usage_rules allows a malicious package publisher to inject terminal control sequences into the output of mix usage_rules.search_docs. mix usage_rules.search_docs searches Hex documentation through search.hexdocs.pm, which… | |
| Aplazada | Media (6.3) | 0.69% | — | Ash-project ASH Authentication Oauth2 ServerAI | 7/9/2026 | 8/9/2026 | Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to register OAuth clients even when Dynamic Client Registration is gated by an initial access token. resolve_secret/3 in AshAuthentication.Oauth2Server (reached through __resolve_secret__!) treated… | |
| Aplazada | Media (6.3) | 0.66% | — | Ash-project ASH Authentication Oauth2 ServerAI | 7/9/2026 | 8/9/2026 | Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an attacker who controls a client metadata URL and its DNS to make the server connect to internal or loopback addresses. public_ip?/1 in AshAuthentication.Oauth2Server.CIMD.ReqFetcher enforces the outbound policy… | |
| Aplazada | Media (6.3) | 0.68% | — | Ash-project ASH Authentication Oauth2 ServerAI | 7/9/2026 | 8/9/2026 | Improper Encoding or Escaping of Output vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to inject arbitrary authentication parameters into the WWW-Authenticate challenge header. BearerPlug and RequireScopePlug built the Bearer resource_metadata="..." challenge by… | |
| Aplazada | Media (6.3) | 0.66% | — | Ash-project ASH Authentication Oauth2 ServerAI | 7/9/2026 | 8/9/2026 | Use of Cache Containing Sensitive Information vulnerability in ash-project ash_authentication_oauth2_server allows a shared HTTP cache to serve one tenant's OAuth discovery metadata to another tenant's clients. The RFC 8414 and RFC 9728 metadata endpoints in AshAuthentication.Phoenix.Oauth2Server.ProtocolRouter return… | |
| Aplazada | Media (6.3) | 0.69% | — | Ash-project ASH Authentication Oauth2 ServerAI | 7/9/2026 | 8/9/2026 | Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server exposes the state-changing OAuth endpoints under an unintended URL prefix, bypassing controls scoped to the canonical prefix. oauth2_server_protocol_routes/1 in AshAuthentication.Phoenix.Oauth2Server.Router forwards the… | |
| Aplazada | Alta (8.2) | 0.66% | — | Ash-project ASH Authentication Oauth2 ServerAI | 7/9/2026 | 8/9/2026 | Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to exhaust database storage and memory. The /authorize endpoint is unauthenticated by design. With Client ID Metadata Documents enabled, resolve_client/3 in… | |
| Aplazada | Alta (8.2) | 0.52% | — | Ash-project ASH LUAAI | 7/9/2026 | 8/9/2026 | Improper Protection of Alternate Path vulnerability in ash-project ash_lua allows a user-supplied Lua script to read attributes that are not on the exposed-field allow-list. AshLua exposes Ash resources to Lua scripts, gated by a manifest declaring which fields are exposed. The read action's operation aggregate path… | |
| Aplazada | Baja (2.1) | 0.19% | — | Ash-project ASH Double EntryAI | 7/9/2026 | 8/9/2026 | Improper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier. AshDoubleEntry.ULID renders a 128-bit ULID as 26 Crockford base-32 characters, but the first character encodes only 3 bits, so canonical values… | |
| Aplazada | Baja (2.3) | 0.53% | — | Ash-project IgniterAI | 7/9/2026 | 28/9/2026 | Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project igniter allows a malicious package publisher to forge the mix igniter.install confirmation prompt. mix igniter.install prints a confirmation panel (an anti-typosquatting safeguard) listing a package's hex metadata before adding… | |
| Aplazada | Alta (7.5) | 0.61% | — | NET IP LPM Project NET IP LPMAI | 7/9/2026 | 8/9/2026 | Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths. Non-numeric and non-ASCII prefix lengths are accepted and treated as 0. Integers over 31 bits are silently truncated. A single malformed mask will poison the lookup table. The result is that the lookup will silently succeed for every address.… | |
| Pendiente de análisis | Alta (8.4) | 0.48% | 💥 PoC | 389 Project 389 DS BaseAICockpit 389 ConsoleAI | 7/9/2026 | 8/9/2026 | A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN… | |
| Pendiente de análisis | Alta (7.5) | 0.85% | — | 389 Project 389 Directory ServerAI | 7/9/2026 | 9/9/2026 | A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests using the USE_ONE_BACKEND control, resulting in denial of service. |