Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
823 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.18% | — | Space Studio Click AND TweetAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Space Studio Click & Tweet allows Stored XSS. This issue affects Click & Tweet: from n/a through 0.8.9. | |
| Analizada | Media (5.2) | 0.18% | — | Zimaspace Zimaos | 17/9/2025 | 17/6/2026 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and all prior versions, the /v2_1/files/file/uploadV2 endpoint allows file upload from ANY USER who has access to localhost. File uploads are performed AS ROOT. | |
| Analizada | Media (4.8) | 0.21% | — | Zimaspace Zimaos | 17/9/2025 | 17/6/2026 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and earlier, the /v2_1/files/file/download endpoint allows file read from ANY USER who has access to localhost. File reads are performed AS ROOT. | |
| Analizada | Crítica (9.8) | 0.61% | 💥 PoC | Solspace Freeform | 27/8/2025 | 17/6/2026 | Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitrary code injection for all users that have access to editing a form (submission title). | |
| Analizada | Alta (7.5) | 1.4% | 💥 Exploit | Monospace Directus | 20/8/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file update mechanism which allows an unauthenticated actor to modify existing files with arbitrary contents (without changes being applied to the files' database-resident… | |
| Aplazada | Alta (8.8) | 0.33% | — | Real Spaces Wordpress Properties Directory ThemeAI | 19/8/2025 | 17/6/2026 | The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'change_role_member' parameter in all versions up to, and including, 3.5. This is due to a lack of restriction in the profile update role. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Crítica (9.8) | 0.37% | 💥 PoC | Real Spaces Wordpress Properties Directory ThemeAI | 19/8/2025 | 17/6/2026 | The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'imic_agent_register' function in all versions up to, and including, 3.6. This is due to a lack of restriction in the registration role. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (5.9) | 0.22% | — | Keeross Do-spaces-syncAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in keeross DigitalOcean Spaces Sync do-spaces-sync allows Stored XSS.This issue affects DigitalOcean Spaces Sync: from n/a through <= 2.2.1. | |
| Aplazada | Media (5.4) | 0.19% | — | Omnissa Workspace ONE UEMAI | 11/8/2025 | 17/6/2026 | Omnissa Workspace ONE UEM contains a Server-Side Request Forgery (SSRF) Vulnerability. A malicious actor with user privileges may be able to access restricted internal system information, potentially enabling enumeration of internal network resources. | |
| Aplazada | Alta (7.5) | 22% | 💥 Exploit | Omnissa Workspace ONE UEMAI | 11/8/2025 | 17/6/2026 | Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to gain access to sensitive information by sending crafted GET requests (read-only) to restricted API endpoints. | |
| Analizada | Media (4.3) | 0.26% | — | ARM 5TH GEN GPU Architecture Userspace DriverARM Bifrost GPU Userspace DriverARM Valhall GPU Userspace Driver | 4/8/2025 | 17/6/2026 | Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to gain access to already freed memory.This… | |
| Aplazada | Media (6.4) | 0.23% | — | Wpthemespace Magical Addons FOR ElementorAI | 29/7/2025 | 17/6/2026 | The Magical Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Attributes in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.2) | 0.45% | — | DspaceAIApache TomcatAI | 15/7/2025 | 17/6/2026 | DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.4, 8.2, and 9.1, a path traversal vulnerability is possible during the import of an archive (in Simple Archive Format), either from command-line (`./dspace import` command) or from the… | |
| Aplazada | Media (6.9) | 0.41% | — | DspaceAIApache TomcatAI | 15/7/2025 | 17/6/2026 | DSpace open source software is a repository application which provides durable access to digital resources. Two related XML External Entity (XXE) injection possibilities impact all versions of DSpace prior to 7.6.4, 8.2, and 9.1. External entities are not disabled when parsing XML files during import of an archive (in… | |
| Analizada | Media (6.5) | 0.44% | — | Monospace Directus | 15/7/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 11.9.0, Directus Flows with a manual trigger are not validating whether the user triggering the Flow has permissions to the items provided as payload to the Flow. Depending on what the Flow… | |
| Analizada | Media (5.3) | 0.98% | 💥 Exploit | Monospace Directus | 15/7/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, the exact Directus version number is incorrectly being used as OpenAPI Spec version this means that it is being exposed by the `/server/specs/oas` endpoint without authentication.… | |
| Analizada | Media (4.5) | 0.43% | — | Monospace Directus | 15/7/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus Flows with the WebHook trigger all incoming request details are logged including security sensitive data like access and refresh tokens in cookies. Malicious… | |
| Analizada | Media (4.2) | 0.19% | — | Monospace Directus | 15/7/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus Flows to handle CRUD events for users it is possible to log the incoming data to console using the "Log to Console" operation and a template string. Malicious… | |
| Analizada | Media (6.7) | 0.19% | — | Cisco Spaces Connector | 2/7/2025 | 17/6/2026 | A vulnerability in Cisco Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root. This vulnerability is due to insufficient restrictions during the execution of specific CLI commands. An attacker could exploit this… | |
| Analizada | Baja (2) | 0.67% | — | Chatchat-space Langchain-chatchat | 29/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This issue affects some unknown processing of the file /v1/file. The manipulation of the argument flag leads to path traversal. The exploit has been disclosed to the public and may be used. | |
| Analizada | Baja (2.1) | 0.58% | — | Chatchat-space Langchain-chatchat | 29/6/2025 | 17/6/2026 | A vulnerability classified as problematic was found in chatchat-space Langchain-Chatchat up to 0.3.1. This vulnerability affects unknown code of the file /v1/files?purpose=assistants. The manipulation leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Baja (2.1) | 0.58% | — | Chatchat-space Langchain-chatchat | 29/6/2025 | 17/6/2026 | A vulnerability classified as critical has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This affects the function upload_temp_docs of the file /knowledge_base/upload_temp_docs of the component Backend. The manipulation of the argument flag leads to path traversal. It is possible to initiate the attack… | |
| Analizada | Alta (7.3) | 0.13% | — | Citrix Workspace | 17/6/2025 | 17/6/2026 | Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows | |
| Analizada | Alta (7.8) | 0.38% | — | Ivanti Workspace Control | 10/6/2025 | 17/6/2026 | A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt stored SQL credentials. | |
| Analizada | Alta (7.3) | 0.36% | — | Ivanti Workspace Control | 10/6/2025 | 17/6/2026 | A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt the stored environment password. |