Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3074▲ 486 respecto a la semana anterior
Críticas / altas1457▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

23.740 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.56%—Supsystic Easy Google MapsAI18/8/202620/8/2026
Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
Pendiente de análisisAlta (8.8)0.81%—Redhat Advanced Cluster Management FOR KubernetesAIRedhat Governance Policy Addon ControllerAI18/8/202627/8/2026
A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container image. This allows an attacker to run a controlled image with…
AnalizadaCrítica (9.3)0.28%—Gohugo Hugo18/8/202629/9/2026
Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, Babel, or TailwindCSS could not reach the file system outside the project directory. Hugo 0.162.0 added tailwindcss to the AllowChildProcess default in config/security/securityConfig.go, which makes…
AplazadaMedia (5.9)0.26%—GoshsAI18/8/202618/9/2026
goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit` under `RLock`, releases the lock, serves the file, then re-acquires the lock to increment the counter. Concurrent requests all read the same `Downloaded`/`DownloadLimit` snapshot, all pass the…
AplazadaAlta (8.1)0.38%—GoshsAI18/8/202618/9/2026
goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `--read-only`, `--upload-only`, and `--no-delete` are enforced only on the primary HTTP port. The WebDAV port is wired straight to `golang.org/x/net/webdav.Handler` with no…
Pendiente de análisisCrítica (9.4)0.34%—Google Chronicle SoarAI17/8/202631/8/2026
A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to execute blind SQL queries using a crafted request parameter. This vulnerability was patched in version 6.3.85, and no…
AplazadaMedia (5.3)0.37%—Gomarble-ai Facebook-ads-mcp-serverAI16/8/202620/8/2026
A vulnerability has been found in gomarble-ai facebook-ads-mcp-server 0.1.0. The impacted element is the function fetch_pagination_url of the file server.py. Such manipulation leads to server-side request forgery. The attack can be launched remotely. The name of the patch is 4e53875aa22e8991c2fa4a7660d86e1caba66659.…
Pendiente de análisisAlta (7.5)0.41%—Golang X ImageAI14/8/20263/9/2026
VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion.
AplazadaMedia (6.9)0.24%—Go-chi CHIAI14/8/20268/10/2026
go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating trusted proxies. A malicious client can prepend a forged IP as the first value of the…
AplazadaMedia (6.9)0.30%—Go-chi CHIAI14/8/20268/10/2026
go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() function reads client-controlled headers (True-Client-IP, X-Real-IP, and X-Forwarded-For) and overwrites r.RemoteAddr without verifying that the request originated from a trusted proxy.…
AplazadaMedia (6.9)0.50%💥 PoCGo-chi CHIAI14/8/20268/10/2026
go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. A remote attacker can bypass IP-based access control lists and rate-limiting mechanisms, and forge log entries, by supplying a…
AplazadaMedia (6.8)0.43%💥 PoCEmbed Google Photos AlbumAI14/8/202626/8/2026
The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputting it inside an HTML attribute, allowing users with the Contributor role or above to inject arbitrary JavaScript that executes in the browser of any user, including administrators, who views the…
AplazadaBaja (2)0.35%—Sourcecodester AIR Cargo Management SystemAI14/8/202614/8/2026
A vulnerability was determined in SourceCodester Air Cargo Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_cargo_type. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and…
AplazadaAlta (8.3)0.35%—BudibaseAIGoogle FirebaseAI13/8/202631/8/2026
Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection strings and Firebase private keys in plaintext. Attackers with table read permissions can retrieve datasource configurations through the read API to obtain live backend…
Pendiente de análisisAlta (8.4)0.13%—GOAI13/8/20263/9/2026
A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache. This attack allows for a malicious GOPROXY to serve malicious module content that cannot be detected by…
Pendiente de análisisAlta (7.5)0.30%—Google GOAI13/8/20263/9/2026
A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log. In order to determine if you have been…
AplazadaMedia (5.3)0.29%—Django-helpdeskAI13/8/20269/9/2026
django-helpdesk before 2.3.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary JavaScript by submitting HTML-formatted email messages or uploading .html/.htm file attachments through public ticket submission channels. Attackers can exploit the lack of…
AnalizadaCrítica (9.3)0.33%—Sangoma Freepbx13/8/20269/10/2026
FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/lib/server.js, but Socket.IO version 4 applies that middleware only to the default namespace. An unauthenticated client can connect to custom namespaces that do not consistently invoke checkAuth…
AnalizadaCrítica (9.3)0.38%—Sangoma Freepbx13/8/20269/10/2026
FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into the missedcalllog INSERT in agi-bin/missedcallnotify.php without escaping or bound parameters. An unauthenticated caller can inject SQL when a…
AnalizadaAlta (7.6)0.88%—Sangoma Freepbx13/8/20269/10/2026
FreePBX is an open source IP PBX. From 17.0.1 until 17.0.7, the FreePBX Music on Hold module permits dangerous command-line options for /usr/bin/mpg123 and other allowed players in validateCustomConfiguration() in Music.class.php. An authenticated administrator can use options that write files, open control channels,…
AnalizadaAlta (8.6)0.31%—Sangoma Freepbx13/8/20269/10/2026
FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.30, the FreePBX Framework module permits a crafted backup to restore the hidden AUTHTYPE setting with the value none through runRestore() in amp_conf/htdocs/admin/libraries/Builtin/Restore.php. An authenticated user with sufficient backup-restore access or…
AplazadaAlta (8.2)0.43%—SvgoAI13/8/202618/9/2026
SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named removeScriptElement in versions 1 through 3, can leave executable content in optimized SVGs because it does not remove…
AplazadaMedia (5.3)0.38%—Golang GOAI13/8/202626/8/2026
Private Repository Existence Disclosure via go-get Meta Endpoint
Pendiente de análisisMedia (6.5)0.50%—MongooseAI13/8/202618/9/2026
Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.24.1, and 9.7.2, passing a user-controlled update such as MyModel.updateOne(filter, req.body) can exploit Mongoose update casting with a __proto__.x dotted path under $set. Schema.prototype.path and…
AplazadaCrítica (9.8)0.27%—LOG IN With GoogleAI13/8/202614/8/2026
Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.