Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3082▲ 502 respecto a la semana anterior
Críticas / altas1460▲ 59 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
23.740 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.17% | — | Mongodb | 11/8/2026 | 25/9/2026 | An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileges on one encrypted collection to cause unauthorized modification or destruction of data belonging to a different collection. This is due to insufficient validation of certain internal metadata… | |
| Analizada | Alta (7.1) | 0.49% | — | Mongodb | 11/8/2026 | 25/9/2026 | An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to cause an internal reference to be used after the underlying memory has been freed, when running certain queries against time-series collections. This could result in a server crash or disclosure of… | |
| Pendiente de análisis | Alta (7.5) | 0.16% | — | Google TurbiniaAI | 11/8/2026 | 26/8/2026 | Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evidence path/name obtains code execution on the worker fleet. Fixed on 2026-07-10. | |
| Pendiente de análisis | Alta (7.8) | 0.19% | — | Google GenkitAI | 11/8/2026 | 26/8/2026 | Genkit does not properly validate host request headers. Any host on the developer's network, and any website the developer visits (via DNS rebinding), can reach POST /api/runAction on the Dev UI server (default port 4000) and execute any registered Genkit action and read the result. Fixed on 2026-06-18. | |
| Pendiente de análisis | Media (5.3) | 0.24% | — | Siemens Desigo Dxr2AISiemens Desigo Pxc3AISiemens Desigo Pxc4AISiemens Desigo Pxc5.e003AI+2 | 11/8/2026 | 28/8/2026 | A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3 (All versions < V01.21.233.16-7862), Desigo PXC4 (All versions < V02.21.194.36-2715), Desigo PXC5.E003 (All versions < V02.21.194.36-2715), Desigo PXC5.E24 (All versions < V02.21.194.36-2715), Desigo PXC7 (All versions… | |
| Pendiente de análisis | Alta (7) | 0.11% | — | Siemens Logo Soft ComfortAI | 11/8/2026 | 28/8/2026 | A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). The project password feature in the affected products stores the password as an unsalted SHA-256 hash. This could allow an attacker who has obtained the project file to perform efficient offline dictionary or brute-force attacks against the… | |
| Pendiente de análisis | Alta (7) | 0.15% | — | Siemens Logo Soft ComfortAI | 11/8/2026 | 28/8/2026 | A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). Affected products use a static, hardcoded AES master key to encrypt project files. This could allow a local attacker to extract the master key from the application files or memory and use it to decrypt project files or remove project… | |
| Pendiente de análisis | Media (6.1) | 0.34% | — | SWC Html MinifierAIGO HtmlAI | 11/8/2026 | 18/9/2026 | SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0, the minifyJson processing in crates/swc_html_minifier/src/lib.rs parsed and serialized attacker-controlled JSON in application/json and application/ld+json script elements without the… | |
| Aplazada | Alta (8.8) | 0.40% | — | Goauthentik AuthentikAI | 11/8/2026 | 3/9/2026 | A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to take over any user account including superusers by provisioning a SCIM user that matches an existing local user by username. The SCIM user ingest function adopts… | |
| Aplazada | Alta (8.8) | 0.42% | — | Goauthentik AuthentikAI | 11/8/2026 | 3/9/2026 | A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to gain superuser privileges by provisioning a SCIM group that matches an existing administrator group by name. The SCIM group ingest function adopts any existing group… | |
| Aplazada | Media (4.3) | 0.25% | — | Lingotek RAY Enterprise TranslationAI | 11/8/2026 | 26/8/2026 | The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated user, including Subscribers, to add or delete the site's configured languages. | |
| Aplazada | Media (6.5) | 0.30% | — | Lingotek RAY Enterprise TranslationAI | 11/8/2026 | 26/8/2026 | The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated user, including Subscribers, to overwrite the administrator-configured translation API token with an arbitrary value. | |
| Pendiente de análisis | Alta (7.6) | 0.51% | — | Data Science PipelinesAIArgoproj Argo WorkflowsAI | 10/8/2026 | 8/9/2026 | A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of the attacker.… | |
| Pendiente de análisis | Alta (7.5) | 0.83% | — | Google Ml-metadataAI | 10/8/2026 | 21/9/2026 | A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to known HTTP/2 denial of service (DoS) issues. An in-cluster attacker, with network access to the MLMD pod, could exploit these vulnerabilities by sending specially crafted HTTP/2 requests. This could… | |
| Aplazada | Alta (7) | 0.17% | — | Block GooseAI | 10/8/2026 | 9/9/2026 | goose is general-purpose AI agent that runs on your machine. Prior to 1.44.0, the `goose review` command runs the system `git` executable to gather the diff for review without stripping attacker-controlled Git configuration. A malicious repository whose `.git/config` sets [`core] fsmonitor = <command>` causes Git to… | |
| Aplazada | Alta (7.5) | 0.63% | — | Frangoteam FuxaAI | 10/8/2026 | 28/8/2026 | A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated remote attacker to query all historical sensor data via the DAQ_QUERY Socket.IO event. When secureEnabled=true, all other sensitive Socket.IO events (DEVICE_BROWSE, HOST_INTERFACES, DEVICE_TAGS_REQUEST, etc.) call… | |
| Aplazada | Crítica (9.6) | 0.44% | — | PangolinAI | 10/8/2026 | 28/8/2026 | An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to authenticate to any resource in any organization by reusing an access token issued for a different resource. | |
| Aplazada | Baja (2.3) | 0.17% | — | Ecovacs PRO APPAIApple IOSAIGoogle AndroidAI | 10/8/2026 | 28/8/2026 | Android and iOS apps ECOVACS PRO App improperly validate server certificates. Communication may be retrieved and/or altered. | |
| Aplazada | Baja (1.9) | 0.17% | — | Ichigo3766 Image-gen-mcpAI | 9/8/2026 | 12/8/2026 | A vulnerability was identified in Ichigo3766 image-gen-mcp 0.1.0. The impacted element is an unknown function of the file src/index.ts of the component upscale_images. Such manipulation of the argument output_path leads to path traversal. The attack must be carried out locally. The project was informed of the problem… | |
| Aplazada | Media (5.1) | 0.38% | — | NXP Auto GoldvipAI | 9/8/2026 | 12/8/2026 | A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0. Affected by this issue is the function SitewiseCustomFunction of the component Lambda Function Handler. Such manipulation leads to improper access controls. The attack can be launched remotely. Upgrading to version 1.15.0 can resolve this… | |
| Aplazada | Baja (1.9) | 0.16% | — | Adenot Mcp-google-searchAI | 9/8/2026 | 12/8/2026 | A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/index.ts of the component read_webpage. Executing a manipulation of the argument url can lead to server-side request forgery. The attack is restricted to local execution. This patch is called… | |
| Aplazada | Baja (1.9) | 1.1% | — | Adolfosalasgomez3011 Slidev-builder-mcpAI | 8/8/2026 | 12/8/2026 | A security flaw has been discovered in adolfosalasgomez3011 slidev-builder-mcp 2.1.0. This affects the function generateChart of the file src/tools/generateAssets.ts of the component generateAssets Tool. Performing a manipulation of the argument outputDir results in command injection. The attack is only possible with… | |
| Aplazada | Alta (7.5) | 0.49% | — | Klever-goAI | 7/8/2026 | 9/9/2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely triggerable denial of service. Both REST APIs are started with the Gin Engine.Run convenience method, which serves requests through Go's default HTTP server with no ReadHeaderTimeout,… | |
| Aplazada | Alta (7.5) | 0.49% | — | Klever-goAI | 7/8/2026 | 9/9/2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-message ingress handler spawns a new goroutine for every incoming direct message before the processor-level antiflood layer makes any admission decision, with no semaphore, throttler, or bound on the… | |
| Aplazada | Alta (7.5) | 0.49% | — | Klever-goAIGo-libp2p-pubsubAI | 7/8/2026 | 9/9/2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a nil-pointer panic triggered by a protobuf Transaction whose embedded RawData sub-message is omitted. This omission causes RawData to decode to nil. Every transaction gossiped on the Klever-Go P2P… |