Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
40.018 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.19% | — | Bestwebsoft Google MapsAI | 4/10/2026 | 6/10/2026 | The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. On-path attackers can present any certificate to intercept Google Maps web-service requests, steal the API… | |
| Aplazada | Crítica (9.1) | 0.18% | 💥 PoC | GistAI | 4/10/2026 | 6/10/2026 | The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login… | |
| Aplazada | Crítica (9.1) | 0.16% | — | GopayAI | 4/10/2026 | 6/10/2026 | gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present any certificate to read merchant credentials, signatures and transaction data, and modify payment, refund and order… | |
| Pendiente de análisis | Crítica (9.1) | 0.19% | — | Go-microAI | 4/10/2026 | 6/10/2026 | go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the shared TLS helper sets InsecureSkipVerify to true by default. Man-in-the-middle attackers can present any certificate to intercept or modify gRPC transport, HTTP and… | |
| Aplazada | Crítica (9.3) | 0.23% | — | Wwbn AvideoAI | 4/10/2026 | 6/10/2026 | WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates and channel playlists, letting attackers break out of onclick strings or iframe… | |
| Aplazada | Crítica (9.3) | 0.23% | — | Wwbn AvideoAI | 4/10/2026 | 6/10/2026 | WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entities and runs twice via setTitle() and save(), attackers can store markup… | |
| Aplazada | Crítica (9.3) | 0.34% | — | ZitadelAI | 4/10/2026 | 5/10/2026 | ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConfigID and… | |
| Aplazada | Crítica (9.2) | 0.33% | — | ZitadelAI | 4/10/2026 | 5/10/2026 | ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action… | |
| Aplazada | Crítica (9.3) | 0.22% | — | ZitadelAI | 4/10/2026 | 5/10/2026 | ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organization. Attackers with user-write permission in one organization can obtain… | |
| Aplazada | Crítica (9.3) | 0.31% | — | ZitadelAI | 4/10/2026 | 6/10/2026 | ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User Service V2 AddIDPLink endpoint. An unauthenticated attacker knowing a… | |
| Aplazada | Crítica (9.3) | 0.25% | 💥 PoC | Unlimited-elements Unlimited Elements FOR ElementorAI | 4/10/2026 | 6/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection.This issue affects Unlimited Elements For Elementor (Free Widgets,… | |
| Aplazada | Crítica (9.3) | 0.77% | — | Internlm MindsearchAI | 4/10/2026 | 6/10/2026 | A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inputs leads to code injection. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Aplazada | Crítica (9.3) | 1.8% | 💥 PoC | AhsaycbsAI | 4/10/2026 | 6/10/2026 | A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os command injection. It is possible to launch the attack remotely. The exploit… | |
| Pendiente de análisis | Crítica (9.8) | 0.78% | — | Nasa-ammos Ait-coreAI | 3/10/2026 | 6/10/2026 | CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows an unauthenticated remote attacker with network access to the ZeroMQ message bus to inject spacecraft command data, exfiltrate command and telemetry… | |
| Pendiente de análisis | Crítica (9.2) | 0.19% | — | Bouncycastle Bouncy CastleAI | 3/10/2026 | 6/10/2026 | In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a LeafNode's signature_key. LeafNode.verify() checked a leaf's signature against the signature_key carried in the leaf itself, while the credential's X.509 certificate chain was stored… | |
| Aplazada | Crítica (9.1) | 0.53% | 💥 PoC | Fastlinemedia Beaver BuilderAI | 3/10/2026 | 6/10/2026 | The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode.… | |
| Aplazada | Crítica (9.1) | 0.88% | — | Vikappointments Services Booking CalendarAI | 3/10/2026 | 6/10/2026 | The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which… | |
| Aplazada | Crítica (9.4) | 0.33% | 💥 PoC | C4illin ConvertxAI | 2/10/2026 | 6/10/2026 | In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This affects executable code in a .recipe or .downloaded_recipe file. | |
| Pendiente de análisis | Crítica (9.3) | 0.95% | — | Mikrotik RouterosAI | 2/10/2026 | 6/10/2026 | The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single… | |
| Pendiente de análisis | Crítica (9.3) | 0.34% | — | — | 2/10/2026 | 6/10/2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation… | |
| Aplazada | Crítica (9.3) | 0.55% | — | UtmstackAI | 2/10/2026 | 6/10/2026 | UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable value, which the InternalApiKeyFilter accepts for any endpoint without path… | |
| Pendiente de análisis | Crítica (9.4) | 0.53% | — | — | 2/10/2026 | 6/10/2026 | A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device. Disable the web server when not configuring the device. | |
| Pendiente de análisis | Crítica (9.3) | 1.4% | — | Amazon Sagemaker DistributionAI | 2/10/2026 | 6/10/2026 | OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, and 4.4.x before 4.4.3, as used by Amazon SageMaker Unified Studio, might allow an authenticated… | |
| Pendiente de análisis | Crítica (10) | 0.47% | 💥 PoC | Loom FOR AWSAI | 2/10/2026 | 6/10/2026 | Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority over the agent control plane, including registering tool servers, reading stored integration credentials, and rewriting the IAM role policies attached to… | |
| Aplazada | Crítica (9.3) | 0.59% | — | H3C CVMAI | 2/10/2026 | 6/10/2026 | H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability in the /cas/fileUpload/upload endpoint that allows remote attackers to write arbitrary files by manipulating the caller-supplied token parameter without restricting path… |