Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3142▲ 563 respecto a la semana anterior
Críticas / altas1455▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
23.740 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 0.21% | — | Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+139 | 4/8/2026 | 6/8/2026 | Cryptographic Issue while processing registration requests with malformed or missing authentication parameters. | |
| Analizada | Media (6.5) | 0.17% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+143 | 4/8/2026 | 6/8/2026 | Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling. | |
| Analizada | Media (6.5) | 0.17% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+140 | 4/8/2026 | 6/8/2026 | Information Disclosure when processing wireless network channel switch information with improperly formatted length fields. | |
| Analizada | Media (6.7) | 0.11% | — | Qualcomm Aqt1000 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+48 | 4/8/2026 | 6/8/2026 | Memory Corruption when processing registry values with incorrect types using a direct query method. | |
| Modificada | Media (6.9) | 1.1% | — | Djangoproject Django | 4/8/2026 | 8/10/2026 | An issue was discovered in Django 6.0 before 6.0.9 and 5.2 before 5.2.18. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers… | |
| Analizada | Media (6.1) | 0.13% | — | Google A2ui/web Core | 4/8/2026 | 23/9/2026 | The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A malicious agent can supply a javascript: URI as the url argument of a Button component's functionCall action. When the user clicks the rendered button, arbitrary JavaScript executes in… | |
| Aplazada | Media (5.3) | 0.32% | — | Simple Google Calendar Outlook Events WidgetAI | 4/8/2026 | 26/8/2026 | The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL before performing a server-side request, allowing unauthenticated attackers to perform Server-Side Request Forgery attacks and, in some cases, read the response of the internal request. | |
| Pendiente de análisis | Alta (8.2) | 0.27% | — | OpensslAIGoogle BoringsslAICryptography.io CryptographyAIOpenbsd LibresslAI | 3/8/2026 | 10/9/2026 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the… | |
| Aplazada | Crítica (9.1) | 0.63% | — | Go-baseAI | 3/8/2026 | 10/9/2026 | go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 2026-05-18, the JWT signing secret is hardcoded to the known string "random", letting any attacker who reads the public repository forge tokens for arbitrary users, including admin roles, and completely… | |
| Aplazada | Baja (2.7) | 0.30% | — | TAG Category Taxonomy ManagerAI | 3/8/2026 | 26/8/2026 | The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing it and returning derived data, allowing users with contributor privileges to disclose data from private or draft posts they do not own. | |
| Aplazada | Media (6) | 0.17% | — | Google ApusysAI | 3/8/2026 | 28/8/2026 | In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00837766; Issue ID: MSV-6767. | |
| Aplazada | Alta (7.5) | 0.43% | — | Gallery FOR Google PhotosAI | 2/8/2026 | 26/8/2026 | The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the connected account, exposing the persistent access and refresh tokens to unauthenticated users and allowing long-term compromise of the linked account. | |
| Aplazada | Media (4.9) | 0.44% | — | Gsheetconnector CF7 Google Sheets ConnectorAI | 1/8/2026 | 12/8/2026 | The GSheetConnector – CF7 Google Sheets Connector with Real-Time Sync plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 5.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.… | |
| Pendiente de análisis | Baja (3.1) | 0.13% | — | Sigstore-goAI | 31/7/2026 | 10/9/2026 | sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an attacker holding expired key material to sign… | |
| Aplazada | Baja (3.7) | 0.29% | — | WP GO MapsAI | 31/7/2026 | 26/8/2026 | The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. | |
| Analizada | Alta (8) | 0.25% | — | Google MCP Toolbox FOR Databases | 31/7/2026 | 8/8/2026 | An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defined audience or clientId, the ValidateMCPAuth pipeline for opaque tokens skips… | |
| Analizada | Alta (8) | 0.13% | — | Google MCP Toolbox FOR Databases | 31/7/2026 | 8/8/2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. While the toolbox implements baseline input sanitization for user-controlled parameters, the underlying HTTP client (internal/sources/http/http.go) fails to… | |
| Analizada | Media (6.6) | 0.24% | — | Google MCP Toolbox FOR Databases | 31/7/2026 | 8/8/2026 | An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows an unauthenticated attacker to cause a denial of service (DoS). The /mcp endpoint handler reads incoming payloads directly into system memory using an unrestricted… | |
| Analizada | Media (5.7) | 0.20% | — | Google MCP Toolbox FOR Databases | 31/7/2026 | 8/8/2026 | An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to bypass allowedDatasets validation checks. The toolbox relies on the BigQuery dry-run API to enforce dataset… | |
| Analizada | Alta (8.1) | 0.25% | — | Google MCP Toolbox FOR Databases | 31/7/2026 | 8/8/2026 | Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocation requests through legacy HTTP endpoints when the --enable-api flag is active. | |
| Aplazada | Alta (7.1) | 0.29% | — | IEC GooseAI | 30/7/2026 | 3/9/2026 | The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during message processing, causing the process to… | |
| Aplazada | Alta (7.1) | 0.29% | — | GooseAI | 30/7/2026 | 3/9/2026 | The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 multicast frame on the process bus. When processing specific payload fields, an attacker controlled inner element length may exceed its enclosing length, causing the parser to over read by one byte.… | |
| Pendiente de análisis | Media (6.2) | 0.18% | — | Google RE2AINodejsAI | 30/7/2026 | 10/9/2026 | re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's String.prototype.match implementation with a global RE2 pattern that can match the empty string fails to advance its native matching cursor in lib/match.cc, causing an infinite loop and unbounded native memory growth that… | |
| Aplazada | Media (5.3) | 0.45% | — | GoaccessAI | 30/7/2026 | 8/9/2026 | GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to 1.11, the parse_ios() function uses an attacker-controlled keyword-to-OS offset as both the source offset and copy length for memmove, allowing a crafted User-Agent in a processed… | |
| Aplazada | Alta (8.7) | 0.47% | — | GoaccessAI | 30/7/2026 | 8/9/2026 | GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to version 1.11, the built-in WebSocket server narrows a 64-bit extended frame length into the signed 32-bit WSFrame.payloadlen field before enforcing the maximum frame size, allowing… |