Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3142▲ 568 respecto a la semana anterior
Críticas / altas1455▲ 53 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
14.306 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.31% | — | Aioseo ALL IN ONE SEOAI | 20/5/2026 | 24/7/2026 | El plugin All in One SEO para WordPress es vulnerable a la Exposición de Información Sensible a través de datos de script localizados de 'internalOptions' en versiones hasta la 4.9.7, inclusive, debido a que datos de opciones internas sensibles se pasan a wp_localize_script() en contextos del editor de publicaciones… | |
| Aplazada | Alta (7.4) | 0.41% | — | Mailcow-dockerizedAI | 20/5/2026 | 24/7/2026 | mailcow-dockerized contiene una vulnerabilidad de cross-site scripting almacenado en el Gestor de Colas del administrador. El Gestor de Colas obtiene entradas de la cola de correo de /api/v1/get/mailq/all, copia campos de la cola de Postfix controlados por el servidor en filas de DataTables y renderiza varios de esos… | |
| Aplazada | Media (4.4) | 0.33% | — | Anomify AIAI | 20/5/2026 | 24/7/2026 | El plugin Anomify AI - Anomaly Detection and Alerting para WordPress es vulnerable a Stored Cross-Site Scripting a través del parámetro 'anomify_api_key' en versiones hasta la 0.3.6 inclusive. Esto se debe a una sanitización de entrada insuficiente y a una falta de escape de salida: el plugin aplica… | |
| Aplazada | Alta (7.5) | 0.51% | — | Constantcontact Creative MailAI | 20/5/2026 | 21/8/2026 | El plugin Creative Mail - Easier WordPress & WooCommerce Email Marketing para WordPress es vulnerable a inyección SQL a través del parámetro checkout_uuid en todas las versiones hasta la 1.6.9, inclusive. Esto se debe a un escape insuficiente en el parámetro proporcionado por el usuario y a la falta de preparación… | |
| Analizada | Media (5.3) | 0.54% | — | Apache-airflow-providers-amazon | 19/5/2026 | 24/7/2026 | En los backends de secretos de AWS Secrets Manager y SSM Parameter Store de 'apache-airflow-providers-amazon' anteriores a la versión 9.28.0, la lógica de alcance de equipo podría resolver un 'conn_id' que contuviera un / (por ejemplo, my_team/conn ) a la misma ruta que un secreto con alcance de equipo de otro equipo… | |
| Analizada | Alta (8.7) | 0.21% | — | Apache-airflow-providers-cncf-kubernetes | 19/5/2026 | 24/7/2026 | Los tokens JWT que eran utilizados por los workers en los ejecutores de Kubernetes han sido expuestos a usuarios que tenían acceso de solo lectura a los Pods de Kubernetes. Esto podría permitir a usuarios con solo acceso de solo lectura realizar acciones que solo estaban disponibles para tareas en ejecución a través… | |
| Pendiente de análisis | Media (5.3) | 0.15% | — | Dell Portrait Color ManagementAI | 19/5/2026 | 24/7/2026 | Se descubrió un problema en la aplicación Portrait Dell Color Management anterior a la versión 3.7.0 para monitores Dell. En Windows, una vulnerabilidad de enlace simbólico permite a un usuario local con pocos privilegios escalar privilegios a Administrador. Durante la instalación, el software escribe el archivo… | |
| Aplazada | Media (4.3) | 0.27% | — | Brainstormforce Presto PlayerAI | 19/5/2026 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force Presto Player allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Presto Player: from n/a through 4.1.3. | |
| Analizada | Media (6.1) | 0.34% | — | Hsclabs Mailinspector | 18/5/2026 | 17/6/2026 | HSC MailInspector 5.3.3-7 is vulnerable to Cross Site Scripting (XSS) in the /police/WarningUrlPage.php endpoint due to improper neutralization of user-supplied input that uses alternate or obfuscated JavaScript syntax. | |
| Analizada | Media (6.1) | 0.41% | — | Hsclabs Mailinspector | 18/5/2026 | 17/6/2026 | HSC MailInspector v5.3.3-7 contains a Cross-Site Scripting (XSS) vulnerability in the /tap/tap.php endpoint due to improper neutralization of user-controlled input using alternate or obfuscated JavaScript syntax. The endpoint reflects unsanitized user input in HTTP responses without adequate output encoding, allowing… | |
| Analizada | Alta (7.5) | 3.0% | 💥 Exploit | Hsclabs Mailinspector | 18/5/2026 | 17/6/2026 | HSC MailInspector 5.3.3-7 has a Path Traversal vulnerability due to improper validation of user-supplied input in the /tap/dw.php endpoint. The text parameter is used to construct file paths without adequate normalization or restriction to a safe base directory. A remote attacker can exploit this flaw to access… | |
| Analizada | Alta (7.5) | 1.8% | 💥 Exploit | Hsclabs Mailinspector | 18/5/2026 | 17/6/2026 | HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability caused by improper control of user-supplied file paths. The endpoint /vendor/phpunit/phpunit.php processes user-controlled parameters that directly affect file access operations without adequate validation, sanitization, or path… | |
| Pendiente de análisis | Crítica (9.1) | 0.24% | — | Novus Airgate 4GAI | 18/5/2026 | 5/7/2026 | Incorrect access control in the /uci/get/ endpoint of NOVUS AirGate 4G firmware v1.1.16 allows unauthenticated attackers to obtain administrator credentials via a crafted POST request. | |
| Modificada | Alta (7.5) | 1.1% | — | GnutlsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux+10 | 18/5/2026 | 8/10/2026 | A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable… | |
| Analizada | Baja (2.1) | 0.73% | — | Vercel AI | 17/5/2026 | 17/6/2026 | A vulnerability was determined in vercel ai up to 3.0.97. The impacted element is the function createJsonResponseHandler/createJsonErrorResponseHandler of the file packages/provider-utils/src/response-handler.ts of the component provider-utils. This manipulation causes resource consumption. The attack may be initiated… | |
| Analizada | Media (5.5) | 0.69% | — | Vercel AI | 17/5/2026 | 17/6/2026 | A vulnerability was found in vercel ai up to 3.0.97. The affected element is the function validateDownloadUrl of the file packages/provider-utils/src/download-blob.ts of the component provider-utils. The manipulation results in server-side request forgery. The attack can be launched remotely. The exploit has been made… | |
| Analizada | Baja (1.3) | 7.0% | — | Vercel AI | 17/5/2026 | 17/6/2026 | A vulnerability has been found in vercel ai up to 3.0.97. Impacted is the function run of the file .github/workflows/prettier-on-automerge.yml of the component PR Branch Name Interpolation. The manipulation leads to os command injection. The attack can be initiated remotely. The complexity of an attack is rather high.… | |
| Aplazada | Alta (8.8) | 0.44% | — | AI EngineAI | 17/5/2026 | 17/6/2026 | The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. This is due to missing WordPress capability enforcement in the MCP OAuth bearer-token authorization path, where any valid OAuth token causes MCP access to be granted without… | |
| Aplazada | Alta (7.5) | 0.75% | — | Nodemailer Smtp ServerAI | 15/5/2026 | 17/6/2026 | An issue in Nodemailer smtp_server before v.3.18.3 allows a remote attacker to cause a denial of service via the SMTPStream._write, lib/smtp-stream.js components | |
| Pendiente de análisis | Alta (8.6) | 0.11% | — | AMD Raid DriverAI | 15/5/2026 | 17/6/2026 | Improper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary memory location potentially resulting in privilege escalation and arbitrary code execution. | |
| Analizada | Baja (2.5) | 0.13% | — | Saitoha Libsixel | 14/5/2026 | 17/6/2026 | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a wrong NULL check after an allocation call in sixel_decode_raw and sixel_decode causes a NULL pointer dereference whenever the allocation fails. The check tests the address of the output parameter (always non-NULL)… | |
| Analizada | Alta (7.1) | 0.17% | — | Saitoha Libsixel | 14/5/2026 | 17/6/2026 | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a signed integer overflow in the SIXEL parser's image-buffer doubling loop can lead to an out-of-bounds heap write in sixel_decode_raw_impl. context->pos_x grows by repeat_count on every sixel character with no upper bound… | |
| Modificada | Alta (7.8) | 0.14% | — | Saitoha Libsixel | 14/5/2026 | 17/6/2026 | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, signed integer overflow in sixel_encode_highcolor's allocation size calculation can lead to a heap buffer overflow. The public sixel_encode entry point validates only that width and height are greater than zero, with no… | |
| Aplazada | Media (6.5) | 0.18% | — | KubetailAI | 14/5/2026 | 17/6/2026 | Kubetail is a real-time logging dashboard for Kubernetes. Prior to 0.14.0, Kubetail's dashboard exposes WebSocket endpoints that did not adequately validate the Origin header on connection upgrade. A malicious web page visited by a user with an active Kubetail session could open a WebSocket to the user's dashboard and… | |
| Aplazada | Media (5.8) | 0.24% | — | Premailer CSS ParserAI | 14/5/2026 | 17/6/2026 | css_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Parser gem does not validate HTTPS connections, allowing a Man-in-the-Middle (MITM) attacker to inject or modify CSS content when stylesheets are loaded via HTTPS. The connection is established with OpenSSL::SSL::VERIFY_NONE, meaning any HTTPS… |