Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2585▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
401.024 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.32% | — | MispAI | 2/10/2026 | 2/10/2026 | MISP contains a cross-site scripting (XSS) vulnerability in the ID Translator feature. When a user views the ID Translator page, the application queries linked (remote) MISP servers for corresponding event identifiers. The event ID returned by the remote server was rendered in the HTML output without proper output… | |
| Aplazada | Media (5.3) | 0.36% | — | MispAI | 2/10/2026 | 2/10/2026 | MISP contains a stored cross-site scripting (XSS) vulnerability in the index table rendering of the remote event preview. The count field template escaped the associated link URL but rendered the field value without HTML encoding. An attacker with the ability to create or modify events on a linked (remote) MISP server… | |
| Pendiente de análisis | Alta (8.5) | 0.30% | — | Prosemirror-viewAI | 2/10/2026 | 2/10/2026 | ProseMirror's view component renders and manages the editable browser interface for ProseMirror documents. Prior to 1.42.3, prosemirror-view paste handling accepts attacker-provided HTML whose clipboard slice context contains attributes that are not passed through schema attribute validation. When a user pastes the… | |
| Aplazada | Crítica (9.8) | 0.34% | — | Lxsmnsyc SerovalAI | 2/10/2026 | 2/10/2026 | Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. From 0.12.0 until 1.6.2, fromJSON deserialization of a fulfilled Promise control node can pass a plugin-produced callable-bearing thenable to a native Promise resolver. ECMAScript thenable assimilation then… | |
| Aplazada | Alta (7.5) | 0.43% | — | Lxsmnsyc SerovalAI | 2/10/2026 | 2/10/2026 | Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.6.3, deserializeTypedArray in fromJSON and fromCrossJSON trusts a deserialized source value as an ArrayBuffer and does not bound the serialized element count. An attacker can provide a small… | |
| Pendiente de análisis | Media (5.9) | 0.39% | — | Postcss Selector ParserAI | 2/10/2026 | 2/10/2026 | PostCSS Selector Parser is a CSS selector parser that integrates with PostCSS but does not require it. Prior to 7.1.6, src/parser.js splitWord() can receive a flat selector as one word token carrying many class or ID indexes because period and hash characters are not tokenizer word delimiters. The uniqs()… | |
| Pendiente de análisis | Media (5.9) | 0.43% | — | Astral UVAI | 2/10/2026 | 2/10/2026 | uv is a Python package and project manager written in Rust. From 0.12.7 until 0.12.18, uv wheel extraction on Windows can process a malicious wheel in a way that writes a file outside the installation prefix, including an executable in a directory already present on the user's PATH. Non-Windows hosts are not affected.… | |
| Pendiente de análisis | Crítica (9.1) | 0.41% | — | Image-downloaderAI | 2/10/2026 | 3/10/2026 | Path traversal in image-downloader 4.3.0 allows an attacker who can control the download URL to cause downloaded response data to be written outside the configured destination directory. | |
| En análisis | Sin puntuar | 0.25% | — | Google ChromeAI | 2/10/2026 | 3/10/2026 | Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| En análisis | Sin puntuar | 0.21% | — | Google ChromeAI | 2/10/2026 | 3/10/2026 | Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| En análisis | Media (4.3) | 0.17% | — | Google ChromeAI | 2/10/2026 | 3/10/2026 | Integer overflow in Skia in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | |
| En análisis | Crítica (9.6) | 0.33% | — | Google ChromeAI | 2/10/2026 | 3/10/2026 | Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | |
| En análisis | Sin puntuar | 0.17% | — | Google ChromeAI | 2/10/2026 | 3/10/2026 | Information leak in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | |
| Pendiente de análisis | Crítica (9.6) | 0.21% | — | Google ChromeAI | 2/10/2026 | 3/10/2026 | Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| En análisis | Alta (8.8) | 0.29% | — | Google ChromeAI | 2/10/2026 | 3/10/2026 | Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Pendiente de análisis | Alta (8.3) | 0.21% | — | Google ChromeAI | 2/10/2026 | 3/10/2026 | Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| En análisis | Sin puntuar | 0.21% | — | Google ChromeAI | 2/10/2026 | 3/10/2026 | Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| En análisis | Alta (8.8) | 0.27% | — | Google ChromeAI | 2/10/2026 | 3/10/2026 | Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| En análisis | Media (4.3) | 0.18% | — | Google ChromeAI | 2/10/2026 | 3/10/2026 | Integer overflow in Compositing in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | |
| Aplazada | Media (6.3) | 0.27% | — | Meari IOT Cloud PlatformAI | 2/10/2026 | 3/10/2026 | The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized actions, such as altering device settings or triggering unintended behaviors,… | |
| Pendiente de análisis | Crítica (9.9) | 0.94% | — | Gitlab AI GatewayAI | 2/10/2026 | 2/10/2026 | GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template… | |
| Aplazada | Media (5.2) | 0.14% | — | Loglama TurkhotspotAI | 2/10/2026 | 2/10/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Loglama.net TurkHotspot allows Reflected XSS. This issue affects TurkHotspot: through 2026-10-02. NOTE: The vendor was contacted and it was learned that the product is not supported. | |
| Aplazada | Media (4.3) | 0.15% | — | Thimpress LearnpressAI | 2/10/2026 | 2/10/2026 | Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnPress: from n/a through 4.4.9.1. | |
| Aplazada | Baja (3.7) | 0.16% | — | Wpdevelop Booking CalendarAI | 2/10/2026 | 3/10/2026 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in WPdevelop Booking Calendar booking allows Leveraging Race Conditions.This issue affects Booking Calendar: from n/a through 11.8.4. | |
| Aplazada | Media (4.7) | 0.17% | — | Mehul Gohil Aculect AI CompanionAI | 2/10/2026 | 2/10/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Mehul Gohil Aculect AI Companion aculect-ai-companion allows Phishing.This issue affects Aculect AI Companion: from n/a through 0.8.1. |