Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

40.005 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9.9)0.94%💥 PoCGitlab AI GatewayAI2/10/20262/10/2026
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template…
AplazadaCrítica (9.8)0.33%—Divi MembershipAI2/10/20263/10/2026
The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash…
AplazadaCrítica (9.2)0.38%—Apache ThriftAI2/10/20262/10/2026
Allocation of resources without limits or throttling, Integer overflow or wraparound, Heap-based buffer overflow vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
AplazadaCrítica (9.3)0.64%—Tenda HG7AITenda HG9AITenda Hg10AI2/10/20262/10/2026
A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_en_xpon. This impacts the function boaGetVar of the file /boaform/formLoopBack of the component Boa Web Server. Such manipulation of the argument Ethtype leads to stack-based buffer overflow. The attack can be executed remotely. The…
AplazadaCrítica (9.2)0.37%—YeswikiAI2/10/20262/10/2026
YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiService::isAuthorized() that allows unauthenticated attackers to call admin-only API routes when public API mode is enabled. Attackers can send requests to endpoints like api/ci/update_config and api/archives to overwrite configuration and list,…
AplazadaCrítica (9.2)0.46%—Apache ThriftAI2/10/20262/10/2026
Heap-based buffer overflow vulnerability in Apache Thrift C++ THeaderTransport. When an application enables the ZLIB transform for the frames it sends, THeaderTransport::transform() copies the compressed frame into the write buffer without making sure it fits. Data that does not compress, such as content a remote peer…
Pendiente de análisisCrítica (9.4)0.34%——2/10/20262/10/2026
A stack-based buffer overflow vulnerability exists in protocol gateways' account management interface. The vulnerability is caused by insufficient length validation of the `account_name` parameter when processing account management requests. An attacker authenticated as a read-only user to the web management interface…
AplazadaCrítica (9.8)0.49%💥 PoCAmauri Wpmobile.appAI2/10/20262/10/2026
The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to exfiltrate…
AplazadaCrítica (9.8)0.64%—Json API AuthAIPI Media Json APIAI2/10/20263/10/2026
The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in all versions up to, and including, 3.1.2. The vulnerability exists because the required PI-Media/json-api parent plugin caches controller dispatch results in transients keyed solely by URI and query…
AplazadaCrítica (9.9)0.46%——2/10/20262/10/2026
Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.
AplazadaCrítica (9)0.40%—Cpanel WHMAI2/10/20262/10/2026
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
AplazadaCrítica (9)0.40%—Cpanel WHMAI2/10/20262/10/2026
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.
En análisisCrítica (9.1)0.40%—Bouncycastle Bc-csharpAI2/10/20262/10/2026
Improper input validation in DHAgreement.CalculateAgreement (MTI/A0 two-pass Diffie-Hellman) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an on-path attacker to make the local party compute an agreed value the attacker already knows, defeating the key authentication MTI/A0 is meant to provide. It…
AplazadaCrítica (9.1)0.88%—Super-forms Super FormsAI2/10/20262/10/2026
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive…
AplazadaCrítica (9.8)0.40%💥 PoCDivi MembershipAI2/10/20263/10/2026
The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership…
AplazadaCrítica (9.8)0.48%💥 PoCDevkit PROAI2/10/20263/10/2026
The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled `original_user_id` cookie as the privileged identity:…
Pendiente de análisisCrítica (9.4)0.40%—Discord LibdaveAI2/10/20262/10/2026
Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected…
Pendiente de análisisCrítica (9)0.38%—389project 389 DS BaseAI1/10/20262/10/2026
A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's…
AplazadaCrítica (9.3)0.64%—Mooncake Transfer EngineAI1/10/20262/10/2026
Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with arbitrary addr and size values using READ or…
AplazadaCrítica (9.3)0.29%—Johnsoncontrols Easyio Fs32AI1/10/20262/10/2026
: Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data. This issue affects EasyIO FS32: before 3.0b63.
AplazadaCrítica (9.8)0.73%—Infiniflow RagflowAI1/10/20265/10/2026
RAGFlow 0.24.0 contains improper access control in get_dataset (api/apps/evaluation_app). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution
AplazadaCrítica (9.8)0.27%—Infiniflow RagflowAI1/10/20265/10/2026
infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via trace_mindmap. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object.
Pendiente de análisisCrítica (9.8)0.40%—LangflowAI1/10/20265/10/2026
langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The component is: src/backend/base/langflow/api/v1/validate.py:validate-post_validate_code-a-real-authenticated-http-post-to-api-v1. The attack vector is: Attack surface: HTTP or browser-backed service path. A…
AplazadaCrítica (9.8)0.51%—Langchain ChatchatAI1/10/20265/10/2026
The /knowledge_base/upload_temp_docs temporary document upload endpoint in Langchain Chatchat 0.3.1 is vulnerable to path traversal. By crafting malicious filenames, an attacker can write files to arbitrary locations on the server, bypassing the intended restrictions on the temporary directory.
AplazadaCrítica (9.1)0.35%—Chatchat-space Langchain-chatchatAI1/10/20265/10/2026
The knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is vulnerable to path traversal. An attacker can inject path traversal sequences (such as `..\`) into the `knowledge_base_name` parameter to write knowledge base content to arbitrary locations outside the configured knowledge…