Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1319 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.22% | — | Vercel Next.jsAINextchatAI | 2/5/2026 | 17/6/2026 | A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This impacts an unknown function of the file Next.js of the component API Endpoint. Executing a manipulation can lead to permissive cross-domain policy with untrusted domains. The attack may be launched remotely. The exploit has been published and may be… | |
| Aplazada | Media (6.4) | 0.19% | — | Nextmove Lite Thank YOU Page WoocommerceAI | 2/5/2026 | 17/6/2026 | The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xlwcty_current_date' shortcode in all versions up to, and including, 2.23.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Baja (2.1) | 0.47% | — | Nextlevelbuilder Ui-ux-pro-max-skillAI | 1/5/2026 | 17/6/2026 | A vulnerability has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this issue is the function data.get of the file .claude/skills/design-system/scripts/generate-slide.py of the component Slide Generator. Such manipulation leads to cross site scripting. The attack may be performed from… | |
| Aplazada | Baja (2.1) | 0.41% | — | Nextlevelbuilder Ui-ux-pro-max-skillAI | 1/5/2026 | 17/6/2026 | A flaw has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this vulnerability is the function _format_plugins of the file .claude/skills/ui-styling/scripts/tailwind_config_gen.py of the component Tailwind Config Generator. This manipulation causes code injection. The attack is possible to… | |
| Aplazada | Media (5.5) | 0.51% | — | Nextlevelbuilder GoclawAINextlevelbuilder Goclaw LiteAI | 30/4/2026 | 17/6/2026 | A flaw has been found in nextlevelbuilder GoClaw and GoClaw Lite up to 3.8.5. This affects an unknown function of the component RPC Handler. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been published and may be used. Upgrading to version 3.9.0 mitigates this… | |
| Modificada | Alta (8.8) | 0.21% | — | RTI Connext Professional | 30/4/2026 | 7/10/2026 | Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Linking. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before… | |
| Analizada | Media (5.5) | 0.60% | — | Nextchat | 27/4/2026 | 24/7/2026 | A weakness has been identified in ChatGPTNextWeb NextChat up to 2.16.1. This affects the function storeUrl of the file app/api/artifacts/route.ts of the component Artifacts Endpoint. This manipulation of the argument ID causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has… | |
| Analizada | Media (5.5) | 0.60% | — | Nextchat | 27/4/2026 | 17/6/2026 | A security flaw has been discovered in ChatGPTNextWeb NextChat up to 2.16.1. Affected by this issue is the function proxyHandler of the file app/api/[provider]/[...path]/route.ts. The manipulation results in server-side request forgery. The attack may be performed from remote. The exploit has been released to the… | |
| Aplazada | Crítica (9.1) | 0.53% | — | Clerk NextjsAIClerk NuxtAIClerk AstroAIClerk SharedAI | 24/4/2026 | 17/6/2026 | Clerk JavaScript is the official JavaScript repository for Clerk authentication. createRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro can be bypassed by certain crafted requests, allowing them to skip middleware gating and reach downstream handlers. This vulnerability is fixed in @clerk/astro 1.5.7,… | |
| Analizada | Media (5.5) | 0.15% | — | Dayuanjiang Next AI Draw.io | 21/4/2026 | 17/6/2026 | Next AI Draw.io is a next.js web application that integrates AI capabilities with draw.io diagrams. Prior to 0.4.15, the embedded HTTP sidecar contains three POST handlers (/api/state, /api/restore, and /api/history-svg) that process incoming requests by accumulating the entire request body into a JavaScript string… | |
| Aplazada | Media (6.9) | 0.54% | — | Next-intlAI | 17/4/2026 | 17/6/2026 | next-intl provides internationalization for Next.js. Applications using the `next-intl` middleware prior to version 4.9.1with `localePrefix: 'as-needed'` could construct URLs where path handling and the WHATWG URL parser resolved a relative redirect target to another host (e.g. scheme-relative `//` or control… | |
| Analizada | Media (5.4) | 0.26% | — | Nextjs-auth0 | 17/4/2026 | 17/6/2026 | The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 through 4.17.1, simultaneous requests that trigger a nonce retry may cause the proxy cache fetcher to perform improper lookups for the token request results. Users are affected if their project uses both… | |
| Aplazada | Crítica (9.3) | 0.97% | — | Nextendweb Smart Slider 3AI | 9/4/2026 | 17/6/2026 | Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers to execute arbitrary code and commands. Attackers can trigger pre-authentication remote shell execution via HTTP headers,… | |
| Modificada | Crítica (9.1) | 0.42% | — | Frappe ErpnextFrappe | 8/4/2026 | 25/7/2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized before being rendered into PDF. When generating PDFs from user-controlled HTML content, the application allows the inclusion… | |
| Aplazada | Media (5.3) | 0.33% | — | Posimyth Nexter BlocksAI | 8/4/2026 | 24/7/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in POSIMYTH Nexter Blocks the-plus-addons-for-block-editor allows Retrieve Embedded Sensitive Data.This issue affects Nexter Blocks: from n/a through <= 4.7.0. | |
| Aplazada | Media (5.4) | 0.32% | — | Nextendweb Smart Slider 3AI | 7/4/2026 | 24/7/2026 | The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple wp_ajax_smart-slider3 controller actions in all versions up to, and including, 3.5.1.33. The display_admin_ajax() method does not call checkForCap() (which requires… | |
| Analizada | Alta (8.7) | 2.6% | 💥 Exploit | Nextcloud FlowWindmill | 7/4/2026 | 17/6/2026 | Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with the Operator role to perform prohibited entity creation and modification actions via the backend API. Although Operators are documented and priced as unable to create or modify entities, the API does not… | |
| Analizada | Alta (8.8) | 0.45% | — | Mobilenexthq Mobile MCP | 6/4/2026 | 24/7/2026 | Mobile Next is an MCP server for mobile development and automation. Prior to 0.0.50, the mobile_open_url tool in mobile-mcp passes user-supplied URLs directly to Android's intent system without any scheme validation, allowing execution of arbitrary Android intents, including USSD codes, phone calls, SMS messages, and… | |
| Modificada | Alta (8.8) | 0.39% | — | RTI Connext Professional | 1/4/2026 | 22/9/2026 | Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Recording Service,Routing Service,Queueing Service,Cloud Discovery Service,Observability Collector) allows Serialized Data External Linking, Data Serialization External Entities Blowup. This issue affects Connext… | |
| Modificada | Media (6.3) | 0.16% | — | RTI Connext Professional | 31/3/2026 | 22/9/2026 | Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.2.34, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, from 4.3x before 5.1.*. | |
| Analizada | Media (6.5) | 0.52% | — | Mobilenexthq Mobile MCP | 27/3/2026 | 17/6/2026 | Mobile Next is an MCP server for mobile development and automation. Prior to version 0.0.49, the `@mobilenext/mobile-mcp` server contains a Path Traversal vulnerability in the `mobile_save_screenshot` and `mobile_start_screen_recording` tools. The `saveTo` and `output` parameters were passed directly to filesystem… | |
| Aplazada | Media (6.5) | 0.41% | 💥 PoC | Nextendweb Smart Slider 3AI | 27/3/2026 | 17/6/2026 | The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can… | |
| Aplazada | Baja (2.3) | 0.32% | — | Mickasmt Next-saas-stripe-starterAI | 22/3/2026 | 17/6/2026 | A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPortal of the file actions/open-customer-portal.ts of the component Stripe API. This manipulation causes authorization bypass. Remote exploitation of the attack is possible. The complexity of an attack… | |
| Aplazada | Media (5.3) | 0.34% | — | Mickasmt Next-saas-stripe-starterAI | 22/3/2026 | 17/6/2026 | A vulnerability was detected in mickasmt next-saas-stripe-starter 1.0.0. Affected by this vulnerability is the function updateUserrole of the file actions/update-user-role.ts. The manipulation of the argument userId/role results in improper authorization. The attack may be launched remotely. | |
| Aplazada | Media (5.3) | 0.36% | — | Mickasmt Next-saas-stripe-starterAI | 22/3/2026 | 17/6/2026 | A security vulnerability has been detected in mickasmt next-saas-stripe-starter 1.0.0. Affected is the function generateUserStripe of the file actions/generate-user-stripe.ts of the component Checkout Handler. The manipulation of the argument priceId leads to business logic errors. The attack may be initiated remotely. |