Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
6557 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.69% | — | Ash-project ASH Authentication Oauth2 ServerAI | 7/9/2026 | 8/9/2026 | Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server exposes the state-changing OAuth endpoints under an unintended URL prefix, bypassing controls scoped to the canonical prefix. oauth2_server_protocol_routes/1 in AshAuthentication.Phoenix.Oauth2Server.Router forwards the… | |
| Aplazada | Alta (8.2) | 0.66% | — | Ash-project ASH Authentication Oauth2 ServerAI | 7/9/2026 | 8/9/2026 | Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to exhaust database storage and memory. The /authorize endpoint is unauthenticated by design. With Client ID Metadata Documents enabled, resolve_client/3 in… | |
| Aplazada | Alta (8.6) | 1.1% | — | Laradashboard Lara DashboardAI | 7/9/2026 | 10/9/2026 | Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code execution. | |
| Aplazada | Alta (8.6) | 0.71% | — | Laradashboard Lara DashboardAI | 7/9/2026 | 8/9/2026 | Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators to upload and extract arbitrary zip archives over the live application source code. Attackers can upload a malicious archive containing modified… | |
| Aplazada | Media (5.3) | 0.53% | — | Lara DashboardAI | 7/9/2026 | 9/9/2026 | Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content permissions to upload files. Attackers can upload polyglot files with attacker-chosen extensions to the public web root and execute code if the deployment permits… | |
| Pendiente de análisis | Media (6.5) | 0.35% | — | Redhat Openshift AIAIRedhat Odh-dashboardAI | 7/9/2026 | 8/9/2026 | A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard service account and returns the full Secret object, including .data, without an authorization check. Any authenticated dashboard user can retrieve the… | |
| Aplazada | Alta (8.6) | 2.7% | — | Tenda Hg10AIBOAAI | 6/9/2026 | 8/9/2026 | A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loid leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and… | |
| Aplazada | Alta (7.4) | 0.85% | — | Tenda Hg10AIBOA WEB ServerAI | 6/9/2026 | 11/9/2026 | A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation of the argument if can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly… | |
| Aplazada | Alta (8.8) | 0.25% | — | Nokri JOB BoardAI | 5/9/2026 | 8/9/2026 | The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nokri_account_member_permissions' function in all versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Aplazada | Crítica (9.3) | 1.1% | — | Laradashboard Lara DashboardAI | 5/9/2026 | 18/9/2026 | Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request the GET /screenshot-login/{email} endpoint with a registered email address to… | |
| Aplazada | Crítica (9.3) | 0.98% | — | AutoagentAI | 5/9/2026 | 24/9/2026 | AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can connect to the exposed communication port and execute arbitrary bash commands within the container, gaining access to bind-mounted host… | |
| Aplazada | Media (5.3) | 0.37% | — | RowboatAI | 5/9/2026 | 23/9/2026 | Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure arbitrary destinations. Attackers can point these URLs at internal services and cloud metadata endpoints to perform server-side request forgery and enumerate internal network topology. | |
| Aplazada | Media (6.5) | 0.68% | — | Joomunited WP File DownloadAI | 5/9/2026 | 8/9/2026 | The WP File Download plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.8 via the 'remoteurl' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain… | |
| Aplazada | Crítica (9.8) | 0.50% | — | Oasys SysoaAI | 4/9/2026 | 9/9/2026 | SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path | |
| Aplazada | Alta (8.7) | 0.50% | — | Douyin Tiktok Download APIAI | 4/9/2026 | 10/9/2026 | Douyin_TikTok_Download_API through 4.1.2 contains a server-side request forgery vulnerability in the /api/download and /api/hybrid/video_data endpoints that allows unauthenticated attackers to fetch arbitrary URLs by supplying a url query parameter. Attackers can request internal services including cloud metadata… | |
| Aplazada | Alta (7.1) | 0.25% | — | Ninjaforms File Uploads ExtensionAI | 3/9/2026 | 5/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | |
| Aplazada | Alta (7.4) | 0.85% | — | Tenda Hg10AIBOA WEB ServerAI | 3/9/2026 | 3/9/2026 | A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formWlanSetup of the file /boaform/formWlanSetup of the component Boa Web Server. The manipulation of the argument ssid leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might… | |
| Aplazada | Alta (8.9) | 1.1% | — | Tenda Hg10AIBOA WEB ServerAI | 3/9/2026 | 3/9/2026 | A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing a manipulation of the argument Username can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed… | |
| Aplazada | Media (5.5) | 0.70% | — | Rowboatlabs RowboatAI | 2/9/2026 | 28/9/2026 | A vulnerability was detected in rowboatlabs rowboat up to 0.9.1. The impacted element is the function request.text/req.json of the file apps/rowboat/app/api/composio/webhook/route.ts of the component Composio Webhook Endpoint. The manipulation results in denial of service. It is possible to launch the attack remotely.… | |
| Aplazada | Media (6.6) | 0.51% | — | Yoast SEO PremiumAI | 2/9/2026 | 3/9/2026 | The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize control characters from redirect origins before writing them to the site's Apache configuration file when the file-based redirect mode is enabled, and the redirect-creation endpoint is reachable by users with only Author-level access. This allows… | |
| Aplazada | Alta (8.8) | 0.20% | — | Mangboard Mang Board WPAI | 2/9/2026 | 2/9/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions. | |
| Aplazada | Alta (8.1) | 0.38% | — | Miniorange Oauth Single Sign ONAI | 2/9/2026 | 3/9/2026 | The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its Steam single sign-on flow, allowing unauthenticated attackers to log in as an arbitrary non-administrator user, and to create new accounts. | |
| Aplazada | Alta (8.1) | 0.52% | — | Joomunited WP File DownloadAI | 2/9/2026 | 4/9/2026 | The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete function in all versions. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead… | |
| Pendiente de análisis | Media (6.4) | 0.28% | — | KeycloakAI | 2/9/2026 | 3/9/2026 | A flaw was found in the first-broker-login flow of the Keycloak identity management service. When a user links a social identity provider account to their local account, the verification proof generated is not strictly bound to the specific upstream identity being verified. This allows an attacker with a different… | |
| Aplazada | Baja (2.1) | 0.43% | — | GouguoaAI | 2/9/2026 | 2/9/2026 | A security vulnerability has been detected in gouguoa up to 5.10.0/6.0.1. This vulnerability affects the function update of the file app/home/controller/Index.php of the component edit_personal Endpoint. Such manipulation of the argument position_id leads to dynamically-determined object attributes. The attack can be… |