Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
23.377 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.7) | 0.32% | — | Captcha Protected Page Project Captcha Protected Page | 2/9/2026 | 9/9/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2. | |
| Analizada | Media (4.8) | 0.24% | — | Address Suggestion Project Address Suggestion | 2/9/2026 | 9/9/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Address Suggestion allows Cross-Site Scripting (XSS). This issue affects Address Suggestion versions: from 0.0.0 to 1.0.25. | |
| Analizada | Media (5.3) | 0.31% | — | Blazy Project Blazy | 2/9/2026 | 16/9/2026 | Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from 0.0.0 to 3.0.18. | |
| Analizada | Media (5.3) | 0.33% | — | Dxpr Builder Project Dxpr Builder | 2/9/2026 | 9/9/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experience for Drupal versions: from 0.0.0 to 2.8.1. | |
| Analizada | Media (5.3) | 0.31% | — | Diff Project Diff | 2/9/2026 | 16/9/2026 | Incorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing. This issue affects Diff versions: from 0.0.0 to 2.0.1, from 2.1.0 to 2.1.1. | |
| Analizada | Media (5.3) | 0.32% | — | Quick Tabs Project Quick Tabs | 2/9/2026 | 16/9/2026 | Incorrect Authorization vulnerability in Drupal Quick Tabs allows Forceful Browsing. This issue affects Quick Tabs versions: from 0.0.0 to 4.3.1. | |
| Analizada | Media (5.4) | 0.30% | — | External Authentication Project External Authentication | 2/9/2026 | 15/9/2026 | Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This issue affects External Authentication versions: from 0.0.0 to 2.0.13. | |
| Analizada | Media (5.3) | 0.34% | — | Entity Share Websub Project Entity Share Websub | 2/9/2026 | 9/9/2026 | Server-Side Request Forgery (SSRF) vulnerability in Drupal Entity Share Websub allows Server Side Request Forgery. This issue affects Entity Share Websub versions: from 0.0.0 to 1.1.2. | |
| Analizada | Media (4.8) | 0.14% | — | Entity Browser Project Entity Browser | 2/9/2026 | 8/9/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Entity Browser allows Stored XSS. This issue affects Entity Browser versions: from 0.0.0 to 2.16.0. | |
| Analizada | Media (5.4) | 0.23% | — | Entity PDF Project Entity PDF | 2/9/2026 | 7/10/2026 | Missing Authorization vulnerability in Drupal Entity PDF allows Forceful Browsing. This issue affects Entity PDF versions: from 0.0.0 to 2.1.5. | |
| Analizada | Baja (3.3) | 0.21% | — | Content Moderation Notifications Project Content Moderation Notifications | 2/9/2026 | 24/9/2026 | Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notifications versions: from 0.0.0 to 3.9.0. | |
| Analizada | Media (6.1) | 0.25% | — | Slick Carousel Project Slick Carousel | 2/9/2026 | 1/10/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Slick Carousel allows Stored XSS. This issue affects Slick Carousel versions: from 0.0.0 to 2.1.0. | |
| Analizada | Media (5.3) | 0.31% | — | Entity API Project Entity API | 2/9/2026 | 1/10/2026 | Incorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing. This issue affects Entity API versions: from 0.0.0 to 1.8.0. | |
| Analizada | Media (4.8) | 0.14% | — | Pypdf Project Pypdf | 1/9/2026 | 5/10/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_page.py PageObject._extract_text and PageObject.extract_xform_text to traverse a directed acyclic graph of reused form XObjects in which each form invokes a child multiple times, creating… | |
| Analizada | Media (4.8) | 0.14% | — | Pypdf Project Pypdf | 1/9/2026 | 5/10/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long runtimes and large amounts of memory when retrieving document outlines with large numbers of entries or deeply nested reused paths because the traversal… | |
| Analizada | Media (6.9) | 0.19% | — | Pypdf Project Pypdf | 1/9/2026 | 5/10/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.16.0, an attacker can craft a PDF whose cyclic tree structure causes pypdf/generic/_data_structures.py TreeObject.insert_child to follow /Next links indefinitely when a writing code path inserts a child, producing an infinite loop. This issue is fixed… | |
| Aplazada | Alta (8.7) | 0.61% | — | XmldomAIXmldom Project XmldomAI | 1/9/2026 | 8/9/2026 | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, the DOCUMENT_TYPE_NODE branch in lib/dom.js validates publicId, systemId, and internalSubset under requireWellFormed:… | |
| Aplazada | Media (6.3) | 0.55% | — | Ash-project ASH TypescriptAI | 1/9/2026 | 1/9/2026 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to read internal application data from an HTTP 500 response body. When a typed-controller route handler returns anything other than a %Plug.Conn{}, dispatch/3 in… | |
| Aplazada | Media (6.3) | 0.68% | — | Ash-project ASH TypescriptAI | 1/9/2026 | 1/9/2026 | Improper Input Validation vulnerability in ash-project ash_typescript allows a remote attacker to submit argument values outside a declared allowlist or bound on typed-controller routes. AshTypescript.TypedController.RequestHandler in lib/ash_typescript/typed_controller/request_handler.ex calls Ash.Type.cast_input/3… | |
| Aplazada | Baja (2.3) | 0.50% | — | Ash-project ASH TypescriptAI | 1/9/2026 | 1/9/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ash-project ash_typescript allows an attacker who controls a path-parameter value to redirect a generated client's request, and the credentials attached to it, to an unintended route or an external origin. The URL builders in… | |
| Aplazada | Alta (8.2) | 0.50% | — | Ash-project ASH TypescriptAI | 1/9/2026 | 1/9/2026 | Incorrect Authorization vulnerability in ash-project ash_typescript allows an unauthorized RPC caller to read attribute values that Ash field policies denied. When a field policy denies an attribute, Ash substitutes %Ash.ForbiddenField{}, which retains the real value in original_value because embedded resources must… | |
| Aplazada | Media (6.3) | 0.55% | — | Ash-project ASH TypescriptAI | 1/9/2026 | 1/9/2026 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to receive unredacted internal error data by provoking an error shape the configured error handler does not match. apply_error_handler/3 in lib/ash_typescript/rpc/errors.ex is the… | |
| Aplazada | Alta (8.2) | 0.55% | — | Ash-project ASH TypescriptAI | 1/9/2026 | 1/9/2026 | Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort the node via client-supplied typed struct field names. resolve_typed_struct_field/2 in lib/ash_typescript/rpc/field_processing/field_selector.ex… | |
| Aplazada | Alta (8.7) | 0.55% | — | Ash-project ASH TypescriptAI | 1/9/2026 | 1/9/2026 | Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort the node via client-supplied RPC field names. AshTypescript.FieldFormatter.convert_to_field_atom/2 in lib/ash_typescript/field_formatter.ex… | |
| Analizada | Media (6.9) | 0.52% | — | Pypdf Project Pypdf | 31/8/2026 | 5/10/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pypdf/_utils.py function read_until_whitespace reads a stream containing a long run of bytes without whitespace. The function repeatedly performs immutable bytes concatenation in a… |