Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.21% | — | Actual Sync ServerAI | 25/9/2026 | 28/9/2026 | Actual is a local-first personal finance tool. Prior to 26.7.0, Actual Sync Server's CORS proxy is intended to let authenticated users fetch resources only from repositories listed in the official plugin allowlist. When `ACTUAL_GITHUB_TOKEN` is configured, the proxy automatically attaches the server's GitHub token to… | |
| Pendiente de análisis | Alta (7.9) | 0.20% | — | Holloway Chew Kean HO ActualizerAI | 4/9/2026 | 8/9/2026 | (Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerability in the Alpha user and root user password loops of Shell/debian-minbase-install.sh. The installer invokes mkpasswd to generate yescrypt password hashes but does not check the command's return value and… | |
| Aplazada | Media (4.2) | 0.29% | — | Csv-stringifyAIActualbudget ActualAI | 7/7/2026 | 9/7/2026 | Actual is a local-first personal finance tool. Prior to 26.6.0, exportToCSV and exportQueryToCSV in packages/loot-core/src/server/transactions/export/export-to-csv.ts pass user-controlled Payee, Notes, Account, and Category strings to csv-stringify with no cast callback and no formula-prefix neutralization. Strings… | |
| Aplazada | Alta (8.3) | 0.44% | — | Actualbudget ActualAI | 7/7/2026 | 9/7/2026 | Actual is a local-first personal finance app. Prior to 26.6.0, in OpenID multi-user mode, disabling a user only blocks future OpenID login for that identity, while existing Actual session tokens for the disabled user remain valid. The shared session validation path accepts any existing token row that has not expired… | |
| Aplazada | Alta (7.2) | 0.43% | — | Actualbudget ActualAI | 7/7/2026 | 8/7/2026 | Actual is an open-source personal finance application. Prior to 26.7.0, a missing authorization issue allows a shared user with user_access on a budget file to perform owner-only file management actions. A non-owner shared user can call file-management endpoints intended for higher-privilege users, including… | |
| Aplazada | Media (4.3) | 0.34% | — | Actual APP Sync ServerAI | 7/7/2026 | 8/7/2026 | Actual is a local-first personal finance tool. Prior to 26.6.0, the GET /secret/:name endpoint in @actual-app/sync-server checks only that the caller has a valid session and does not verify the caller is an admin, while the sibling POST /secret/ handler enforces an admin check in OpenID mode. Any authenticated… | |
| Aplazada | Media (4.6) | 0.19% | — | Actual-app CLIAIMicrosoft ExcelAILibreoffice CalcAIGoogle SheetsAI | 7/7/2026 | 8/7/2026 | Actual is a local-first personal finance app. Prior to 26.6.0, @actual-app/cli ships a hand-rolled CSV serializer in packages/cli/src/output.ts used whenever the global --format csv option is passed, whose escapeCsv helper only handles RFC 4180 delimiter, quote, and newline escaping and does not neutralize standard… | |
| Aplazada | Media (5.3) | 0.45% | — | Actualbudget ActualAI | 12/6/2026 | 17/6/2026 | Actual is an open-source personal finance application. Prior to version 26.5.0, several endpoints are affected by a path traversal vulnerability. Version 26.5.0 fixes the issue. | |
| Aplazada | Media (4.8) | 0.18% | — | ElectronAIActualbudget ActualAI | 12/6/2026 | 17/6/2026 | Actual is an open-source personal finance application. In the macOS desktop application version 25.x (built on Electron 39.2.7), the ELECTRON_RUN_AS_NODE fuse is not disabled, allowing an attacker who can place a file on disk or control command-line arguments to invoke the signed Actual.app binary with the… | |
| Aplazada | Media (6.9) | 0.56% | — | Actual Sync-serverAI | 12/6/2026 | 17/6/2026 | Actual is a local-first personal finance tool. The `POST /openid/config` endpoint in Actual Budget's sync-server versions <= 26.4.0 exposes the full OpenID Connect configuration—including the OAuth2 `client_secret`—to any caller who knows the bootstrap password. The endpoint also lacks authentication and rate… | |
| Analizada | Alta (8.8) | 0.59% | — | Actualbudget Actual | 24/4/2026 | 17/6/2026 | Actual is a local-first personal finance tool. Prior to version 26.4.0, any authenticated user (including `BASIC` role) can escalate to `ADMIN` on servers migrated from password authentication to OpenID Connect. Three weaknesses combine: `POST /account/change-password` has no authorization check, allowing any session… | |
| Analizada | Media (5.3) | 0.45% | — | Actualbudget Actual | 9/3/2026 | 17/6/2026 | Actual Sync Server allows authenticated users to upload files through POST /sync/upload-user-file. In versions prior to 26.3.0, improper validation of the user-controlled x-actual-file-id header means that traversal segments (../) can escape the intended directory and write files outside userFiles.This issue affects… | |
| Analizada | Media (5.7) | 0.36% | — | Actualbudget Actual | 26/2/2026 | 17/6/2026 | Actual is a local-first personal finance tool. Prior to version 26.2.1, in multi-user mode (OpenID), the sync API endpoints (`/sync/*`) don't verify that the authenticated user owns or has access to the file being operated on. Any authenticated user can read, modify, and overwrite any other user's budget files by… | |
| Analizada | Crítica (9.2) | 0.56% | — | Actualbudget Actual | 24/2/2026 | 17/6/2026 | Actual is a local-first personal finance tool. Prior to version 26.2.1, missing authentication middleware in the ActualBudget server component allows any unauthenticated user to query the SimpleFIN and Pluggy.ai integration endpoints and read sensitive bank account balance and transaction information. This… | |
| Aplazada | Alta (7.5) | 0.29% | — | ActualizerAIOpensslAIDebianAI | 13/5/2025 | 17/6/2026 | Actualizer is a single shell script solution to allow developers and embedded engineers to create Debian operating systems (OS). Prior to version 1.2.0, Actualizer uses OpenSSL's "-passwd" function, which uses SHA512 instead of a more suitable password hasher like Yescript/Argon2i. All Actualizer users building a full… | |
| Modificada | Alta (7.5) | 0.97% | — | Pyxicom Actualite | 20/10/2008 | 16/6/2026 | SQL injection vulnerability in the actualite module 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Actualscripts Actualanalyzer GoldActualscripts Actualanalyzer LiteActualscripts Actualanalyzer PROActualscripts Actualanalyzer Server | 3/6/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in view.php in ActualScripts ActualAnalyzer Server 8.37 and earlier, ActualAnalyzer Gold 7.74 and earlier, ActualAnalyzer Pro 6.95 and earlier, and ActualAnalyzer Lite 2.78 and earlier allows remote attackers to inject arbitrary web script or HTML via the language parameter. | |
| Modificada | Alta (7.5) | 6.3% | — | Actualscripts Actualanalyzer Lite | 5/5/2008 | 16/6/2026 | Directory traversal vulnerability in admin.php in ActualScripts ActualAnalyzer Lite 2.78 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the style parameter. | |
| Modificada | Alta (9.3) | 8.2% | — | Interactual Technologies Interactual PlayerRoxio Cineplayer | 17/7/2007 | 16/6/2026 | Multiple stack-based buffer overflows in (a) InterActual Player 2.60.12.0717 and (b) Roxio CinePlayer 3.2 allow remote attackers to execute arbitrary code via a (1) long FailURL attribute in the IAMCE ActiveX Control (IAMCE.dll) or a (2) long URLCode attribute in the IAKey ActiveX Control (IAKey.dll). NOTE: the… | |
| Modificada | Alta (9.3) | 35% | — | Interactual Technologies Interactual PlayerIntervideo WindvdRoxio Cineplayer | 21/3/2007 | 16/6/2026 | Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio CinePlayer 3.2, (3) WinDVD 7.0.27.172, and possibly other products, allows remote attackers to execute arbitrary code via a long ApplicationType property. | |
| Modificada | Media (6.4) | 2.8% | — | Interactual Technologies Interactual Player | 28/7/2006 | 16/6/2026 | Stack-based buffer overflow in ITIRecorder.MicRecorder ActiveX control in iarecord.dll in InterActual Player before 2.6 allows remote attackers to execute arbitrary code via a long argument to the Files method. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Alta (7.5) | 13% | — | Actualscripts Actualanalyzer | 21/4/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in direct.php in ActualScripts ActualAnalyzer Lite 2.72 and earlier, Gold 7.63 and earlier, and Server 8.23 and earlier allows remote attackers to execute arbitrary code via a URL in the rf parameter. |