Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2950▲ 8 respecto a la semana anterior
Críticas / altas1450▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
60 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.5) | 0.20% | — | Aquasec TrivyAI | 2/10/2026 | 5/10/2026 | Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to access pathnames above the scan root. The risk occurs when using misconf scanning on untrusted input (e.g., upon a third-party pull request that contains a Terraform configuration), if sensitive data can be found at those… | |
| Aplazada | Media (6.6) | 0.18% | — | Jetbrains AquaAI | 28/8/2026 | 9/9/2026 | aqua is a declarative command-line version manager written in Go. Prior to 2.60.1, pkg/unarchive/archives.go in the handler.HandleFile method calls os.Symlink with archives.FileInfo.LinkTarget without verifying that the target remains under the extraction destination. A later regular-file entry at the same archive… | |
| Aplazada | Media (6.8) | 0.19% | — | Aquasec TrivyAI | 18/8/2026 | 18/9/2026 | Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager.go to construct paths under ~/.trivy/plugins without confining plugin names to that root, allowing an attacker who persuades a user to install or run a malicious plugin to write the manifest and plugin binary to… | |
| Aplazada | Alta (7.5) | 0.51% | — | Jetbrains AquaAI | 13/7/2026 | 13/7/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes Aqua aqua allows PHP Local File Inclusion.This issue affects Aqua: from n/a through <= 5.1.2. | |
| Analizada | Alta (7) | 0.44% | — | Aquasec Trivy | 25/6/2026 | 27/6/2026 | Trivy is a security scanner. Prior to 0.71.1, when Trivy downloads an OCI artifact, it uses the org.opencontainers.image.title annotation from the artifact manifest as the destination filename without validation. An attacker who can make Trivy fetch an attacker-controlled artifact can supply a crafted annotation that… | |
| Analizada | Media (6.9) | 0.44% | — | Aquasec Trivy | 25/6/2026 | 26/6/2026 | Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker reads each entry with io.ReadAll(tr) and no size limit. An attacker who can place a malicious .tgz file in the scanned path can craft a small compressed archive that decompresses to gigabytes, causing… | |
| Analizada | Crítica (9.4) | 1.7% | ⚠ Explotación activa | Aquasec Setup-trivyAquasec TrivyAquasec Trivy ActionLitellm+1 | 23/3/2026 | 17/6/2026 | Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with malicious commits. This… | |
| Aplazada | Crítica (10) | 0.45% | — | Microsoft Visual Studio CodeAIAquasec TrivyAI | 5/3/2026 | 17/6/2026 | Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. In Trivy VSCode Extension version 1.8.12, which was distributed via OpenVSX marketplace was compromised and contained malicious code designed to leverage local AI coding agent to collect and exfiltrate sensitive information. Users… | |
| Aplazada | Alta (8.1) | 0.58% | — | Themerex AqualotsAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Aqualots aqualots allows PHP Local File Inclusion.This issue affects Aqualots: from n/a through <= 1.1.6. | |
| Analizada | Alta (8.1) | 2.1% | — | Aquasec Trivy Action | 19/2/2026 | 17/6/2026 | Trivy Action runs Trivy as GitHub action to scan a Docker container image for vulnerabilities. A command injection vulnerability exists in `aquasecurity/trivy-action` versions 0.31.0 through 0.33.1 due to improper handling of action inputs when exporting environment variables. The action writes `export VAR=<input>`… | |
| Analizada | Media (6.1) | 0.20% | — | Aquaplatform Revive Adserver | 20/1/2026 | 17/6/2026 | HackerOne community member Huynh Pham Thanh Luc (nigh7c0r3) has reported a reflected XSS vulnerability in the afr.php delivery script of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a parameter. If a logged in administrator visits the URL, the HTML is sent to the browser and… | |
| Analizada | Media (6.1) | 0.20% | — | Aquaplatform Revive Adserver | 20/1/2026 | 17/6/2026 | HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the banner-acl.php script of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a parameter. If a logged in administrator visits the URL, the HTML is sent to the browser and malicious scripts… | |
| Analizada | Media (6.1) | 0.20% | — | Aquaplatform Revive Adserver | 20/1/2026 | 17/6/2026 | HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the `banner-acl.php` and `channel-acl.php` scripts of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a parameter. If a logged in administrator visits the URL, the HTML is sent to the… | |
| Analizada | Media (6.5) | 0.27% | — | Aquaplatform Revive Adserver | 20/1/2026 | 17/6/2026 | HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass vulnerability in the `tracker-delete.php` script of Revive Adserver. Users with permissions to delete trackers are mistakenly allowed to delete trackers owned by other accounts. | |
| Analizada | Baja (2.7) | 0.25% | — | Aquaplatform Revive Adserver | 20/1/2026 | 17/6/2026 | HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver settings. When specific character combinations are used in a setting, the admin user console could be disabled due to a fatal PHP error. | |
| Analizada | Alta (7.7) | 0.28% | — | Acustica-audio Aquarius | 3/12/2025 | 17/6/2026 | Aquarius Desktop 3.0.069 for macOS contains an insecure file handling vulnerability in its support data archive generation feature. The application follows symbolic links placed inside the ~/Library/Logs/Aquarius directory and treats them as regular files. When building the support ZIP, Aquarius recursively enumerates… | |
| Analizada | Media (5.1) | 0.17% | — | Acustica-audio Aquarius Helpertool | 3/12/2025 | 17/6/2026 | The Aquarius HelperTool (1.0.003) privileged XPC service on macOS contains multiple flaws that allow local privilege escalation. The service accepts XPC connections from any local process without validating the client's identity, and its authorization logic incorrectly calls AuthorizationCopyRights with a NULL… | |
| Modificada | Media (6.2) | 0.20% | — | Acustica-audio Aquarius | 3/12/2025 | 5/7/2026 | Aquarius Desktop 3.0.069 for macOS stores user authentication credentials in the local file ~/Library/Application Support/Aquarius/aquarius.settings using a weak obfuscation scheme. The password is "encrypted" through predictable byte-substitution that can be trivially reversed, allowing immediate recovery of the… | |
| Analizada | Media (5.4) | 0.24% | — | Aquaplatform Revive Adserver | 2/12/2025 | 17/6/2026 | HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive Adserver was still vulnerable to impersonation attacks after the fix for CVE-2025-52672, via several alternate techniques. Homoglyphs based impersonation has been independently reported by other HackerOne users, such as… | |
| Analizada | Media (5.4) | 0.23% | — | Aquaplatform Revive Adserver | 20/11/2025 | 17/6/2026 | HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the username when adding new users. A username with leading or trailing whitespace could be virtually indistinguishable from its legitimate counterpart when the username is displayed in the UI, potentially… | |
| Analizada | Media (6.5) | 0.21% | — | Aquaplatform Revive Adserver | 20/11/2025 | 17/6/2026 | HackerOne community member Dang Hung Vi (vidang04) has reported a stored XSS vulnerability involving the navigation box at the top of advertiser-related pages, with campaign names being the vector for the stored XSS | |
| Analizada | Media (6.5) | 0.40% | — | Aquaplatform Revive Adserver | 20/11/2025 | 25/9/2026 | HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in the “userlog-index.php”. An attacker with access to the admin interface could request an arbitrarily large number of items per page, potentially leading to a denial of service. | |
| Modificada | Media (4.3) | 0.21% | — | Jenkins Aqua Security Scanner | 9/7/2025 | 17/6/2026 | Jenkins Aqua Security Scanner Plugin 3.2.8 and earlier stores Scanner Tokens for Aqua API unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system. | |
| Aplazada | Crítica (9.3) | 1.6% | — | Aquatronica Controller SystemAI | 20/6/2025 | 17/6/2026 | An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve sensitive configuration data, including… | |
| Aplazada | Media (6.4) | 0.32% | — | Aqua SVG SpriteAI | 13/11/2024 | 17/6/2026 | The Aqua SVG Sprite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.0.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary… |