Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 440 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
216 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.3) | 0.47% | — | VaadinAIVaadin CoreAIVaadin Charts FlowAIVaadin ChartsAI+1 | 30/9/2026 | 30/9/2026 | A prototype pollution vulnerability exists in the deep merge helpers of Vaadin Charts and Vaadin Component Base. Merging an object the application does not control into a chart configuration or into a component's i18n property writes onto Object.prototype, making the injected properties visible to every object in the… | |
| Aplazada | Crítica (9.8) | 0.56% | — | MailuAIMailu Helm-chartsAI | 21/9/2026 | 24/9/2026 | Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-charts 2.7.3, deployments with PROXY_AUTH_WHITELIST configured but REAL_IP_HEADER unset trusted a client-controlled X-Forwarded-By header for header-based proxy authentication. The proxy_hide_header… | |
| Aplazada | Crítica (9.3) | 0.59% | — | Wartsila Fos-onboardAI | 15/9/2026 | 24/9/2026 | A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framework component of Wärtsilä FOS-Onboard. | |
| Aplazada | Crítica (9.5) | 0.51% | — | Wartsila Fos-onboardAI | 15/9/2026 | 24/9/2026 | A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard. | |
| Aplazada | Alta (7.5) | 0.69% | — | Formidable ChartsAIFormidable FormsAI | 26/8/2026 | 27/8/2026 | The Formidable Charts plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.0.1 via the 'frm_graph' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Successful… | |
| Aplazada | Alta (7.1) | 0.25% | — | SmartsmtpAI | 20/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions. | |
| Aplazada | Media (5.3) | 0.44% | — | Cti-transmuteAIApache EchartsAI | 11/8/2026 | 26/8/2026 | Affected versions of cti-transmute fail to HTML-escape attacker-controlled values used in ECharts Sunburst and Treemap tooltip formatters. Slice names may originate directly from STIX or MISP data, including STIX types, relationship_type, pattern prefixes, and MISP category/type values. Since ECharts interprets the… | |
| Aplazada | Alta (7.1) | 0.27% | — | LG Electronics SmartshareAIMicrosoft Windows 10AI | 30/7/2026 | 30/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics SmartShare allows SQL Injection. This issue affects SmartShare: through 2.3.1712.1202, which is supported on Microsoft Windows 10 and earlier versions. | |
| Aplazada | Media (4.8) | 0.18% | — | Procertum SmartsignAI | 27/7/2026 | 30/7/2026 | proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially allowing the reading of local files, depending on the parser's configuration. The XML External Entity (XXE) vulnerability is triggered simply by previewing a file in the file selection window, before… | |
| Aplazada | Media (4.6) | 0.11% | — | Procertum SmartsignAI | 27/7/2026 | 30/7/2026 | proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare arbitrary certificate with CPS URI pointing to a local executable file or any URL, sign a document with it, and send it to the victim. When the victim opens the document in the application, the… | |
| Aplazada | Baja (2.1) | 0.23% | — | Geex-arts Django-jetAI | 19/7/2026 | 21/7/2026 | A weakness has been identified in geex-arts django-jet up to 1.0.8. Affected is an unknown function of the component OAuth Handler. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.… | |
| Aplazada | Media (5.5) | 0.55% | — | Geex-arts Django-jetAI | 19/7/2026 | 20/7/2026 | A security flaw has been discovered in geex-arts django-jet up to 1.0.8. This impacts an unknown function of the component OAuth Credential Revoke Handler. Performing a manipulation results in missing authorization. The attack is possible to be carried out remotely. The exploit has been released to the public and may… | |
| Aplazada | Baja (2.1) | 0.38% | — | Geex-arts Django-jetAI | 19/7/2026 | 22/7/2026 | A vulnerability was identified in geex-arts django-jet up to 1.0.8. This affects an unknown function of the file jet/dashboard/views.py of the component Dashboard Module. Such manipulation leads to authorization bypass. The attack can be executed remotely. The exploit is publicly available and might be used. The… | |
| Analizada | Alta (8.1) | 0.41% | — | Openfga Helm ChartsOpenfga | 9/7/2026 | 14/7/2026 | OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skipped JWT audience validation when authn.method was set to oidc, authn.oidc.issuer was configured, and authn.oidc.audience was not set, allowing a token minted for an unrelated service by the same… | |
| Analizada | Baja (2.1) | 0.34% | — | Openfga Helm ChartsOpenfga | 9/7/2026 | 14/7/2026 | OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, when MySQL is being used as the datastore and authorization decisions rely on case-sensitive user strings, the tuple, changelog, and authorization_model identifier columns can compare case-distinct values such as user:Alice and… | |
| Aplazada | Alta (8.1) | 0.36% | — | AutopartsAI | 17/6/2026 | 17/6/2026 | Unauthenticated Local File Inclusion in AutoParts <= 1.5.8 versions. | |
| Analizada | Media (5.3) | 0.13% | — | Openfga Helm ChartsOpenfga | 10/6/2026 | 17/6/2026 | OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to OpenFGA reusing an earlier cached result for a subsequent request. This issue has been patched in version 1.16.0. | |
| Aplazada | Crítica (10) | 0.44% | — | Cloudpirates Open Source Helm ChartsAIGithub ActionsAI | 1/6/2026 | 22/7/2026 | CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (generate-schema.yaml) exposes sensitive credentials (Personal Access Token and SSH signing key) to fork-controlled code due to unsafe checkout and credential handling practices. This issue has been… | |
| Aplazada | Crítica (10) | 0.44% | — | Cloudpirates Open Source Helm ChartsAIGithub ActionsAI | 1/6/2026 | 22/7/2026 | CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (pull-request.yaml) executes attacker-controlled code from fork pull requests in a privileged context, exposing repository secrets including Docker Hub credentials and tokens without requiring… | |
| Analizada | Media (6.1) | 0.93% | — | Apache Echarts | 25/5/2026 | 23/7/2026 | A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rendering logic. This issue affects Apache ECharts: from before 6.1.0. In versions prior to 6.1.0, if both Lines series and tooltip are used, and no user-specified tooltip.formatter is provided, and series.data[i].name is… | |
| Aplazada | Media (5.3) | 0.13% | — | SmartshopAI | 23/5/2026 | 23/7/2026 | Smartshop 1 contains a cross-site request forgery vulnerability that allows attackers to modify user profiles by tricking authenticated users into submitting malicious requests. Attackers can craft HTML forms targeting editprofile.php with hidden fields for email and password parameters that execute automatically when… | |
| Aplazada | Alta (8.8) | 0.33% | — | SmartshopAI | 23/5/2026 | 23/7/2026 | Smartshop 1 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'searched' parameter in search.php. Attackers can send GET requests with malicious SQL payloads like SLEEP commands to extract sensitive database… | |
| Aplazada | Alta (8.8) | 0.33% | — | SmartshopAI | 23/5/2026 | 23/7/2026 | Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to product.php with union-based SQL injection payloads in the id parameter to extract sensitive database… | |
| Aplazada | Alta (8.8) | 0.33% | — | SmartshopAI | 23/5/2026 | 23/7/2026 | Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to category.php with UNION-based SQL injection payloads in the id parameter to extract sensitive database… | |
| Aplazada | Media (6.4) | 0.33% | — | Charts NinjaAI | 5/5/2026 | 17/6/2026 | The Charts Ninja: Create Beautiful Graphs & Charts and Easily Add Them to Your Website plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'chartid' shortcode attribute in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible… |