Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2636▼ 272 respecto a la semana anterior
Críticas / altas1349▲ 92 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
67 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (5.4) | 0.17% | — | Brainstormforce Astra SitesAI | 5/10/2026 | 5/10/2026 | Missing Authorization vulnerability in Brainstorm Force Starter Templates astra-sites allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Starter Templates: from n/a through 4.7.7. | |
| Recibida | Media (6.5) | 0.16% | — | Brainstormforce Astra SitesAI | 5/10/2026 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Starter Templates astra-sites allows Stored XSS.This issue affects Starter Templates: from n/a through 4.7.7. | |
| Pendiente de análisis | Media (5.9) | 0.43% | — | Astral UVAI | 2/10/2026 | 2/10/2026 | uv is a Python package and project manager written in Rust. From 0.12.7 until 0.12.18, uv wheel extraction on Windows can process a malicious wheel in a way that writes a file outside the installation prefix, including an executable in a directory already present on the user's PATH. Non-Windows hosts are not affected.… | |
| Aplazada | Baja (2.7) | 0.23% | — | Brainstormforce AstraAI | 30/9/2026 | 30/9/2026 | Shop manager Content Injection in Astra WordPress Theme <= 4.13.12 versions. | |
| Aplazada | Alta (7.1) | 0.38% | — | MastraAI | 28/8/2026 | 23/9/2026 | Mastra through 1.63.0 contains an authentication bypass vulnerability in the memory API thread ownership validation when mapUserToResourceId callback is omitted from configuration. Authenticated attackers can enumerate all threads via GET /api/memory/threads and read conversation history and metadata of other resource… | |
| Pendiente de análisis | Alta (7.3) | 0.15% | — | Siemens Simcenter FemapAISiemens Simcenter NastranAI | 11/8/2026 | 28/8/2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2606), Simcenter Nastran (All versions < V2606). The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the… | |
| Aplazada | Baja (1.9) | 0.17% | — | Astralisone Rive-mcp-server-coreAI | 8/8/2026 | 12/8/2026 | A vulnerability has been found in astralisone rive-mcp-server-core up to db1d0cc4cd52589116360428b7504fd0ca748b3e. This affects an unknown part of the file packages/mcp-server/src/tools/importRiveFile.ts of the component importRiveFile Flow. Such manipulation of the argument libraryId leads to path traversal. The… | |
| Aplazada | Alta (8.5) | 0.16% | — | Siemens ComosAISiemens Designcenter NXAISiemens Simcenter 3DAISiemens Simcenter FemapAI+6 | 14/7/2026 | 5/10/2026 | A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1), Designcenter NX (All versions < V2512.7000), Simcenter 3D (All versions < V2512.7000), Simcenter Femap V2506 (All versions < V2506.0003), Simcenter Femap V2512 (All versions < V2512.0002), Simcenter… | |
| Aplazada | Media (5.3) | 0.29% | — | Adastracrypto Cryptocurrency Donation BOXAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in AdAstraCrypto Cryptocurrency Donation Box – Bitcoin & Crypto Donations cryptocurrency-donation-box allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cryptocurrency Donation Box – Bitcoin & Crypto Donations: from n/a through <= 2.2.13. | |
| Analizada | Baja (1.7) | 0.30% | — | Astral-tokio-tar | 20/3/2026 | 17/6/2026 | astral-tokio-tar is a tar archive reading/writing library for async Rust. In versions 0.5.6 and earlier, malformed PAX extensions were silently skipped when parsing tar archives. This silent skipping (rather than rejection) of invalid PAX extensions could be used as a building block for a parser differential, for… | |
| Aplazada | Media (6.5) | 0.22% | — | Brainstormforce Astra Bulk EditAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra Bulk Edit astra-bulk-edit allows DOM-Based XSS.This issue affects Astra Bulk Edit: from n/a through <= 1.2.10. | |
| Aplazada | Media (6.4) | 0.35% | — | Brainstormforce AstraAI | 11/3/2026 | 17/6/2026 | The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `ast-page-background-meta` and `ast-content-background-meta` post meta fields in all versions up to, and including, 4.12.3. This is due to insufficient input sanitization on meta registration and missing output escaping in the… | |
| Analizada | Media (6.3) | 0.15% | — | Astral UV | 27/2/2026 | 17/6/2026 | A flaw was found in uv. This vulnerability allows an attacker to execute malicious code during package resolution or installation via specially crafted ZIP (Zipped Information Package) archives that exploit parsing differentials, requiring user interaction to install an attacker-controlled package. | |
| Analizada | Alta (7.3) | 0.17% | — | Siemens Simcenter FemapSiemens Simcenter Nastran | 10/2/2026 | 17/6/2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an out of bounds read vulnerability while parsing specially crafted NDB files. This could allow an attacker to execute code in the context of the current process. | |
| Analizada | Alta (7.3) | 0.14% | — | Siemens Simcenter FemapSiemens Simcenter Nastran | 10/2/2026 | 17/6/2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted NDB files. This could allow an attacker to execute code in the context of the current process. | |
| Analizada | Alta (7.3) | 0.14% | — | Siemens Simcenter FemapSiemens Simcenter Nastran | 10/2/2026 | 17/6/2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an out of bounds read vulnerability while parsing specially crafted NDB files. This could allow an attacker to execute code in the context of the current process. | |
| Analizada | Alta (7.3) | 0.14% | — | Siemens Simcenter FemapSiemens Simcenter Nastran | 10/2/2026 | 17/6/2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an out of bounds read vulnerability while parsing specially crafted XDB files. This could allow an attacker to execute code in the context of the current process. | |
| Analizada | Alta (7.3) | 0.14% | — | Siemens Simcenter FemapSiemens Simcenter Nastran | 10/2/2026 | 17/6/2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an out of bounds read vulnerability while parsing specially crafted XDB files. This could allow an attacker to execute code in the context of the current process. | |
| Analizada | Alta (7.3) | 0.17% | — | Siemens Simcenter FemapSiemens Simcenter Nastran | 10/2/2026 | 17/6/2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an out of bounds write vulnerability while parsing specially crafted XDB files. This could allow an attacker to execute code in the context of the current process. | |
| Aplazada | Media (5.9) | 0.31% | — | Brainstormforce Astra WidgetsAI | 24/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra Widgets astra-widgets allows Stored XSS.This issue affects Astra Widgets: from n/a through <= 1.2.16. | |
| Aplazada | Media (5.4) | 0.17% | — | Wpastra Element Pack AddonsAI | 18/11/2025 | 17/6/2026 | The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Open Street Map widget's marker content parameter in all versions up to, and including, 8.3.4. This is due to insufficient input sanitization and output escaping on user-supplied attributes in the render… | |
| Aplazada | Alta (8.1) | 0.48% | — | Astra Security SuiteAI | 11/11/2025 | 17/6/2026 | The Astra Security Suite – Firewall & Malware Scan plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient validation of remote URLs for zip downloads and an easily guessable key in all versions up to, and including, 0.2. This makes it possible for unauthenticated attackers to upload arbitrary… | |
| Aplazada | Alta (8.1) | 0.70% | — | Astral Tokio-tarAI | 21/10/2025 | 17/6/2026 | astral-tokio-tar is a tar archive reading/writing library for async Rust. Versions of astral-tokio-tar prior to 0.5.6 contain a boundary parsing vulnerability that allows attackers to smuggle additional archive entries by exploiting inconsistent PAX/ustar header handling. When processing archives with PAX-extended… | |
| Aplazada | Media (6.5) | 0.58% | — | MastraAI | 3/10/2025 | 17/6/2026 | Mastra is a Typescript framework for building AI agents and assistants. Versions 0.13.8 through 0.13.20-alpha.0 are vulnerable to a Directory Traversal attack that results in the disclosure of directory listings. The code contains a security check to prevent path traversal for reading file contents, but this check is… | |
| Aplazada | Media (6.1) | 0.22% | — | Astral Tokio TARAI | 23/9/2025 | 17/6/2026 | astral-tokio-tar is a tar archive reading/writing library for async Rust. In versions 0.5.3 and earlier of astral-tokio-tar, tar archives may extract outside of their intended destination directory when using the Entry::unpack_in_raw API. Additionally, the Entry::allow_external_symlinks control (which defaults to… |