Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

334 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)1.3%—Atomic-agents-stackAI15/9/202624/9/2026
atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths. Attackers can bypass path containment checks by including '../' segments in requests to the…
AplazadaCrítica (9.2)0.32%—Atomic-agents-stackAI15/9/202624/9/2026
atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses. Attackers can inject arbitrary command and argument values that are spawned as local subprocesses by MCPClientPool to achieve code…
AplazadaAlta (7.1)0.48%—Atomic-agents-stackAI15/9/202624/9/2026
atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that returns zero cost for unknown models not in the pricing table. Attackers can configure deployments with unknown model identifiers to bypass daily cost caps and exceed budget limits in parallel batch operations.
AplazadaAlta (8.1)0.38%—Uptimekuma Uptime KumaAIMatomoAI5/8/202626/8/2026
Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo value as a bare, unquoted JavaScript expression inside a <script> block rendered on every public status page. A siteId value such as , once saved by an editor/admin, executes arbitrary JavaScript for…
AplazadaAlta (8.1)0.47%—AtomlabAI17/6/202617/6/2026
Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions.
Pendiente de análisisAlta (8.6)0.15%—Atomic Alarm ClockAI13/5/202617/6/2026
Atomic Alarm Clock 6.3 contains a stack overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string to the display name textbox in the Time Zones Clock configuration. Attackers can craft a buffer with structured exception handling overwrite and encoded shellcode to…
AplazadaAlta (8.7)0.31%—Atom 3X ProjectorAI10/4/202617/6/2026
This vulnerability exists in the Atom 3x Projector due to improper exposure of the Android Debug Bridge (ADB) service over the local network without authentication or access controls. An unauthenticated attacker on the same network can exploit this vulnerability to obtain root-level access, leading to complete…
AplazadaMedia (4.3)0.29%—Atomchat Group Chat AND Video ChatAI21/3/202617/6/2026
The Group Chat & Video Chat by AtomChat plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'atomchat_update_auth_ajax' and 'atomchat_update_layout_ajax' functions in all versions up to, and including, 1.1.7. This makes it possible for authenticated…
AnalizadaMedia (5.5)0.15%—Openatom Openharmony16/3/202617/6/2026
in OpenHarmony v6.0 and prior versions allow a local attacker case DOS through missing release of memory.
AnalizadaMedia (5.5)0.15%—Openatom Openharmony16/3/202617/6/2026
in OpenHarmony v5.1.0 and prior versions allow a local attacker cause DOS through improper input.
AnalizadaAlta (7.8)0.16%—Openatom Openharmony16/3/202617/6/2026
in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.
AnalizadaAlta (7.8)0.17%—Openatom Openharmony16/3/202617/6/2026
in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.
AnalizadaBaja (3.3)0.14%—Openatom Openharmony16/3/202617/6/2026
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information improper input. This vulnerability can be exploited only in restricted scenarios.
AnalizadaAlta (7)0.15%—Openatom Openharmony16/3/202617/6/2026
in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through using incompatible type. This vulnerability can be exploited only in restricted scenarios.
AnalizadaMedia (6.5)0.17%—Openatom Openharmony16/3/202617/6/2026
in OpenHarmony v5.0.3 and prior versions allow a local attacker case sensitive information leak through use of uninitialized resource.
AplazadaAlta (8.5)0.19%—Atomic Alarm ClockAI30/1/202617/6/2026
Atomic Alarm Clock 6.3 contains a local privilege escalation vulnerability in its service configuration that allows attackers to execute arbitrary code with SYSTEM privileges. Attackers can exploit the unquoted service path by placing a malicious executable named 'Program.exe' to gain persistent system-level access.
AnalizadaAlta (7.4)0.36%—Atomberg Erica Smart FAN Firmware22/1/202617/6/2026
An issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive information and escalate privileges via a crafted deauth frame
ModificadaCrítica (9.3)0.47%—Thedigitalcraft Atomcms22/12/202517/6/2026
Atom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries through unvalidated parameters. Attackers can inject malicious SQL code in the 'id' parameter of the admin index page to execute time-based blind SQL injection attacks.
AplazadaMedia (5.5)0.22%—Interactive Human Anatomy With Clickable Body PartsAI3/10/202517/6/2026
The Interactive Human Anatomy with Clickable Body Parts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
AplazadaMedia (5.9)0.19%—Rbaer Simple Matomo Tracking CodeAI3/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rbaer Simple Matomo Tracking Code simple-matomo-tracking-code allows Stored XSS.This issue affects Simple Matomo Tracking Code: from n/a through <= 1.1.0.
AnalizadaAlta (7)0.10%—Openatom Openharmony11/8/202517/6/2026
in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition.
AnalizadaMedia (5.5)0.12%—Openatom Openharmony11/8/202517/6/2026
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.
AnalizadaMedia (5.5)0.12%—Openatom Openharmony11/8/202517/6/2026
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through type confusion.
AnalizadaAlta (7.8)0.15%—Openatom Openharmony11/8/202517/6/2026
in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free.
AnalizadaMedia (5.5)0.12%—Openatom Openharmony11/8/202517/6/2026
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.