Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3062▲ 584 respecto a la semana anterior
Críticas / altas1459▲ 293 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
736 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.13% | — | Root Browser ClassicAI | 24/9/2026 | 25/9/2026 | Root Browser Classic 3.3.0 passes the path of a selected SQLite database to an operating-system shell without safely separating the filename from the command. | |
| Pendiente de análisis | Alta (7.4) | 0.20% | — | Thebrowser ARC SearchAI | 23/9/2026 | 24/9/2026 | Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker can exploit this via a specially crafted website to render fake UI elements, such as a spoofed address bar, misleading the user about… | |
| Aplazada | Media (6.9) | 0.14% | — | Tencent BrowserskillAI | 20/9/2026 | 22/9/2026 | Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-extension origin with 32 characters in range a-p. Attackers can register a malicious extension as a browser client to intercept and manipulate page content, DOM,… | |
| Aplazada | Crítica (9.4) | 1.2% | — | Webrecorder BrowsertrixAI | 17/9/2026 | 24/9/2026 | Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance. From 1.15.0 until 1.22.8, Browsertrix improperly sanitizes Git URLs specified as Custom Behaviors, allowing command injection through… | |
| Aplazada | Alta (7.1) | 0.45% | — | BrowserlessAI | 16/9/2026 | 22/9/2026 | browserless versions 1.44.0 through 2.56.7 fail to enforce file protocol restrictions in Playwright websocket endpoints, allowing authenticated token holders to read arbitrary files. Attackers can navigate Playwright-driven browsers to file scheme URLs and access files accessible to the container process despite the… | |
| Pendiente de análisis | Alta (7.6) | 0.50% | — | Filebrowser File BrowserAI | 14/9/2026 | 24/9/2026 | File Browser through 2.63.23 applies path rules to the requested lexical path but resolves symbolic links without reapplying rules to the target, allowing authenticated users to bypass deny rules. Attackers can read and overwrite rule-denied files by accessing them through in-scope symbolic link aliases that resolve… | |
| Pendiente de análisis | Alta (7.2) | 0.44% | — | Filebrowser File BrowserAI | 14/9/2026 | 24/9/2026 | File Browser versions >= 2.5.0 and <= 2.63.23 contain an incorrect authorization flaw in the direct-upload endpoint (resourcePostHandler in http/resource.go). Unlike the TUS upload handler, the direct-upload handler does not reject a target that is an existing directory; a POST with ?override=true aimed at a directory… | |
| Pendiente de análisis | Alta (7.1) | 0.44% | — | Filebrowser File BrowserAI | 14/9/2026 | 24/9/2026 | File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle files into memory without size limits. Authenticated attackers with download permission can request conversion of large .srt, .ass, or .ssa files and exhaust server memory through… | |
| Pendiente de análisis | Alta (7.1) | 0.44% | — | FilebrowserAI | 14/9/2026 | 24/9/2026 | filebrowser through 2.63.23 fails to limit WebSocket message size in the /api/command handler before checking permissions, allowing authenticated users to buffer arbitrarily large messages. Attackers can send oversized WebSocket messages to exhaust server heap memory and cause denial of service regardless of… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Ucweb UC BrowserAI | 8/9/2026 | 9/9/2026 | UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. An attacker hosts a specially crafted URL on a UC-owned domain (via a reflected XSS) that leverages the… | |
| Aplazada | Media (6.5) | 0.46% | — | NubrowserAI | 8/9/2026 | 9/9/2026 | NuBrowser lacks protocol whitelist validation for the S.browser_fallback_url field of intent://, allowing attackers to inject javascript: URLs via 302 redirects. This results in a universal cross‑site scripting (UXSS) vulnerability that enables script execution within the origin of arbitrary websites. | |
| Aplazada | Baja (2.1) | 0.51% | — | Ntegrals OpenbrowserAI | 2/9/2026 | 3/9/2026 | A vulnerability was found in ntegrals openbrowser up to 067fc45d649baa961750da8e2f4a75d87c5c75c8. Affected by this vulnerability is an unknown functionality of the file packages/core/src/agent/agent.ts of the component Browser Agent Message Construction. Performing a manipulation results in resource consumption. It is… | |
| Analizada | Media (4.8) | 0.14% | — | Entity Browser Project Entity Browser | 2/9/2026 | 8/9/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Entity Browser allows Stored XSS. This issue affects Entity Browser versions: from 0.0.0 to 2.16.0. | |
| Aplazada | Media (6.8) | 0.07% | — | Browser-use Web-uiAI | 30/8/2026 | 10/9/2026 | browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or access restrictions. Attackers with read access to the temporary settings directory can recover provider API keys from predictably-named JSON files. | |
| Aplazada | Media (6.9) | 0.41% | — | Browser-use Web-uiAI | 30/8/2026 | 2/9/2026 | browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing attackers to create directories at arbitrary locations by supplying absolute paths to save_recording_path, save_trace_path, save_agent_history_path, or save_download_path parameters. Attackers can… | |
| Pendiente de análisis | Baja (2.3) | 0.21% | — | FilebrowserAI | 28/8/2026 | 30/9/2026 | filebrowser from version 2.24.0 contains a race condition in the TUS upload handler that allows authenticated users to write past the declared Upload-Length by sending concurrent PATCH requests. Attackers can send multiple simultaneous PATCH requests at the same offset to bypass length validation, resulting in files… | |
| Pendiente de análisis | Baja (2.3) | 0.21% | — | FilebrowserAI | 28/8/2026 | 24/9/2026 | filebrowser through 2.63.23 does not remove share records when a shared file is renamed (only deletion triggers share cleanup). The share record is keyed by path, so it survives the rename and remains dormant (returning 404 while the path is empty). When any new, unrelated file later appears at the original shared… | |
| Pendiente de análisis | Baja (2.3) | 0.35% | — | Filebrowser File BrowserAI | 28/8/2026 | 30/9/2026 | File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes another user's shared file. Attackers can access the surviving share link to retrieve new unrelated content uploaded to the same path without authentication. | |
| Pendiente de análisis | Alta (8.2) | 0.52% | — | FilebrowserAI | 28/8/2026 | 24/9/2026 | filebrowser through 2.63.23 fails to validate named pipes in directory archive and public download handlers, allowing attackers to trigger blocking open syscalls. Authenticated users or anonymous visitors with public share links can repeatedly request archives containing named pipes to pin server goroutines and… | |
| Aplazada | Baja (2.7) | 0.43% | — | Filebrowser File BrowserAI | 18/8/2026 | 18/9/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, the Link storage struct is serialized directly by sharePostHandler, shareListHandler, and shareGetsHandler through renderJSON, causing POST /api/share/{path} and… | |
| Aplazada | Alta (7.1) | 0.53% | — | FilebrowserAI | 14/8/2026 | 8/9/2026 | FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS resumable-upload PATCH endpoint, allowing authenticated users to write arbitrary data to disk. Attackers can send oversized request bodies that exceed the declared upload length to exhaust available disk space and cause service… | |
| Aplazada | Alta (8.7) | 0.56% | — | FilebrowserAI | 14/8/2026 | 8/9/2026 | File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify, delete, and share files belonging to other users by exploiting the server root scope assignment. | |
| Aplazada | Crítica (9.2) | 0.55% | — | FilebrowserAI | 14/8/2026 | 8/9/2026 | FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership during self-registration. When Signup and CreateUserDir are enabled and FileBrowser's root is on a case-insensitive filesystem (confirmed on Windows/NTFS), two self-registered usernames that differ only… | |
| Aplazada | Alta (7.6) | 0.50% | — | FilebrowserAI | 14/8/2026 | 8/9/2026 | filebrowser versions before v2.63.21 fail to canonicalize paths before evaluating access rules, allowing authenticated users to bypass administrator-defined deny rules using case-variant or backslash-separated paths. Attackers can request files with alternate path representations that match no rule but resolve to the… | |
| Aplazada | Media (5.3) | 0.39% | — | FilebrowserAI | 14/8/2026 | 8/9/2026 | filebrowser before 2.63.19 contains a permission bypass in the /api/resources endpoint. The checksum (?checksum=) branch of resourceGetHandler reads the entire file to compute a digest and returns it without performing a Perm.Download check (unlike the sibling raw, preview, and subtitle paths). As a result, an… |