Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2532▼ 363 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7) | 0.38% | — | Gibsonedu GibbonAI | 9/5/2026 | 24/7/2026 | Gibbon versions before v30.0.01 are affected by an authenticated SQL Injection vulnerability by abusing the Tracking/graphing https://github.com/GibbonEdu/core/blob/c431e25fdc874adece5d2dc7e408e9aa2d1abadb/modules/Tracking/graphing.php#L145 feature. Successful exploitation requires Teacher or higher privileges.… | |
| Aplazada | Crítica (9.8) | 0.61% | — | Moddable XSAIMongodb LibbsonAI | 16/5/2025 | 17/6/2026 | BSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilities. Those include CVE-2017-14227, CVE-2018-16790, CVE-2023-0437, CVE-2024-6381, CVE-2024-6383, and CVE-2025-0755. BSON-XS was the official Perl XS implementation of MongoDB's BSON serialization, but this… | |
| Aplazada | Media (6.5) | 0.36% | — | Dobsondev ShortcodesAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DobsonDev DobsonDev Shortcodes dobsondev-shortcodes allows Stored XSS.This issue affects DobsonDev Shortcodes: from n/a through <= 2.1.12. | |
| Modificada | Alta (7.5) | 0.77% | — | Mongodb LibbsonMongodb | 18/3/2025 | 17/6/2026 | The various bson_append functions in the MongoDB C driver library may be susceptible to buffer overflow when performing operations that could result in a final BSON document which exceeds the maximum allowable size (INT32_MAX), resulting in a segmentation fault and possible application crash. This issue affected… | |
| Aplazada | Media (4.3) | 0.33% | — | Martin Gibson WP Custom Admin InterfaceAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Martin Gibson WP Custom Admin Interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through 7.32. | |
| Aplazada | Media (5.3) | 0.63% | — | Mongodb C DriverAIMongodb LibbsonAI | 3/7/2024 | 17/6/2026 | The bson_string_append function in MongoDB C Driver may be vulnerable to a buffer overflow where the function might attempt to allocate too small of buffer and may lead to memory corruption of neighbouring heap memory. This issue affects libbson versions prior to 1.27.1 | |
| Modificada | Media (5.3) | 0.39% | — | Mongodb Libbson | 2/7/2024 | 17/6/2026 | The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at a negative offset. This may result in memory corruption. This issue affected libbson versions prior to 1.26.2 | |
| Aplazada | Media (5.4) | 0.31% | — | Martin Gibson WP Linkedin Auto PublishAI | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Martin Gibson WP LinkedIn Auto Publish.This issue affects WP LinkedIn Auto Publish: from n/a through 8.11. | |
| Modificada | Crítica (9.8) | 0.71% | — | Standford Gibsonenv | 27/1/2024 | 17/6/2026 | A vulnerability was found in StanfordVL GibsonEnv 0.3.1. It has been classified as critical. Affected is the function cloudpickle.load of the file gibson\utils\pposgd_fuse.py. The manipulation leads to deserialization. It is possible to launch the attack remotely. The complexity of an attack is rather high. The… | |
| Modificada | Media (5.4) | 0.77% | — | Mongodb Js-bson | 31/3/2020 | 17/6/2026 | Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour including data disclosure. This issue affects: MongoDB Inc. js-bson library version 1.1.3 and prior to. | |
| Modificada | Crítica (9.8) | 2.3% | — | Mongodb Bson | 30/3/2020 | 17/6/2026 | All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype, leading to cases where an object is serialized as a document rather than the intended BSON type. | |
| Modificada | Alta (7.5) | 6.4% | — | Mongodb BsonFedoraproject Fedora | 20/2/2020 | 17/6/2026 | The Moped::BSON::ObjecId.legal? method in mongodb/bson-ruby before 3.0.4 as used in rubygem-moped allows remote attackers to cause a denial of service (worker resource consumption) via a crafted string. NOTE: This issue is due to an incomplete fix to CVE-2015-4410. | |
| Modificada | Alta (7.5) | 1.1% | — | Bson-objectid Project Bson-objectid | 11/12/2019 | 17/6/2026 | An issue was discovered in the BSON ObjectID (aka bson-objectid) package 1.3.0 for Node.js. ObjectID() allows an attacker to generate a malformed objectid by inserting an additional property to the user-input, because bson-objectid will return early if it detects _bsontype==ObjectID in the user-input object. As a… | |
| Modificada | Alta (8) | 0.42% | — | Subsonic | 19/12/2018 | 17/6/2026 | Subsonic V6.1.5 allows internetRadioSettings.view streamUrl CSRF, with resultant SSRF. | |
| Modificada | Media (6.1) | 0.68% | — | Subsonic | 21/9/2018 | 17/6/2026 | An XSS issue was discovered in Subsonic Media Server 6.1.1. The podcast subscription form is affected by a stored XSS vulnerability in the add parameter to podcastReceiverAdmin.view; no administrator access is required. By injecting a JavaScript payload, this flaw could be used to manipulate a user's session, or… | |
| Modificada | Media (6.1) | 0.68% | — | Subsonic | 21/9/2018 | 17/6/2026 | An issue was discovered in Subsonic 6.1.1. The music tags feature is affected by three stored cross-site scripting vulnerabilities in the c0-param2, c0-param3, and c0-param4 parameters to dwr/call/plaincall/tagService.setTags.dwr that could be used to steal session information of a victim. | |
| Modificada | Media (6.1) | 0.68% | — | Subsonic | 21/9/2018 | 17/6/2026 | An issue was discovered in Subsonic 6.1.1. The general settings are affected by two stored cross-site scripting vulnerabilities in the title and subtitle parameters to generalSettings.view that could be used to steal session information of a victim. | |
| Modificada | Media (6.1) | 0.68% | — | Subsonic | 21/9/2018 | 17/6/2026 | An issue was discovered in Subsonic 6.1.1. The transcoding settings are affected by five stored cross-site scripting vulnerabilities in the name[x], sourceformats[x], targetFormat[x], step1[x], and step2[x] parameters (where x is an integer) to transcodingSettings.view that could be used to steal session information… | |
| Modificada | Media (6.1) | 0.68% | — | Subsonic | 21/9/2018 | 17/6/2026 | An issue was discovered in Subsonic 6.1.1. The radio settings are affected by three stored cross-site scripting vulnerabilities in the name[x], streamUrl[x], homepageUrl[x] parameters (where x is an integer) to internetRadioSettings.view that could be used to steal session information of a victim. | |
| Modificada | Media (5.9) | 0.91% | — | Subsonic Music Streamer | 11/9/2018 | 17/6/2026 | The Subsonic Music Streamer application 4.4 for Android has Improper Certificate Validation of the Subsonic server certificate, which might allow man-in-the-middle attackers to obtain interaction data. | |
| Modificada | Alta (8.1) | 2.1% | — | Mongodb Libbson | 10/9/2018 | 17/6/2026 | _bson_iter_next_internal in bson-iter.c in libbson 1.12.0, as used in MongoDB mongo-c-driver and other products, has a heap-based buffer over-read via a crafted bson buffer. | |
| Modificada | Media (5.9) | 0.54% | — | Dsub FOR Subsonic Project Dsub FOR Subsonic | 6/9/2018 | 17/6/2026 | daneren2005 DSub for Subsonic (Android client) version 5.4.1 contains a CWE-295: Improper Certificate Validation vulnerability in HTTPS Client that can result in Any non-CA signed server certificate, including self signed and expired, are accepted by the client. This attack appear to be exploitable via The victim… | |
| Modificada | Alta (7.5) | 1.9% | — | Mongodb Js-bson | 10/7/2018 | 17/6/2026 | The MongoDB bson JavaScript module (also known as js-bson) versions 0.5.0 to 1.0.x before 1.0.5 is vulnerable to a Regular Expression Denial of Service (ReDoS) in lib/bson/decimal128.js. The flaw is triggered when the Decimal128.fromString() function is called to parse a long untrusted string. | |
| Modificada | Alta (8.8) | 15% | — | Subsonic | 5/2/2018 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Subscribe to Podcast feature in Subsonic 6.1.1 allows remote attackers to hijack the authentication of unspecified victims for requests that conduct cross-site scripting (XSS) attacks or possibly have unspecified other impact via the name parameter to… | |
| Modificada | Crítica (9.8) | 4.7% | — | Bson Project Bson | 5/2/2018 | 17/6/2026 | BSON injection vulnerability in the legal? function in BSON (bson-ruby) gem before 3.0.4 for Ruby allows remote attackers to cause a denial of service (resource consumption) or inject arbitrary data via a crafted string. |