Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▲ 24 respecto a la semana anterior
Críticas / altas1467▲ 357 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.56% | — | BugsinkAI | 15/9/2026 | 30/9/2026 | Bugsink is a self-hosted error tracking tool. Prior to version 2.2.2, Bugsink stores every set of custom tags supplied with an incoming event, allowing a caller with a valid project DSN to submit an unusually large tag set and force excessive tag-row writes. Because Bugsink uses a single-writer database architecture,… | |
| Aplazada | Media (4.3) | 0.28% | — | BugsinkAI | 26/5/2026 | 24/7/2026 | Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink resolved sourcemaps and debug files by debug ID without scoping that lookup to the project that owned the uploaded metadata. An authenticated user with access to one project could cause event processing in that project to use sourcemap/debug-file… | |
| Aplazada | Baja (3.1) | 0.23% | — | BugsinkAI | 26/5/2026 | 24/7/2026 | Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, In affected versions, the issue list view authorizes access through the project in the URL, but applies the requested bulk action to the submitted issue IDs without also requiring those issues to belong to that project. This vulnerability is fixed in 2.2.0. | |
| Aplazada | Baja (3.1) | 0.24% | — | BugsinkAI | 26/5/2026 | 24/7/2026 | Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink issue event pages accept a direct event identifier from the URL and, in affected versions, look up that event without also requiring it to belong to the issue in the URL. This is a project-boundary authorization issue: a logged-in user with access… | |
| Aplazada | Media (4.3) | 0.39% | — | BugsinkAI | 26/5/2026 | 24/7/2026 | Bugsink is a self-hosted error tracking tool. Prior to 2.1.3, Bugsink’s webhook URL validation could be (partially) bypassed because of a mismatch in URL parsing. The original validation logic parsed webhook URLs with Python’s urllib.parse.urlparse, then sent the request with requests.post. For malformed inputs… | |
| Analizada | Alta (7.1) | 0.51% | — | Bugsink | 10/4/2026 | 17/6/2026 | Bugsink is a self-hosted error tracking tool. In 2.1.0, an authenticated file write vulnerability was identified in Bugsink 2.1.0 in the artifact bundle assembly flow. A user with a valid authentication token could cause the application to write attacker-controlled content to a filesystem location writable by the… | |
| Analizada | Media (6.1) | 0.43% | — | Bugsink | 25/2/2026 | 17/6/2026 | Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.13, an unauthenticated attacker who can submit events to a Bugsink project can store arbitrary JavaScript in an event. The payload executes only if a user explicitly views the affected Stacktrace in the web UI. When Pygments returns more lines than… | |
| Aplazada | Alta (7.5) | 0.32% | — | BugsinkAI | 10/11/2025 | 17/6/2026 | Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.6, a specially crafted Brotli-compressed envelope can cause Bugsink to spend excessive CPU time in decompression, leading to denial of service. This can be done if the DSN is known, which it is in many common setups (JavaScript, Mobile Apps). The… | |
| Aplazada | Alta (7.5) | 0.47% | — | BugsinkAI | 10/11/2025 | 17/6/2026 | Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.5, brotli "bombs" (highly compressed brotli streams, such as many zeros) can be sent to the server. Since the server will attempt to decompress these streams before applying various maximums, this can lead to exhaustion of the available memory and… | |
| Aplazada | Crítica (9.8) | 0.59% | — | Ancorathemes BugspatrolAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in AncoraThemes BugsPatrol bugspatrol allows Object Injection.This issue affects BugsPatrol: from n/a through <= 1.5.0. | |
| Aplazada | Alta (7.1) | 0.13% | — | Wordpress Error Monitoring BY BugsnagAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tom Longridge WordPress Error Monitoring by Bugsnag bugsnag allows Stored XSS.This issue affects WordPress Error Monitoring by Bugsnag: from n/a through <= 1.6.3. | |
| Aplazada | Alta (7.2) | 0.58% | — | BugsinkAI | 30/7/2025 | 17/6/2026 | Bugsink is a self-hosted error tracking service. In versions 1.4.2 and below, 1.5.0 through 1.5.4, 1.6.0 through 1.6.3, and 1.7.0 through 1.7.3, ingestion paths construct file locations directly from untrusted event_id input without validation. A specially crafted event_id can result in paths outside the intended… | |
| Modificada | Media (6.1) | 0.84% | — | Pixeline Bugs | 1/10/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in install/index.php in bugs 1.8 and below version allows remote attackers to inject arbitrary web script or HTML via the first_name parameter. | |
| Modificada | Media (6.1) | 0.84% | — | Pixeline Bugs | 1/10/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in install/index.php in bugs 1.8 and below version allows remote attackers to inject arbitrary web script or HTML via the email parameter. | |
| Modificada | Media (6.1) | 0.84% | — | Pixeline Bugs | 1/10/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in install/index.php in bugs 1.8 and below version allows remote attackers to inject arbitrary web script or HTML via the last_name parameter. | |
| Modificada | Media (5.4) | 0.86% | — | Jenkins Findbugs | 4/11/2020 | 17/6/2026 | Jenkins FindBugs Plugin 5.0.0 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide report files to Jenkins FindBugs Plugin's post build step. | |
| Modificada | Crítica (9.8) | 8.9% | — | Themerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+59 | 10/3/2020 | 17/6/2026 | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter. | |
| Modificada | Crítica (9.8) | 2.4% | — | Tiny Issue Project Tiny IssuePixeline Bugs | 22/2/2019 | 17/6/2026 | An issue was discovered in Tiny Issue 1.3.1 and pixeline Bugs through 1.3.2c. install/config-setup.php allows remote attackers to execute arbitrary PHP code via the database_host parameter if the installer remains present in its original directory after installation is completed. | |
| Modificada | Alta (8.8) | 0.95% | — | Jenkins Findbugs | 23/1/2018 | 17/6/2026 | Jenkins FindBugs Plugin 4.71 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forgery, or denial-of-service attacks. | |
| Modificada | Alta (7.8) | 0.38% | — | Apt-listbugs Project Apt-listbugsDebian Linux | 20/10/2017 | 16/6/2026 | apt-listbugs before 0.1.10 creates temporary files insecurely, which allows attackers to have unspecified impact via unknown vectors. | |
| Modificada | Alta (7.5) | 1.0% | — | PHP Arena Pabugs | 8/8/2007 | 16/6/2026 | SQL injection vulnerability in main.php in paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php. | |
| Modificada | Alta (7.5) | 2.7% | — | PHP Arena Pabugs | 29/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in class.mysql.php in Matt Humphrey paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path_to_bt_dir parameter. |