Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2965▲ 27 respecto a la semana anterior
Críticas / altas1456▲ 193 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.36% | — | Capgo Cap-goAI | 11/7/2026 | 13/7/2026 | Cap-go before 12.128.2 contains an information disclosure vulnerability in the public.transfer_app RPC function that returns distinct error messages for existing versus non-existing app IDs. Unauthenticated attackers can enumerate valid app IDs by observing error message differences when calling transfer_app with only… | |
| Aplazada | Media (5.3) | 0.30% | — | Capgo Cap-goAI | 24/6/2026 | 25/6/2026 | Cap-go before 12.128.2 contains an authorization bypass vulnerability in the GET /organization/members endpoint that allows org-limited API keys to bypass limited_to_orgs restrictions. Attackers with org-limited API keys can read membership data including uid, email, image_url, role, and is_tmp from organizations… | |
| Aplazada | Alta (7.1) | 0.37% | — | Capgo Cap-goAI | 22/6/2026 | 24/6/2026 | Cap-go before 12.128.2 contains a privilege inversion vulnerability in GET /build/logs/:jobId that allows read-only API key holders to cancel running native builds. The endpoint registers an abort listener on the SSE stream that unconditionally invokes cancelBuildOnDisconnect() using the privileged server-side… | |
| Aplazada | Alta (7.1) | 0.38% | — | Capgo Cap-goAI | 22/6/2026 | 23/6/2026 | Cap-go before 12.128.2 contains multiple SQL injection vulnerabilities in cloudflare.ts where user-controlled values from API request bodies are interpolated directly into SQL query strings without sanitization or parameterization. Authenticated users with read-level API key permissions can inject arbitrary SQL… | |
| Aplazada | Media (6.9) | 0.41% | — | Capgo Cap-goAI | 21/6/2026 | 24/6/2026 | Cap-go before 12.128.2 contains an information disclosure vulnerability in the OPTIONS /build/upload/:jobId/* endpoint that allows unauthenticated attackers to enumerate valid builder job IDs through observable response discrepancies. Attackers can probe the endpoint without authentication to distinguish valid job IDs… | |
| Aplazada | Media (5.3) | 0.37% | — | Cloudflare WorkerdAICapgo Cap-goAI | 20/6/2026 | 22/6/2026 | Cap-go before 12.128.12 contains a broken cursor pagination vulnerability in the /private/devices endpoint on the Cloudflare/workerd path that allows authenticated attackers to cause duplicate-page loops and make later rows unreachable. Attackers with app.read_devices access can exploit non-advancing cursor filters to… | |
| Aplazada | Crítica (9.3) | 0.57% | — | Capgo Cap-goAI | 19/6/2026 | 22/6/2026 | Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound to a victim's email address before that email is verified. By enabling two-factor authentication on the pre-registered account, the attacker gains control over the account claimed under the victim's… | |
| Aplazada | Crítica (9.3) | 0.27% | — | Capgo Cap-goAI | 19/6/2026 | 22/6/2026 | Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypass email verification by modifying server responses. Attackers can intercept OTP verification requests and manipulate HTTP responses to falsely mark verification successful, enabling unauthorized 2FA… | |
| Aplazada | Alta (7.2) | 0.48% | — | Capgo Cap-goAI | 12/6/2026 | 17/6/2026 | Cap-go prior to 12.128.2 contains an account takeover vulnerability in its email change mechanism that allows an attacker with temporary authenticated session access to change the registered email address without re-authentication such as password or MFA verification. Attackers can redirect verification to an… |