Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 77 respecto a la semana anterior
Críticas / altas1446▲ 303 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.47% | — | Cleo HarmonyAI | 1/9/2026 | 1/9/2026 | A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connections of the component JWT Refresh Token Handler. Performing a manipulation of the argument Bearer results in improper privilege management. The attack is possible to be carried out remotely.… | |
| Aplazada | Baja (2.1) | 0.46% | — | Cleo HarmonyAI | 1/9/2026 | 1/9/2026 | A vulnerability has been found in Cleo Harmony up to 5.8.1.10. Impacted is the function LocalUserUtil.getNativeUserByAssertions of the component SAML Authentication. Such manipulation of the argument Email leads to improper authentication. The attack can be executed remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (6.9) | 0.46% | — | Nucleoidai NucleoidAI | 16/10/2025 | 17/6/2026 | A vulnerability was identified in NucleoidAI Nucleoid up to 0.7.10. The impacted element is the function extension.apply of the file /src/cluster.ts of the component Outbound Request Handler. Such manipulation of the argument https/ip/port/path/headers leads to server-side request forgery. The attack may be performed… | |
| Aplazada | Media (5.9) | 0.23% | — | CK Macleod Category Featured Images ExtendedAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CK MacLeod Category Featured Images Extended category-featured-images-extended allows Stored XSS.This issue affects Category Featured Images Extended: from n/a through <= 1.52. | |
| Analizada | Crítica (9.8) | 94% | ⚠ Explotación activa | Cleo HarmonyCleo LexicomCleo Vltrader | 13/12/2024 | 5/8/2026 | In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa | Cleo HarmonyCleo LexicomCleo Vltrader | 28/10/2024 | 31/7/2026 | In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution. | |
| Analizada | Alta (7.5) | 0.95% | — | Python-poetry Cleo | 9/11/2022 | 17/6/2026 | An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the cleo PyPI package, when an attacker is able to supply arbitrary input to the Table.set_rows method | |
| Modificada | Media (5.3) | 0.58% | — | Cleo Lexicom | 18/6/2021 | 17/6/2026 | An issue was discovered in Cleo LexiCom 5.5.0.0. The requirement for the sender of an AS2 message to identify themselves (via encryption and signing of the message) can be bypassed by changing the Content-Type of the message to text/plain. | |
| Modificada | Crítica (9.8) | 1.5% | — | Cleo Lexicom | 18/6/2021 | 17/6/2026 | An issue was discovered in Cleo LexiCom 5.5.0.0. Within the AS2 message, the sender can specify a filename. This filename can include path-traversal characters, allowing the file to be written to an arbitrary location on disk. | |
| Modificada | Media (5.4) | 0.27% | — | Magzter Cleo Malaysia | 19/10/2014 | 17/6/2026 | The CLEO Malaysia (aka com.magzter.cleomalaysia) application 3.01 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |