Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2532▼ 363 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
65 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.35% | — | Gutenverse Ultimate Wordpress FSE Blocks Addons EcosystemAI | 26/8/2026 | 26/8/2026 | The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the multiple blocks in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Pendiente de análisis | Baja (2.1) | 0.31% | — | Erlang Ecosystem Foundation Oidcc PlugAI | 4/8/2026 | 4/8/2026 | Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback module) allows an attacker to make a victim's browser complete an authorization flow the victim never initiated. This vulnerability is associated with program file… | |
| Pendiente de análisis | Media (6.3) | 0.44% | — | Erlang Ecosystem Foundation Oidcc PlugAI | 4/8/2026 | 4/8/2026 | Improper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.Authorize module) renders the user agent session binding inert, removing a defense in depth control against replay of a stolen session. This vulnerability is associated with program files… | |
| Pendiente de análisis | Alta (8.5) | 0.15% | — | Bosh-ecosystem Bosh-windows-stemcell-builderAI | 9/7/2026 | 9/7/2026 | Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege authenticated users to overwrite C:\bosh\service_wrapper.exe or C:\bosh\bosh-agent.exe and gain NT AUTHORITY\SYSTEM on the next service restart or reboot. This can lead to full host control. Affected… | |
| Pendiente de análisis | Alta (7.5) | 0.42% | — | Bosh-ecosystem Windows Utilities ReleaseAI | 4/6/2026 | 22/7/2026 | Weak Randomness / Insecure Cryptographic Primitive (CWE-338) in Get-RandomPassword in BOSH-Ecosystem / windows-utilities-release allows a network attacker to estimate VM boot time and reconstruct a small candidate list to recover the Administrator password. The randomize_password job exists solely to lock the local… | |
| Aplazada | Media (6.5) | 0.39% | — | Slovak EID Client Ecosystem D.launcherAI | 2/6/2026 | 22/7/2026 | D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Application registers multiple custom URL handlers that could be exploited to initiate full NTLM autentication or SMB connection to attacker infrastructure and to conduct SSRF (Server Side Request Forgery)… | |
| Pendiente de análisis | Alta (8.8) | 0.68% | — | Cosyvoice Project CosyvoiceAIPytorchAI | 12/5/2026 | 17/6/2026 | The CosyVoice project thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its model loading process. When loading model files (.pt) from a user-specified directory (via the --model_dir argument), the code uses torch.load() without the… | |
| Aplazada | Media (5.7) | 0.30% | — | CosyvoiceAI | 11/5/2026 | 17/6/2026 | CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its model loading component. The framework uses torch.load() to load model weight files (e.g., llm.pt, flow.pt, hift.pt) without enabling the security-restrictive… | |
| Aplazada | Alta (7.3) | 0.37% | — | CosyvoiceAI | 11/5/2026 | 17/6/2026 | CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its gRPC server component. When the server starts, it loads the speech synthesis model from a user-specified directory using torch.load() without enabling the weights_only=True… | |
| Aplazada | Alta (7.3) | 0.36% | — | CosyvoiceAIPytorchAI | 11/5/2026 | 17/6/2026 | CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its average_model.py model averaging tool. The script loads PyTorch checkpoint files (epoch_*.pt) for model averaging using torch.load() without enabling the weights_only=True… | |
| Aplazada | Alta (7.3) | 0.36% | — | CosyvoiceAI | 11/5/2026 | 17/6/2026 | CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its make_parquet_list.py data processing tool. The script loads PyTorch .pt files (utterance embeddings, speaker embeddings, speech tokens) using torch.load() without enabling the… | |
| Analizada | Media (5.6) | 0.14% | — | Home-assistant-ecosystem Home Assistant Command-line Interface | 21/4/2026 | 17/6/2026 | The Home Assistant Command-line interface (hass-cli) is a command-line tool for Home Assistant. Up to 1.0.0 of home-assitant-cli an unrestricted environment was used to handle Jninja2 templates instead of a sandboxed one. The user-supplied input within Jinja2 templates was rendered locally with no restrictions. This… | |
| Analizada | Alta (7.1) | 0.59% | — | Nginxui Nginx UIUozi Cosy | 30/3/2026 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui application is vulnerable to a Race Condition. Due to the complete absence of synchronization mechanisms (Mutex) and non-atomic file writes, concurrent requests lead to the severe corruption of the primary configuration… | |
| Aplazada | Crítica (9.8) | 0.94% | — | Hms-networks Ewon FlexyAIHms-networks Cosy PlusAI | 13/3/2026 | 17/6/2026 | HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have a stack buffer overflow that leads to a Denial of Service, which can also be exploited to achieve Unauthenticated Remote Code Execution. | |
| Aplazada | Alta (7.5) | 0.63% | — | Hms-networks Ewon FlexyAIHms-networks Cosy PlusAI | 13/3/2026 | 17/6/2026 | HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 allows unauthenticated attackers to cause a Denial of Service by using a specially crafted HTTP request that leads to a reboot of the device, provided they have access to the… | |
| Aplazada | Crítica (9.1) | 0.20% | — | Hms-networks Ewon FlexyAIHms-networks Cosy PlusAI | 13/3/2026 | 17/6/2026 | HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have weak entropy for authentication cookies, allowing an attacker with a stolen session cookie to find the user password by brute-forcing an encryption parameter. | |
| Aplazada | Alta (8.8) | 0.85% | — | Hms-networks Ewon FlexyAIHms-networks Cosy PlusAI | 13/3/2026 | 17/6/2026 | HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have improper neutralization of special elements used in an OS command allowing remote code execution by attackers with low privilege access on the gateway, provided the attacker… | |
| Analizada | Alta (7.5) | 0.50% | — | Thecosy Icecms | 14/1/2025 | 17/6/2026 | An access control issue in the component /api/squareComment/DelectSquareById of iceCMS v2.2.0 allows unauthenticated attackers to access sensitive information. | |
| Analizada | Alta (7.5) | 0.50% | — | Thecosy Icecms | 14/1/2025 | 17/6/2026 | An access control issue in the component /square/getAllSquare/circle of iceCMS v2.2.0 allows unauthenticated attackers to access sensitive information. | |
| Analizada | Crítica (9.8) | 0.64% | — | Thecosy Icecms | 30/10/2024 | 17/6/2026 | icecms <=3.4.7 has a File Upload vulnerability in FileUtils.java,uploadFile. | |
| Analizada | Crítica (9.8) | 0.63% | — | Thecosy Icecms | 25/9/2024 | 17/6/2026 | IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication information. | |
| Modificada | Alta (7.5) | 0.47% | — | Thecosy Icecms | 25/9/2024 | 17/6/2026 | An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request sent to the endpoint /User/ChangeUser/s in the ChangeUser function in UserController.java | |
| Analizada | Alta (7.5) | 0.67% | — | Thecosy Icecms | 25/9/2024 | 17/6/2026 | An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to access and returns all user information, including passwords | |
| Modificada | Alta (7.6) | 0.52% | — | Thecosy Icecms | 25/9/2024 | 5/7/2026 | Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password via the loginAdmin method in the UserController.java file. | |
| Aplazada | Baja (3.8) | 0.29% | — | N-able Ecosystem AgentAI | 12/8/2024 | 17/6/2026 | Ecosystem Agent version 4 < 4.1.5.2597 and Ecosystem Agent version 5 < 5.1.4.2473 did not properly validate SSL/TLS certificates, which could allow a malicious actor to perform a Man-in-the-Middle and intercept traffic between the agent and N-able servers from a privileged network position. |