Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2585▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
148 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.7) | 0.23% | — | Tp-link Deco M9 PlusAI | 1/10/2026 | 1/10/2026 | A stack-based buffer overflow vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Deco M9 Plus due to insufficient validation of decrypted request data length before it is copied into a fixed-size stack buffer in the subtype 0x91 handler. Successful exploitation may allow an adjacent, unauthenticated… | |
| Aplazada | Media (6.9) | 0.30% | — | Decolua 9routerAI | 30/9/2026 | 1/10/2026 | A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search Endpoint. Performing a manipulation of the argument provider_options.baseUrl results in server-side request forgery. The attack can be initiated… | |
| Pendiente de análisis | Crítica (9.1) | 0.81% | — | Xhmikosr DecompressAI | 28/9/2026 | 30/9/2026 | The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An attacker can supply a crafted archive containing chained symlink entries so that a… | |
| Aplazada | Media (6.1) | 0.34% | — | Udecode PlateAI | 16/9/2026 | 16/9/2026 | Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, and in the discontinued 54.0.0-beta.0 through 54.0.0-beta.1 builds, Plate core HTML deserialization APIs parse supplied HTML strings in the active document. When an application passes untrusted or cross-user HTML to these APIs, certain HTML… | |
| Aplazada | Alta (7.7) | 5.0% | — | Tp-link Deco Be11000AI | 10/9/2026 | 1/10/2026 | An OS command injection vulnerability in the TDDP module of Deco BE11000 and Deco M9 Plus allows an adjacent network attacker to execute arbitrary commands with root privileges by sending a crafted UDP packet. Successful exploitation may lead to complete device compromise, including unauthorized command execution,… | |
| Pendiente de análisis | Alta (8.7) | 0.24% | — | Moos-ivp UfldnodecommsAI | 3/9/2026 | 8/9/2026 | MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than validating it from the connection source. Attackers can craft NODE_MESSAGE packets with spoofed source identities to impersonate other nodes and post arbitrary variable notifications without validation. | |
| Pendiente de análisis | Alta (7.7) | 0.38% | — | Tp-link Deco Xe75AITp-link Xe5300AITp-link We10800AI | 24/8/2026 | 28/8/2026 | The use of hard-coded cryptographic key vulnerability has been identified in the mesh functionality of Deco XE75 v3, XE5300 v3.6 and WE10800 v3.6. A shared RSA-512 mesh group private key is present in the affected firmware and is used by the mesh protocol for node authentication. An attacker who obtains the firmware… | |
| Aplazada | Alta (8.2) | 0.36% | — | Agenticmail ClaudecodeAIAgenticmail CoreAICodexnotes CodexAIOpenclawAI | 20/7/2026 | 23/7/2026 | AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39, @agenticmail/codex prior to version 0.1.33, @agenticmail/core prior to version 0.9.43, and @agenticmail/openclaw prior to version 0.5.71, two inbound-mail handlers act on a privileged effect without… | |
| Pendiente de análisis | Crítica (9.1) | 0.75% | — | Xhmikosr DecompressAI | 14/7/2026 | 15/7/2026 | The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a directory, a crafted archive can read or write files outside that directory because hardlink and symlink entries are created… | |
| Analizada | Alta (7.1) | 0.13% | — | Tp-link Deco M5 Firmware | 14/7/2026 | 6/8/2026 | TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the password hash through system compromise or privileged access could perform brute-force or dictionary attacks. Successful exploitation may result in disclosure of authentication credentials, enabling… | |
| Analizada | Alta (7.5) | 0.66% | — | Decompress Project Decompress | 9/7/2026 | 13/7/2026 | decompress before 4.2.2 allows arbitrary symlink creation during archive extraction. When processing symlink entries (type === 'symlink'), the x.linkname field from the archive is passed directly to fs.symlink() without validation (index.js line 121). The preventWritingThroughSymlink check on line 98 only applies to… | |
| Analizada | Media (6.2) | 0.38% | — | Decompress Project Decompress | 9/7/2026 | 13/7/2026 | decompress before 4.2.2 contains an improper path containment check that enables directory traversal and arbitrary file write. The safeMakeDir function (index.js line 29) and the extraction path validation (index.js line 106) use String.indexOf() to verify the resolved path is within the output directory:… | |
| Analizada | Media (5.5) | 0.30% | — | Decompress Project Decompress | 9/7/2026 | 13/7/2026 | decompress before 4.2.2 allows arbitrary hardlink creation during archive extraction, enabling file read disclosure and file corruption. When processing hardlink entries (type === 'link'), the x.linkname field from the archive is passed directly to fs.link() without validation (index.js line 113). An attacker can… | |
| Aplazada | Alta (8.7) | 0.43% | — | Udecode PlateAI | 8/7/2026 | 10/7/2026 | Plate is a rich-text editor with AI and shadcn/ui. From 53.0.0 until 53.1.4, the media embed renderer trusts serialized provider or sourceUrl metadata in useMediaState and skips parseMediaUrl protocol validation, allowing a crafted Plate document to set a known video provider while keeping url as a javascript: iframe… | |
| Aplazada | Media (6.6) | 0.51% | — | Decode-uri-componentAI | 30/6/2026 | 30/6/2026 | decode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' producing N tokens and calls decodeComponents(), exhibiting super-linear parsing time: 200 '%ab' tokens takes approximately 0.7s, 700 tokens approximately 6s, and 1400 tokens approximately 33s. An attacker… | |
| Aplazada | Alta (7.5) | 0.61% | — | Webp DecoderAI | 25/6/2026 | 26/6/2026 | The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size. | |
| Pendiente de análisis | Media (5.6) | 0.52% | — | DecompressAI | 5/6/2026 | 7/9/2026 | All versions of the package decompress are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) when extracting a ZIP archive containing two entries with the same path - the first being a symlink to an arbitrary target and the second being a regular file - the file content is written through the… | |
| Aplazada | Media (5.3) | 0.28% | — | Decolua 9routerAI | 1/6/2026 | 22/7/2026 | A security vulnerability has been detected in decolua 9router up to 0.4.0. This issue affects the function isAuthenticated of the file src/dashboardGuard.js of the component HTTP Header Handler. The manipulation of the argument Host leads to improper authorization. The attack is possible to be carried out remotely.… | |
| Aplazada | Alta (8.1) | 0.48% | — | Perl Sereal DecoderAI | 31/5/2026 | 22/7/2026 | Sereal::Decoder versions before 5.005 for Perl allow heap out-of-bounds read via crafted input. In Perl/Decoder/srl_decoder.c, srl_read_object() and srl_read_hash() process a COPY tag, a back-reference whose target byte the decoder re-decodes as a fresh tag. When that target byte matches the SHORT_BINARY pattern (an… | |
| Aplazada | Media (6.1) | 0.29% | — | CodecolorerAI | 16/4/2026 | 17/6/2026 | The CodeColorer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in 'cc' comment shortcode in versions up to, and including, 0.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Media (5.5) | 0.54% | — | Decolua 9routerAI | 9/4/2026 | 17/6/2026 | A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the component Administrative API Endpoint. The manipulation leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed… | |
| Analizada | Crítica (9.3) | 0.67% | — | Varaneckas JAD Java Decompiler | 28/3/2026 | 17/6/2026 | JAD Java Decompiler 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying overly long input that exceeds buffer boundaries. Attackers can craft malicious input passed to the jad command to overflow the stack and execute a… | |
| Analizada | Crítica (9.3) | 0.67% | — | Varaneckas JAD Java Decompiler | 28/3/2026 | 17/6/2026 | JAD 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying oversized input that exceeds buffer boundaries. Attackers can craft malicious input strings exceeding 8150 bytes to overflow the stack, overwrite return addresses, and execute… | |
| Aplazada | Alta (7.1) | 0.18% | — | Skygroup MydecorAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup MyDecor mydecor allows Reflected XSS.This issue affects MyDecor: from n/a through < 1.5.9. | |
| Analizada | Alta (8.6) | 0.26% | — | 4mhz Base64 Decoder | 24/3/2026 | 17/6/2026 | Base64 Decoder 1.1.2 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by triggering a structured exception handler (SEH) overwrite. Attackers can craft a malicious input file that overflows a buffer, overwrites the SEH chain with a POP-POP-RET gadget address,… |