Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2546▼ 402 respecto a la semana anterior
Críticas / altas1312▲ 29 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
–

392 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.43%—Digiwin Easyflow DOT NETAI30/9/202630/9/2026
EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain other users' plaintext passwords through a specific API.
AplazadaMedia (5.3)0.59%—DotvvmAI14/9/202630/9/2026
DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, applications with configured file upload storage allow unauthenticated users to submit files directly to DotvvmFileUploadMiddleware without an X-DotVVM-UploadToken generated by the FileUpload component. An…
AplazadaCrítica (9.2)0.62%—DotvvmAI14/9/202630/9/2026
DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, AuthorizeActionFilter performs no authorization because its explicit ICommandActionFilter.OnCommandExecutingAsync, IViewModelActionFilter.OnViewModelCreatedAsync, and…
AplazadaAlta (8.2)0.58%—DotvvmAI14/9/202630/9/2026
DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, a route containing multiple unconstrained parameters in one path segment can cause excessive regular-expression backtracking in DotvvmRoute.IsMatch when a remote requester supplies a long near-match path.…
Pendiente de análisisMedia (6.5)0.27%—Microsoft DotnetAI8/9/20268/9/2026
Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.
AplazadaMedia (5.9)0.23%—Thedotstore Ninja FormsAI4/9/20268/9/2026
The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms WordPress plugin before 3.15.2-specific capability as equivalent to full site administration, which allows any user granted that capability to read Ninja Forms WordPress plugin before 3.15.2…
AplazadaAlta (7.1)0.28%—Spacedot Acubesat OBCAI24/8/20269/9/2026
An out-of-bounds read vulnerability in the CAN::Application::parsePerformFunctionMessage component of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying a crafted CAN message.
AplazadaAlta (7.5)0.46%—Spacedot Acubesat OBCAI24/8/20269/9/2026
A stack overflow in the loadRawData function of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying a crafted ECSS TC message.
AplazadaAlta (7.5)0.46%—Spacedot Acubesat OBCAI24/8/20269/9/2026
An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec allows physically-proximate attackers with UART access to cause a Denial of Service (DoS) via a crafted input.
AplazadaMedia (6.5)0.36%—Spacedot Acubesat OBCAI24/8/20269/9/2026
An out-of-bounds read/write vulnerability in the MessageParser::parseECSSTCHeader component of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying a crafted CAN message.
AplazadaBaja (1.9)1.1%—Leesinliang Godot-mcpAI6/8/202612/8/2026
A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of the file src/index.ts of the component create_scene/add_node. This manipulation of the argument projectPath causes command injection. The attack needs to be launched locally. The project was…
AnalizadaMedia (6.5)0.65%—Apache Qpid Proton-dotnet5/8/20267/8/2026
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the…
AnalizadaMedia (6.5)0.65%—Apache Qpid Proton-dotnet5/8/20267/8/2026
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.
AnalizadaMedia (6.5)0.65%—Apache Qpid Proton-dotnet5/8/20267/8/2026
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.
AnalizadaAlta (7.5)0.77%—Apache Qpid Proton-dotnet5/8/20267/8/2026
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue
AnalizadaAlta (7.5)0.77%—Apache Qpid Proton-dotnet5/8/20267/8/2026
pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.
AnalizadaAlta (7.5)0.77%—Apache Qpid Proton-dotnet5/8/20267/8/2026
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.
AplazadaAlta (7.5)0.41%—Multidots Product Attachment FOR WoocommerceAI2/8/202626/8/2026
The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users to download any attachment — including private or unlinked uploads — by enumerating its numeric ID.
Pendiente de análisisCrítica (9.4)0.55%—DotcmsAI20/7/202622/7/2026
Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms allows a low-privileged authenticated backend user to self-assign the administrative layout and self-grant the CMS Administrator role, then achieve remote code execution via a…
AplazadaBaja (2.1)0.45%—Svgdotjs Svg.jsAI14/7/202615/7/2026
A vulnerability was found in svgdotjs svg.js up to 3.2.5. This affects the function EventTarget.on of the file svgdotjs/svg.js of the component npm Package API. Performing a manipulation results in improperly controlled modification of object prototype attributes. The attack may be initiated remotely. The project was…
AplazadaBaja (1.9)0.17%—Tugcantopaloglu Godot-mcpAI13/7/202613/7/2026
A security flaw has been discovered in tugcantopaloglu godot-mcp 2.0.0. Affected by this vulnerability is the function validatePath of the file build/index.js of the component run_project. The manipulation of the argument projectPath results in path traversal. Attacking locally is a requirement. The exploit has been…
AplazadaBaja (2)0.07%—Thedotmack Claude-memAI5/6/202617/6/2026
A weakness has been identified in thedotmack claude-mem up to 11.0.1. The affected element is the function computeObservationContentHash of the file src/services/sqlite/observations/store.ts of the component Observation Content Hash Handler. This manipulation causes use of weak hash. The attack can only be executed…
AplazadaCrítica (9.2)0.66%—Spacelabs Healthcare SentinelAIMicrosoft IISAIMicrosoft DotnetAI2/6/202622/7/2026
Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability through a deprecated .NET Remoting HTTP channel exposed on port 8989 that allows attackers to perform arbitrary file read and write operations by supplying valid .NET URI…
AplazadaCrítica (10)1.6%—Dotcms CoreAI27/5/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish Audit API endpoints (/api/auditPublishing/get and /api/auditPublishing/getAll) in dotCMS Core 25.11.04-1 through 26.04.28-02 allows remote unauthenticated attackers to read, modify, or destroy arbitrary database…
AplazadaBaja (3.7)0.34%—MicrodotAI11/5/202617/6/2026
Microdot is a minimalistic Python web framework. Prior to 2.6.1, the Response.set_cookie() method does not sanitize its string arguments, and in particular will not detect the presence of the \r\n sequence in them. This can be a potential source of header injection attacks. For a header injection attack through this…