Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3081▲ 625 respecto a la semana anterior
Críticas / altas1483▲ 317 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
2647 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Crítica (9.3) | — | — | Mooncake Transfer EngineAI | 1/10/2026 | 1/10/2026 | Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with arbitrary addr and size values using READ or… | |
| Recibida | Alta (8.7) | — | — | Mooncake Transfer EngineAI | 1/10/2026 | 1/10/2026 | Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenticated attackers to grow process memory without limit. Attackers can repeatedly send notify frames up to 1 MB to the handshake RPC port, filling the uncapped notifys… | |
| Recibida | Alta (8.2) | — | — | Mooncake Transfer EngineAI | 1/10/2026 | 1/10/2026 | Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies. Attackers can send a Metadata request to the handshake RPC port and stall SocketHandShakePlugin's single listener thread in… | |
| Aplazada | Alta (7.2) | — | — | Mowgli AI AI EngineAI | 1/10/2026 | 1/10/2026 | The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.0 This is due to a chain of missing input neutralization and output escaping across the /mwai-ui/v1/chats/submit REST endpoint, the PHP error-log parser… | |
| Aplazada | Media (6.5) | 0.22% | — | Jetimpex JetengineAI | 30/9/2026 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.8.15.3. | |
| Aplazada | Media (5.5) | 0.18% | — | Crocoblock JetengineAI | 30/9/2026 | 30/9/2026 | Subscriber Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetengineAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions. | |
| Aplazada | Alta (7.1) | 0.32% | — | Gosub EngineAI | 30/9/2026 | 30/9/2026 | Uncontrolled recursion in the Gosub browser engine (gosub-engine) through 0.1.0 and main before commit 46868b3 allows a remote attacker to cause a Denial of Service (stack exhaustion and application crash) via an SVG document containing an excessive number of deeply nested elements. Because the engine does not limit… | |
| Aplazada | Media (5.5) | 0.25% | — | Risesoft Y9 Workflow EngineAI | 29/9/2026 | 30/9/2026 | A vulnerability was detected in risesoft-y9 WorkFlow-Engine up to 9.6.10. Impacted is the function getByIdAndYear of the file CustomHistoricProcessServiceImpl.java of the component OAuth2 Resource Filter. Performing a manipulation of the argument year/processInstanceId results in sql injection. Remote exploitation of… | |
| Pendiente de análisis | Alta (7.5) | 0.37% | — | Socket.io Cluster-engineAI | 29/9/2026 | 30/9/2026 | Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 0.1.1, @socket.io/cluster-engine uses inherited object properties when looking up attacker-controlled session IDs in clustered deployments. Special property names such as __proto__ or constructor can resolve through the object… | |
| Pendiente de análisis | Alta (7.8) | 0.99% | — | Esengine Deepseek-reasonixAI | 29/9/2026 | 29/9/2026 | OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine DeepSeek-Reasonix (Reasonix Studio) allows a local attacker who controls repository content (.gitattributes + .git/config) to execute arbitrary commands via the desktop app's workspace-changes diff viewer. | |
| Pendiente de análisis | Alta (8.8) | 0.88% | — | Zohocorp Manageengine DDI CentralAI | 28/9/2026 | 29/9/2026 | Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endpoint leading to destructive PostgreSQL database operations. | |
| Pendiente de análisis | Alta (8.8) | 2.0% | — | Zohocorp Manageengine DDI CentralAI | 28/9/2026 | 29/9/2026 | Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via HA Failover Config sync upload leading to remote code execution. | |
| Pendiente de análisis | Alta (8.8) | 7.0% | — | Zohocorp Manageengine DDI CentralAI | 28/9/2026 | 29/9/2026 | Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the HA configuration workflow. This issue could allow an authenticated operator-level user to modify the Keepalived configuration and potentially execute commands as root on the DDI Central host. | |
| Pendiente de análisis | Alta (8.8) | 4.7% | — | Manageengine DDI CentralAI | 28/9/2026 | 29/9/2026 | ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF/TXT record push leading to remote code execution. | |
| Pendiente de análisis | Alta (7.2) | 3.6% | — | Manageengine DDI CentralAI | 28/9/2026 | 29/9/2026 | ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Query Resolution Policy name field leading to remote code execution. | |
| Aplazada | Media (5.9) | 0.13% | — | Havelsan Liman Render EngineAI | 24/9/2026 | 24/9/2026 | Improper certificate validation vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM). This issue affects Liman Render Engine: from 1.0 before 1.2-75. | |
| Aplazada | Media (5.9) | 0.24% | — | Havelsan Liman Render EngineAI | 24/9/2026 | 24/9/2026 | Key exchange without entity authentication vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM). This issue affects Liman Render Engine: from 1.0 before 1.2-75. | |
| Aplazada | Media (5.5) | 0.25% | — | Softnews Media Group Datalife EngineAI | 23/9/2026 | 24/9/2026 | A vulnerability was identified in SoftNews Media Group DataLife Engine 18.0. This affects the function strip_data of the file engine/modules/search.php of the component Search Module. The manipulation of the argument story leads to sql injection. The attack can be initiated remotely. The exploit is publicly available… | |
| Aplazada | Media (5.3) | 0.23% | — | AI EngineAI | 23/9/2026 | 23/9/2026 | Unauthenticated Insecure Direct Object References (IDOR) in AI Engine <= 3.7.8 versions. | |
| Pendiente de análisis | Crítica (10) | 1.2% | — | Zoho Manageengine Applications ManagerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources. | |
| Pendiente de análisis | Alta (8.1) | 0.68% | — | Zoho Manageengine Applications ManagerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy settings. | |
| Pendiente de análisis | Alta (7.6) | 0.46% | — | Zohocorp Manageengine Applications ManagerAI | 23/9/2026 | 23/9/2026 | ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned scope. | |
| Pendiente de análisis | Alta (7.1) | 0.78% | — | Zoho Manageengine Applications ManagerAI | 23/9/2026 | 23/9/2026 | ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue that allowed a low-privileged user to delete service monitors outside their assigned scope. | |
| Pendiente de análisis | Alta (8.8) | 0.68% | — | Zohocorp Manageengine Applications ManagerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions. |