Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3081▲ 625 respecto a la semana anterior
Críticas / altas1483▲ 317 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
–

2647 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaCrítica (9.3)——Mooncake Transfer EngineAI1/10/20261/10/2026
Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with arbitrary addr and size values using READ or…
RecibidaAlta (8.7)——Mooncake Transfer EngineAI1/10/20261/10/2026
Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenticated attackers to grow process memory without limit. Attackers can repeatedly send notify frames up to 1 MB to the handshake RPC port, filling the uncapped notifys…
RecibidaAlta (8.2)——Mooncake Transfer EngineAI1/10/20261/10/2026
Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies. Attackers can send a Metadata request to the handshake RPC port and stall SocketHandShakePlugin's single listener thread in…
AplazadaAlta (7.2)——Mowgli AI AI EngineAI1/10/20261/10/2026
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.0 This is due to a chain of missing input neutralization and output escaping across the /mwai-ui/v1/chats/submit REST endpoint, the PHP error-log parser…
AplazadaMedia (6.5)0.22%—Jetimpex JetengineAI30/9/202630/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.8.15.3.
AplazadaMedia (5.5)0.18%—Crocoblock JetengineAI30/9/202630/9/2026
Subscriber Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions.
AplazadaAlta (7.1)0.25%—Crocoblock JetengineAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions.
AplazadaAlta (7.1)0.32%—Gosub EngineAI30/9/202630/9/2026
Uncontrolled recursion in the Gosub browser engine (gosub-engine) through 0.1.0 and main before commit 46868b3 allows a remote attacker to cause a Denial of Service (stack exhaustion and application crash) via an SVG document containing an excessive number of deeply nested elements. Because the engine does not limit…
AplazadaMedia (5.5)0.25%—Risesoft Y9 Workflow EngineAI29/9/202630/9/2026
A vulnerability was detected in risesoft-y9 WorkFlow-Engine up to 9.6.10. Impacted is the function getByIdAndYear of the file CustomHistoricProcessServiceImpl.java of the component OAuth2 Resource Filter. Performing a manipulation of the argument year/processInstanceId results in sql injection. Remote exploitation of…
Pendiente de análisisAlta (7.5)0.37%—Socket.io Cluster-engineAI29/9/202630/9/2026
Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 0.1.1, @socket.io/cluster-engine uses inherited object properties when looking up attacker-controlled session IDs in clustered deployments. Special property names such as __proto__ or constructor can resolve through the object…
Pendiente de análisisAlta (7.8)0.99%—Esengine Deepseek-reasonixAI29/9/202629/9/2026
OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine DeepSeek-Reasonix (Reasonix Studio) allows a local attacker who controls repository content (.gitattributes + .git/config) to execute arbitrary commands via the desktop app's workspace-changes diff viewer.
Pendiente de análisisAlta (8.8)0.88%—Zohocorp Manageengine DDI CentralAI28/9/202629/9/2026
Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endpoint leading to destructive PostgreSQL database operations.
Pendiente de análisisAlta (8.8)2.0%—Zohocorp Manageengine DDI CentralAI28/9/202629/9/2026
Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via HA Failover Config sync upload leading to remote code execution.
Pendiente de análisisAlta (8.8)7.0%—Zohocorp Manageengine DDI CentralAI28/9/202629/9/2026
Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the HA configuration workflow. This issue could allow an authenticated operator-level user to modify the Keepalived configuration and potentially execute commands as root on the DDI Central host.
Pendiente de análisisAlta (8.8)4.7%—Manageengine DDI CentralAI28/9/202629/9/2026
ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF/TXT record push leading to remote code execution.
Pendiente de análisisAlta (7.2)3.6%—Manageengine DDI CentralAI28/9/202629/9/2026
ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Query Resolution Policy name field leading to remote code execution.
AplazadaMedia (5.9)0.13%—Havelsan Liman Render EngineAI24/9/202624/9/2026
Improper certificate validation vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM). This issue affects Liman Render Engine: from 1.0 before 1.2-75.
AplazadaMedia (5.9)0.24%—Havelsan Liman Render EngineAI24/9/202624/9/2026
Key exchange without entity authentication vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM). This issue affects Liman Render Engine: from 1.0 before 1.2-75.
AplazadaMedia (5.5)0.25%—Softnews Media Group Datalife EngineAI23/9/202624/9/2026
A vulnerability was identified in SoftNews Media Group DataLife Engine 18.0. This affects the function strip_data of the file engine/modules/search.php of the component Search Module. The manipulation of the argument story leads to sql injection. The attack can be initiated remotely. The exploit is publicly available…
AplazadaMedia (5.3)0.23%—AI EngineAI23/9/202623/9/2026
Unauthenticated Insecure Direct Object References (IDOR) in AI Engine <= 3.7.8 versions.
Pendiente de análisisCrítica (10)1.2%—Zoho Manageengine Applications ManagerAI23/9/202624/9/2026
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources.
Pendiente de análisisAlta (8.1)0.68%—Zoho Manageengine Applications ManagerAI23/9/202624/9/2026
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy settings.
Pendiente de análisisAlta (7.6)0.46%—Zohocorp Manageengine Applications ManagerAI23/9/202623/9/2026
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned scope.
Pendiente de análisisAlta (7.1)0.78%—Zoho Manageengine Applications ManagerAI23/9/202623/9/2026
ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue that allowed a low-privileged user to delete service monitors outside their assigned scope.
Pendiente de análisisAlta (8.8)0.68%—Zohocorp Manageengine Applications ManagerAI23/9/202624/9/2026
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions.