Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
85 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | JettabsAI | 17/9/2026 | 17/9/2026 | Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions. | |
| Aplazada | Media (5.5) | 0.69% | — | Letta-ai LettabotAI | 6/8/2026 | 12/8/2026 | A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts of the component API Status Route. The manipulation results in missing authentication. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted… | |
| Aplazada | Media (5.5) | 0.53% | — | 666ghj BettafishAI | 5/7/2026 | 6/7/2026 | A vulnerability was determined in 666ghj BettaFish up to 1.2.1. Impacted is the function _deduplicate_results of the file InsightEngine/agent.py of the component InsightEngine search-result Deduplication. Executing a manipulation can lead to partial string comparison. The attack can be launched remotely. The exploit… | |
| Analizada | Media (5.5) | 0.77% | — | Letta | 27/3/2026 | 17/6/2026 | A vulnerability was detected in letta-ai letta 0.16.4. This issue affects the function resolve_type of the file letta/functions/ast_parsers.py of the component Incomplete Fix CVE-2025-6101. Performing a manipulation results in improper neutralization of directives in dynamically evaluated code. The attack can be… | |
| Analizada | Baja (2.1) | 0.39% | — | Letta | 27/3/2026 | 17/6/2026 | A security vulnerability has been detected in letta-ai letta 0.16.4. This vulnerability affects the function _convert_message_create_to_message of the file letta/helpers/message_helper.py of the component File URL Handler. Such manipulation of the argument ImageContent leads to server-side request forgery. It is… | |
| Aplazada | Media (6.5) | 0.16% | — | Crocoblock JettabsAI | 29/12/2025 | 1/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs jet-tabs allows DOM-Based XSS.This issue affects JetTabs: from n/a through <= 2.2.12. | |
| Aplazada | Media (6.5) | 0.24% | — | Crocoblock JettabsAI | 29/12/2025 | 1/10/2026 | Missing Authorization vulnerability in Crocoblock JetTabs jet-tabs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetTabs: from n/a through <= 2.2.12. | |
| Aplazada | Alta (8.1) | 0.50% | — | Ancorathemes EttaAIPHPAI | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Etta etta allows PHP Local File Inclusion.This issue affects Etta: from n/a through <= 1.14.0. | |
| Aplazada | Media (6.5) | 0.22% | — | Crocoblock JettabsAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs jet-tabs allows DOM-Based XSS.This issue affects JetTabs: from n/a through <= 2.2.9.1. | |
| Analizada | Alta (8.8) | 1.9% | — | Letta | 22/7/2025 | 17/6/2026 | Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows remote attackers to execute arbitrary Python code and system commands via crafted payloads to the /v1/tools/run endpoint, bypassing intended sandbox restrictions. | |
| Aplazada | Media (6.5) | 0.23% | — | Crocoblock JettabsAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs jet-tabs allows Stored XSS.This issue affects JetTabs: from n/a through <= 2.2.9. | |
| Aplazada | Baja (2) | 0.34% | — | LettaAI | 16/6/2025 | 17/6/2026 | A vulnerability classified as critical has been found in letta-ai letta up to 0.4.1. Affected is the function function_message of the file letta/letta/interface.py. The manipulation of the argument function_name/function_args leads to improper neutralization of directives in dynamically evaluated code. The exploit has… | |
| Aplazada | Media (6.5) | 0.21% | — | Crocoblock JettabsAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs jet-tabs allows DOM-Based XSS.This issue affects JetTabs: from n/a through <= 2.2.7. | |
| Aplazada | Alta (8.8) | 0.96% | — | JettabsAI | 16/8/2024 | 17/6/2026 | The JetTabs for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.3 via the 'switcher_preset' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server,… | |
| Modificada | Crítica (9.8) | 6.0% | — | FreshtomatoSiretta Quartz-gold Firmware | 30/1/2023 | 17/6/2026 | An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 2.1% | — | FreshtomatoSiretta Quartz-gold Firmware | 30/1/2023 | 17/6/2026 | A directory traversal vulnerability exists in the httpd update.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 3.5% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is reachable through the m2m's… | |
| Modificada | Crítica (9.8) | 3.2% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is reachable through the m2m's… | |
| Modificada | Crítica (9.8) | 3.2% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is reachable through the m2m's… | |
| Modificada | Crítica (9.8) | 3.5% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is reachable through the m2m's… | |
| Modificada | Crítica (9.8) | 1.5% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in the m2m DELETE_FILE cmd functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Media (6.5) | 1.9% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | A directory traversal vulnerability exists in the m2m DELETE_FILE cmd functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary file deletion. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 2.7% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer… | |
| Modificada | Alta (7.2) | 2.2% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer… | |
| Modificada | Alta (7.2) | 2.4% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer… |