Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2769▲ 94 respecto a la semana anterior
Críticas / altas1464▲ 354 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)94▼ 417 respecto a la semana anterior
736 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.25% | — | Tipsandtricks-hq WP Express CheckoutAI | 30/9/2026 | 30/9/2026 | Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions. | |
| Pendiente de análisis | Media (6.3) | 0.16% | — | Expresslogic Netx Secure TLSAI | 29/9/2026 | 29/9/2026 | NetX Secure TLS accepts an empty application-data record without verifying its message authentication code. In `_nx_secure_verify_mac`, a decrypted application record whose length equals the negotiated MAC size is treated as valid and returns success after advancing the receive sequence number. The received MAC is… | |
| Pendiente de análisis | Media (6.9) | 0.25% | — | Expresslogic Netx DUOAI | 29/9/2026 | 29/9/2026 | A TFTP server that answers with a short ERROR packet makes the client read up to 64 bytes past the received datagram. Each receive path checks only that the datagram is at least four bytes long (nxd_tftp_client.c:1229, 1521, 1984). When the opcode is NX_TFTP_CODE_ERROR the message string is copied with a loop whose… | |
| Pendiente de análisis | Media (5.3) | 0.15% | — | Expresslogic Netx DUOAI | 29/9/2026 | 29/9/2026 | A DHCP server, or anyone on the LAN who answers a DISCOVER first, can make the client read about a kilobyte past the end of the received message. The option walk keeps a pointer and an offset in step, and the only bound check uses the offset: ```c /* addons/dhcp/nxd_dhcp_client.c:7538, 7572 */ while (i < length - 1)… | |
| Pendiente de análisis | Alta (8.7) | 0.31% | — | Expresslogic Netx DUOAI | 29/9/2026 | 29/9/2026 | hey, `_nx_snmp_utility_object_id_get` in the NetX Duo SNMP addon does not validate the claimed OID data length against the actual buffer size when the OID uses BER multibyte length encoding, so a remote attacker can send a crafted SNMP packet with a multibyte OID length larger than the available buffer, causing the… | |
| Pendiente de análisis | Alta (7.1) | 0.15% | — | Expresslogic Netx DUOAI | 29/9/2026 | 29/9/2026 | Any host on the LAN can send two mDNS records and make the responder write past the end of its transmit packet. The string table stores each name in a slot rounded up to a multiple of four: ```c /* addons/mdns/nxd_mdns.c:11436, 11443, 11447 */ ... len = *((USHORT*)(p - 2)); /* slot size, not string length */ if ((len… | |
| Aplazada | Media (6.8) | 0.24% | — | Optima Express IDXAI | 27/9/2026 | 28/9/2026 | The Optima Express IDX WordPress plugin before 8.7.6 does not properly neutralise a script value submitted through one of its REST endpoints before storing it and echoing it into the document head when the post is rendered, allowing users with a role as low as author to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Media (5.3) | 0.18% | — | Optima Express IDXAI | 27/9/2026 | 28/9/2026 | The Optima Express IDX WordPress plugin before 8.7.6 does not perform any authorisation check on one of its AJAX actions that is available to logged-out users, allowing unauthenticated attackers to force the creation of a fixed author-role account and to repeatedly rotate its application password on any connected… | |
| Aplazada | Alta (7.3) | 0.35% | — | Optima ExpressAI | 25/9/2026 | 25/9/2026 | The Optima Express IDX plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 8.7.5. This is due to the `provisionBlogCredentials()` function in `iHomefinderAdmin.php` being reachable via the `wp_ajax_nopriv_ihf_clear_cache` AJAX action — through the call chain… | |
| Aplazada | Sin puntuar | 0.15% | — | TinyexprAI | 24/9/2026 | 24/9/2026 | An incorrect buffer size calculation vulnerability exists in tinyexpr commit 4a7456e in new_expr(). For arity-0 expression nodes, including constants, variables, and zero-argument functions, the function allocates less memory than sizeof(te_expr) but treats the returned allocation as a complete te_expr object. This… | |
| Pendiente de análisis | Media (5.3) | 0.53% | — | Expressjs MulterAI | 14/9/2026 | 16/9/2026 | multer is a Node.js middleware for handling multipart/form-data uploads. In versions 2.2.0 through 2.3.0, when a request using disk storage is aborted mid-upload, file writes that complete after multer has already run its abort cleanup are not removed, so each aborted upload can leave an orphaned file on disk. A… | |
| Pendiente de análisis | Alta (7.5) | 0.61% | — | CompressionAINodejs Node.jsAIExpressjs ExpressAI | 11/9/2026 | 16/9/2026 | compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a compressed response is still being sent, the zlib stream created to compress that response is never destroyed, so each aborted compressed response leaks its native zlib memory. A remote… | |
| Analizada | Media (6.9) | 0.15% | — | Google Common Expression Language | 9/9/2026 | 23/9/2026 | A user could provide an expression whose string length is longer than the ParserExpressionSizeLimit() configured on the CEL environment, and a memory allocation would occur proportional to the size of the input before the limit would be checked / enforced. | |
| Aplazada | Media (5.3) | 0.16% | — | Tipsandtricks-hq WP Express CheckoutAI | 9/9/2026 | 9/9/2026 | The WP Express Checkout WordPress plugin before 2.5.0 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying. | |
| Aplazada | Alta (7.7) | 0.20% | — | Asus Control Center Express AgentAI | 8/9/2026 | 28/9/2026 | Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the agent when the host has an active login session. Refer to the ' Security Update for ASUS Control Center Express Agent ' section on the ASUS… | |
| Aplazada | Media (5.3) | 0.16% | — | Tipsandtricks-hq WP Express CheckoutAI | 2/9/2026 | 3/9/2026 | The WP Express Checkout WordPress plugin before 2.4.9 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying. | |
| Aplazada | Baja (3.5) | 0.17% | — | Icegram ExpressAI | 2/9/2026 | 3/9/2026 | The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting it within an HTML attribute, which could allow users with the Administrator role and above to perform Stored Cross-Site Scripting attacks. | |
| Pendiente de análisis | Media (6.3) | 0.42% | — | QSAIExpressAIOpenjsf Body-parserAI | 30/8/2026 | 3/9/2026 | ### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by calling `obj.constructor.isBuffer(obj)` after checking only that the property is truthy, so a value such as `{ constructor:… | |
| Analizada | Alta (7.5) | 0.49% | — | Expressjs Multer | 28/8/2026 | 2/9/2026 | multer is a middleware for handling multipart/form-data in Node.js. A small multipart request with two specially crafted text field names can make multer's field parser synchronously iterate a maximum-length sparse array, blocking the event loop so the process cannot handle other requests. A large numeric array index… | |
| Analizada | Alta (7.5) | 0.49% | — | Expressjs Multer | 28/8/2026 | 2/9/2026 | multer is a middleware for handling multipart/form-data in Node.js. A small multipart request containing two specially crafted text field names can cause an uncaught RangeError (Invalid array length) that terminates the Node.js process. The first field uses a very large numeric array index to allocate a maximum-length… | |
| Analizada | Baja (3.7) | 0.23% | — | Expressjs Multer | 28/8/2026 | 2/9/2026 | multer is a middleware for handling multipart/form-data in Node.js. When an application uses an asynchronous fileFilter together with the fileSize limit, a race condition in multer's file stream handling can allow a file that exceeds the configured size limit to bypass the size-limit rejection. All versions before… | |
| Analizada | Alta (7.5) | 0.35% | — | Expressjs Multer | 28/8/2026 | 2/9/2026 | multer is a middleware for handling multipart/form-data in Node.js. In version 2.2.0, when a disk-backed upload is aborted or truncated before the write stream finishes, multer's disk storage engine removes the visible file but does not close the underlying write file descriptor, leaving a deleted but still open… | |
| Aplazada | Alta (7.5) | 0.35% | — | Stitch ExpressAI | 19/8/2026 | 20/8/2026 | Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions. | |
| Aplazada | Baja (2.7) | 0.30% | — | Expressivequiz Quiz AND Survey MasterAI | 19/8/2026 | 26/8/2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the REST routes that return a quiz's email-notification and results-page configuration, allowing users with contributor-level access and above to read the configuration, including notification recipient… | |
| Aplazada | Media (6.4) | 0.42% | — | Expresstech Quiz Survey MasterAI | 16/8/2026 | 20/8/2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_title' parameter in all versions up to, and including, 11.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… |