Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
113 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.84% | — | Punchin-emailAICloudflare WorkersAI | 17/9/2026 | 30/9/2026 | punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. Prior to 1.5.0, handleInbound delivers inbound alias mail with message.forward(), which silently drops the added Reply-To header intended to route responses through the relay. When a correspondent… | |
| Aplazada | Crítica (9.8) | 0.68% | — | Fatpipe MpvpnAIFatpipe IpvpnAICloudflare WarpAI | 17/9/2026 | 18/9/2026 | FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based buffer overflow in /usr/sbin/auth_user_pass. An unauthenticated remote attacker with access to the affected management interface can submit a crafted authentication request that reaches an unchecked… | |
| Aplazada | Crítica (9.8) | 1.4% | — | Fatpipe MpvpnAIFatpipe IpvpnAICloudflare WarpAI | 17/9/2026 | 18/9/2026 | FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command injection vulnerability in the xtremed daemon. An unauthenticated remote attacker with access to the affected management interface can submit crafted input to the AuthFormServlet endpoint, causing… | |
| Aplazada | Media (6.5) | 0.31% | — | Simple Captcha With Cloudflare TurnstileAI | 11/9/2026 | 11/9/2026 | The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. | |
| Aplazada | Media (5.6) | 0.25% | — | Simple Cloudflare TurnstileAI | 10/9/2026 | 10/9/2026 | Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions. | |
| Aplazada | Media (6.5) | 0.28% | — | Cloudflare TurnstileAI | 10/9/2026 | 10/9/2026 | Unauthenticated Content Injection in Simple Cloudflare Turnstile <= 1.42.1 versions. | |
| Pendiente de análisis | Alta (8.8) | 0.68% | — | Cloudflare Pages-actionAICloudflare Wrangler-actionAI | 12/8/2026 | 28/8/2026 | Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execution issue in `src/index.ts` reachable from certain GitHub Actions workflow configurations. Successful exploitation may expose workflow secrets such as CLOUDFLARE_API_TOKEN… | |
| Aplazada | Media (5.3) | 0.16% | — | Simple Captcha With Cloudflare TurnstileAI | 7/8/2026 | 26/8/2026 | The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache to the single-use challenge token in its Forminator integration, instead keying it to an attacker-controlled, reusable request value, allowing unauthenticated attackers to solve one challenge and… | |
| Aplazada | Alta (7.5) | 0.49% | — | FlaresolverrAI | 20/7/2026 | 21/7/2026 | FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. This allows a remote attacker to obtain sensitive information | |
| Pendiente de análisis | Alta (7.5) | 0.44% | — | Cloudflare QuicheAI | 14/7/2026 | 14/7/2026 | Summary Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to unbounded queuing of post-handshake client migration events. Impact quiche supports the connection migration features described in Section 9 of RFC 9000, which allows a single QUIC connection to survive changes in the… | |
| Analizada | Alta (7.5) | 0.53% | — | Cloudflare Quiche | 14/7/2026 | 6/8/2026 | Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by means of specially crafted HTTP/3 frames. Impact HTTP/3 defines multiple frame types to support HTTP message exchanges and connection management. Each frame has a length and a payload whose length depends… | |
| Pendiente de análisis | Alta (7.6) | 0.20% | — | Cloudflare Universal SSLAI | 1/7/2026 | 2/7/2026 | Description: To issue and renew TLS certificates on behalf of customers, Cloudflare's Universal SSL feature automatically manages the CAA RRset for the customer's zone. This auto-managed RRset is permissive by design (e.g. 'issue "letsencrypt.org"' without parameters). On Universal SSL zones, Cloudflare's… | |
| Aplazada | Alta (7.7) | 0.74% | — | Cloudflare WarpAI | 24/6/2026 | 25/6/2026 | Warp is an agentic development environment. From 0.2024.03.12.08.02.stable_01 until 0.2026.05.06.15.42.stable_01, Warp contains an OS command injection vulnerability in the WSL URL-opening fallback. When Warp is running under WSL and cannot open a URL through wslview, it falls back to a Windows command processor path.… | |
| Aplazada | Media (4.3) | 0.40% | — | Cloudflare WarpAI | 24/6/2026 | 25/6/2026 | Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp accepted certain state-mutating terminal lifecycle hooks from the PTY stream without verifying that the hooks were emitted by Warp's shell integration for the active session. An attacker who could… | |
| Aplazada | Alta (8.8) | 1.4% | — | Cloudflare WarpAI | 24/6/2026 | 25/6/2026 | Warp is an agentic development environment. From 0.2023.03.21.08.02.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection issue in the legacy SSH background command path. Warp used the remote working directory reported by the session when building helper commands for SSH-backed metadata… | |
| Aplazada | Alta (7.8) | 0.89% | — | Cloudflare WarpAI | 24/6/2026 | 25/6/2026 | Warp is an agentic development environment. From 0.2024.02.20.08.01.stable_01 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection issue in the Linux external editor launcher. Warp expanded freedesktop .desktop Exec templates for affected editor integrations and executed the expanded command through a… | |
| Aplazada | Alta (8.1) | 0.38% | — | Cloudflare WarpAI | 24/6/2026 | 25/6/2026 | Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp allows terminal output to request access to the local system clipboard. A malicious remote host, remote program, or other attacker-controlled terminal output source can trigger clipboard reads or… | |
| Aplazada | Alta (8.6) | 0.22% | — | Cloudflare WarpAI | 24/6/2026 | 25/6/2026 | Warp is an agentic development environment. From 0.2025.10.08.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command execution permission-check bypass in the default unsandboxed CLI agent profile. The CLI profile is non-interactive and relies on a command denylist as a safety boundary for commands… | |
| Aplazada | Alta (8.8) | 0.44% | — | Cloudflare WarpAI | 24/6/2026 | 25/6/2026 | Warp is an agentic development environment. From 0.2025.03.05.08.02.stable_00 until 0.2026.05.06.15.42.stable_01, Warp accepts non-inline `OSC 1337;File` payloads from terminal output and materialize the decoded payload as a local file without an additional confirmation step. This vulnerability is fixed in… | |
| Aplazada | Alta (8) | 1.3% | — | Cloudflare WarpAI | 24/6/2026 | 25/6/2026 | Warp is an agentic development environment. From 0.2025.08.06.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection in the prompt branch selector. A user who can publish a branch to a Git repository opened in Warp can cause a crafted branch name to be interpreted by the victim's shell… | |
| Aplazada | Alta (8.8) | 0.44% | — | Cloudflare WarpAI | 24/6/2026 | 25/6/2026 | Warp is an agentic development environment. From 0.2023.10.24.08.03.stable_00 until 0.2026.05.06.15.42.stable_01, Warp may open executable local files through the operating system default file handler. A malicious Markdown document or project can contain a local-file link that appears as normal rendered content. If a… | |
| Aplazada | Alta (7.8) | 0.25% | — | Cloudflare WarpAI | 24/6/2026 | 25/6/2026 | Warp is an agentic development environment. From 0.2025.04.09.08.11.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command execution policy bypass in Agent code search tools. The affected Grep and FileGlob actions are authorized as read/search operations, but their implementations build shell command… | |
| Aplazada | Media (5.3) | 0.37% | — | Cloudflare WorkerdAICapgo Cap-goAI | 20/6/2026 | 22/6/2026 | Cap-go before 12.128.12 contains a broken cursor pagination vulnerability in the /private/devices endpoint on the Cloudflare/workerd path that allows authenticated attackers to cause duplicate-page loops and make later rows unreachable. Attackers with app.read_devices access can exploit non-advancing cursor filters to… | |
| Pendiente de análisis | Media (5.6) | 0.25% | — | Cloudflare QuicheAI | 19/6/2026 | 22/6/2026 | Cloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The “quiche_connection_id_iter_next” and “quiche_conn_retired_scid_next” functions would return a pointer to a “ConnectionId” to the applications via function arguments, but the owned “ConnectionId” would be… | |
| Aplazada | Alta (8.8) | 1.1% | — | Offload AI Optimize With Cloudflare ImagesAI | 18/6/2026 | 18/6/2026 | The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.10.2 via the 'account-id' parameter parameter. This is due to insufficient privilege enforcement on the cf_images_do_setup AJAX handler, which requires only the… |