Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
149 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.4) | 0.11% | — | Google Fuse-archiveAI | 28/9/2026 | 29/9/2026 | In Google fuse-archive versions prior to 1.24, an attacker who can prepend a directory to PATH or write a malicious binary to an attacker-controlled or writable directory appearing in PATH can hijack the execution pathway. This allows the attacker to execute arbitrary local code under the security context of the user… | |
| Aplazada | Alta (8.8) | 0.24% | — | Infusedwoo PROAI | 25/8/2026 | 27/8/2026 | The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 5.1.17. This is due to a missing capability check in the `ajax_iwar_preview_email()` function, which uses `is_admin()` as its only authorization check and allows low-privilege users… | |
| Analizada | Alta (7.5) | 0.81% | — | Apache Jena Fuseki | 3/8/2026 | 7/8/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. This issue affects Apache Jena Fuseki: through 6.1.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue. | |
| Aplazada | Media (4.3) | 0.20% | — | FusewpAI | 30/7/2026 | 31/7/2026 | The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.24.2. This is due to missing nonce verification on the toggle_sync_status() function. This makes it possible for unauthenticated attackers to toggle the status of sync rules (enable/disable) via a… | |
| Pendiente de análisis | Baja (2) | 0.14% | — | Fuse-overlayfsAI | 29/7/2026 | 10/9/2026 | fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. Prior to 1.17, the release-1.x C branch preserves SUID and SGID mode bits in main.c during open(O_TRUNC) and truncate handling on a copied-up file, allowing a low-privileged process to leave the upper-layer file with mode 4777. This… | |
| Aplazada | Media (5.3) | 0.40% | — | Huggingface DiffusersAI | 23/7/2026 | 23/7/2026 | Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_files function that allows attackers to read arbitrary files by supplying malicious weight_map values in model index JSON. Attackers can use ../ sequences or absolute paths in weight_map entries to… | |
| Analizada | Alta (7.5) | 0.37% | — | Huggingface Diffusers | 15/7/2026 | 12/8/2026 | Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, Diffusers' DiffusionPipeline.from_pretrained flow can bypass the trust_remote_code guard because download() validates model_index.json and custom pipeline code before later loading from a cached folder that can change, allowing a Hub… | |
| Analizada | Alta (8.1) | 0.65% | — | Vmware Spring FOR Apache KafkaRedhat FuseRedhat Jboss Enterprise Application Platform Expansion Pack | 10/6/2026 | 5/8/2026 | JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Combined with Jackson's default bean deserialization, a producer could supply crafted header values that… | |
| Analizada | Alta (8.8) | 0.70% | — | Huggingface Diffusers | 14/5/2026 | 17/6/2026 | Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, diffusers 0.37.0 allows remote code execution without the trust_remote_code=True safeguard when loading pipelines from Hugging Face Hub repositories. The _resolve_custom_pipeline_and_cls function in pipeline_loading_utils.py performs string… | |
| Modificada | Alta (8.8) | 0.89% | — | Huggingface Diffusers | 14/5/2026 | 28/8/2026 | Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution despite the user passing trust_remote_code=False (or omitting it, which is the default). The vulnerability has three variants, all sharing… | |
| Aplazada | Alta (7.5) | 0.46% | — | Infusedwoo PROAI | 14/5/2026 | 17/6/2026 | The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.1.2 via the popup_submit. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify… | |
| Aplazada | Crítica (9.1) | 0.46% | — | Infusedwoo PROAI | 14/5/2026 | 17/6/2026 | The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete arbitrary posts, pages,… | |
| Aplazada | Crítica (9.8) | 0.70% | — | Infusedwoo PROAI | 14/5/2026 | 17/6/2026 | The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions up to, and including, 5.1.2. This is due to missing nonce verification and capability checks in the iwar_save_recipe() AJAX handler. This makes it possible for unauthenticated attackers to create a… | |
| Aplazada | Alta (8.8) | 0.51% | — | Infusedwoo PROAI | 14/5/2026 | 17/6/2026 | The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.1.2. This is due to the infusedwoo_gdpr_upddata() function missing authorization and capability checks, as well as lacking restrictions on which user meta keys can be updated. This makes it possible… | |
| Analizada | Media (5.3) | 0.32% | — | Langfuse | 8/5/2026 | 17/6/2026 | Langfuse is an open source large language model engineering platform. From version 3.68.0 to before version 3.167.0, there is a role-based-access control flaw in the LLM connection update flow. An authenticated, low-privileged user of role “member” in a project could request the update of an existing LLM connection to… | |
| Modificada | Crítica (9.1) | 0.89% | — | Redhat Build OF Apache Camel - HawtioRedhat Build OF Apache Camel FOR Spring BootRedhat Data GridRedhat Fuse+6 | 27/3/2026 | 21/9/2026 | A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can be exploited by a remote attacker to perform request smuggling.… | |
| Modificada | Crítica (9.1) | 0.89% | — | Redhat Build OF Apache Camel - HawtioRedhat Build OF Apache Camel FOR Spring BootRedhat Data GridRedhat Fuse+6 | 27/3/2026 | 21/9/2026 | A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing… | |
| Modificada | Crítica (9.1) | 0.89% | — | Redhat Build OF Apache Camel - HawtioRedhat Build OF Apache Camel FOR Spring BootRedhat Data GridRedhat Fuse+5 | 27/3/2026 | 21/9/2026 | A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache Traffic Server and Google Cloud Classic Application Load Balancer, potentially leading to… | |
| Aplazada | Media (6.4) | 0.19% | — | Jeremyshapiro FusedeskAI | 21/3/2026 | 17/6/2026 | The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fusedesk_newcase shortcode in all versions up to, and including, 6.8 due to insufficient input sanitization and output escaping on the 'emailtext' attribute. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.5) | 0.17% | — | Libfuse Project Libfuse | 20/3/2026 | 17/6/2026 | libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a NULL pointer dereference and memory leak in fuse_uring_init_queue allows a local user to crash the FUSE daemon or cause resource exhaustion. When numa_alloc_local fails during io_uring queue entry setup, the code… | |
| Modificada | Alta (7.8) | 0.19% | — | Libfuse Project Libfuse | 20/3/2026 | 15/7/2026 | libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a use-after-free vulnerability in the io_uring subsystem of libfuse allows a local attacker to crash FUSE filesystem processes and potentially execute arbitrary code. When io_uring thread creation fails due to… | |
| Analizada | Media (6.4) | 0.21% | — | Redhat Fuse | 13/3/2026 | 17/6/2026 | A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their… | |
| Analizada | Media (6.3) | 0.44% | — | Langfuse | 22/1/2026 | 17/6/2026 | Langfuse is an open source large language model engineering platform. In versions 3.146.0 and below, the /api/public/slack/install endpoint initiates Slack OAuth using a projectId provided by the client without authentication or authorization. The projectId is preserved throughout the OAuth flow, and the callback… | |
| Modificada | Crítica (9.6) | 1.3% | — | Redhat Build OF Apache CamelRedhat Data GridRedhat FuseRedhat Jboss Enterprise Application Platform+4 | 7/1/2026 | 7/9/2026 | A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling… | |
| Aplazada | Alta (7.8) | 0.37% | — | Cogview4AIHuggingface DiffusersAI | 23/12/2025 | 17/6/2026 | Hugging Face Diffusers CogView4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Diffusers. User interaction is required to exploit this vulnerability in that the target must visit a… |