Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2693▼ 77 respecto a la semana anterior
Críticas / altas1446▲ 303 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

23.396 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaMedia (5.8)——Opentelemetry Instrumentation Cassandra DriverAIOpentelemetry Instrumentation KnexAIOpentelemetry Instrumentation MongooseAIOpentelemetry Instrumentation MysqlAI+42/10/20262/10/2026
OpenTelemetry JavaScript Contrib provides instrumentation libraries for collecting telemetry from JavaScript applications. Prior to versions 0.66.0 of @opentelemetry/instrumentation-cassandra-driver, 0.65.0 of @opentelemetry/instrumentation-knex, 0.67.0 of @opentelemetry/instrumentation-mongoose,…
RecibidaAlta (8.7)——Codeart Google MP3 Audio PlayerAI2/10/20262/10/2026
CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to retrieve sensitive files by supplying a path-traversal payload in the file parameter of direct_download.php. Attackers can request…
En análisisSin puntuar——Google ChromeAI2/10/20262/10/2026
Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
En análisisSin puntuar——Google ChromeAI2/10/20262/10/2026
Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
En análisisSin puntuar——Google ChromeAI2/10/20262/10/2026
Integer overflow in Skia in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
En análisisCrítica (9.6)——Google ChromeAI2/10/20262/10/2026
Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
En análisisSin puntuar——Google ChromeAI2/10/20262/10/2026
Information leak in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Pendiente de análisisSin puntuar——Google ChromeAI2/10/20262/10/2026
Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
En análisisAlta (8.8)——Google ChromeAI2/10/20262/10/2026
Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Pendiente de análisisSin puntuar——Google ChromeAI2/10/20262/10/2026
Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
En análisisSin puntuar——Google ChromeAI2/10/20262/10/2026
Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
En análisisAlta (8.8)——Google ChromeAI2/10/20262/10/2026
Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
En análisisSin puntuar——Google ChromeAI2/10/20262/10/2026
Integer overflow in Compositing in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
AplazadaMedia (4.7)——Mehul Gohil Aculect AI CompanionAI2/10/20262/10/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Mehul Gohil Aculect AI Companion aculect-ai-companion allows Phishing.This issue affects Aculect AI Companion: from n/a through 0.8.1.
AplazadaMedia (4.8)0.15%—GotopAI2/10/20262/10/2026
cjbassi/gotop is vulnerable to local argument injection via process termination functionality. The process name is passed directly to pkill without sanitization. A local attacker can create a process with a crafted name beginning with -- (e.g. containing a target user's UID). When the user running gotop invokes the…
AplazadaSin puntuar0.19%—Algorithm Ahocorasick XSAI30/9/202630/9/2026
Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length before the scalar is stringified. The matches, first_match and match_details methods use the T_STD_STRING typemap to translate Perl scalars (SVs) into strings via the std::string constructor, using the SvPV macro to stringify the…
AplazadaMedia (5.3)0.29%—Bbs-goAI30/9/202630/9/2026
bbs-go through 4.4.6 contains a permission bypass vulnerability in the AdminMiddleware authorization logic where the read-only dashboard.user.view permission rule matches the /api/admin/user/synccount endpoint before the intended dashboard.user.update rule. Authenticated users with only view permissions can call the…
AplazadaAlta (7.6)0.28%—Quanticedgesolutions Category Discount WoocommerceAI30/9/202630/9/2026
Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions.
AplazadaAlta (8.8)0.36%—DesignsetgoAI30/9/202630/9/2026
Contributor PHP Object Injection in DesignSetGo <= 2.8.0 versions.
AplazadaAlta (8.8)0.38%—GO Live Update UrlsAI30/9/202630/9/2026
Contributor PHP Object Injection in Go Live Update Urls <= 7.0.8 versions.
AplazadaAlta (7.2)0.37%—Wpfactory Cost OF Goods FOR WoocommerceAI30/9/202630/9/2026
Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions.
AplazadaCrítica (9.2)0.38%—SogoAI30/9/202630/9/2026
sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account. This issue was…
AplazadaCrítica (9.3)0.41%—Sogo YHNAI30/9/202630/9/2026
sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user" to be treated as sent by a verified user without performing password validation. Since Nginx does not strip this header, any client can supply it arbitrarily and gain access as any user, including a privileged…
AplazadaAlta (7.1)0.18%—Supsystic Easy Google MapsAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions.
AplazadaAlta (7.1)0.32%—Gosub EngineAI30/9/202630/9/2026
Uncontrolled recursion in the Gosub browser engine (gosub-engine) through 0.1.0 and main before commit 46868b3 allows a remote attacker to cause a Denial of Service (stack exhaustion and application crash) via an SVG document containing an excessive number of deeply nested elements. Because the engine does not limit…