Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 77 respecto a la semana anterior
Críticas / altas1446▲ 303 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
23.396 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (5.8) | — | — | Opentelemetry Instrumentation Cassandra DriverAIOpentelemetry Instrumentation KnexAIOpentelemetry Instrumentation MongooseAIOpentelemetry Instrumentation MysqlAI+4 | 2/10/2026 | 2/10/2026 | OpenTelemetry JavaScript Contrib provides instrumentation libraries for collecting telemetry from JavaScript applications. Prior to versions 0.66.0 of @opentelemetry/instrumentation-cassandra-driver, 0.65.0 of @opentelemetry/instrumentation-knex, 0.67.0 of @opentelemetry/instrumentation-mongoose,… | |
| Recibida | Alta (8.7) | — | — | Codeart Google MP3 Audio PlayerAI | 2/10/2026 | 2/10/2026 | CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to retrieve sensitive files by supplying a path-traversal payload in the file parameter of direct_download.php. Attackers can request… | |
| En análisis | Sin puntuar | — | — | Google ChromeAI | 2/10/2026 | 2/10/2026 | Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| En análisis | Sin puntuar | — | — | Google ChromeAI | 2/10/2026 | 2/10/2026 | Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| En análisis | Sin puntuar | — | — | Google ChromeAI | 2/10/2026 | 2/10/2026 | Integer overflow in Skia in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | |
| En análisis | Crítica (9.6) | — | — | Google ChromeAI | 2/10/2026 | 2/10/2026 | Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | |
| En análisis | Sin puntuar | — | — | Google ChromeAI | 2/10/2026 | 2/10/2026 | Information leak in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | |
| Pendiente de análisis | Sin puntuar | — | — | Google ChromeAI | 2/10/2026 | 2/10/2026 | Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| En análisis | Alta (8.8) | — | — | Google ChromeAI | 2/10/2026 | 2/10/2026 | Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Pendiente de análisis | Sin puntuar | — | — | Google ChromeAI | 2/10/2026 | 2/10/2026 | Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| En análisis | Sin puntuar | — | — | Google ChromeAI | 2/10/2026 | 2/10/2026 | Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| En análisis | Alta (8.8) | — | — | Google ChromeAI | 2/10/2026 | 2/10/2026 | Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| En análisis | Sin puntuar | — | — | Google ChromeAI | 2/10/2026 | 2/10/2026 | Integer overflow in Compositing in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | |
| Aplazada | Media (4.7) | — | — | Mehul Gohil Aculect AI CompanionAI | 2/10/2026 | 2/10/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Mehul Gohil Aculect AI Companion aculect-ai-companion allows Phishing.This issue affects Aculect AI Companion: from n/a through 0.8.1. | |
| Aplazada | Media (4.8) | 0.15% | — | GotopAI | 2/10/2026 | 2/10/2026 | cjbassi/gotop is vulnerable to local argument injection via process termination functionality. The process name is passed directly to pkill without sanitization. A local attacker can create a process with a crafted name beginning with -- (e.g. containing a target user's UID). When the user running gotop invokes the… | |
| Aplazada | Sin puntuar | 0.19% | — | Algorithm Ahocorasick XSAI | 30/9/2026 | 30/9/2026 | Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length before the scalar is stringified. The matches, first_match and match_details methods use the T_STD_STRING typemap to translate Perl scalars (SVs) into strings via the std::string constructor, using the SvPV macro to stringify the… | |
| Aplazada | Media (5.3) | 0.29% | — | Bbs-goAI | 30/9/2026 | 30/9/2026 | bbs-go through 4.4.6 contains a permission bypass vulnerability in the AdminMiddleware authorization logic where the read-only dashboard.user.view permission rule matches the /api/admin/user/synccount endpoint before the intended dashboard.user.update rule. Authenticated users with only view permissions can call the… | |
| Aplazada | Alta (7.6) | 0.28% | — | Quanticedgesolutions Category Discount WoocommerceAI | 30/9/2026 | 30/9/2026 | Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions. | |
| Aplazada | Alta (8.8) | 0.36% | — | DesignsetgoAI | 30/9/2026 | 30/9/2026 | Contributor PHP Object Injection in DesignSetGo <= 2.8.0 versions. | |
| Aplazada | Alta (8.8) | 0.38% | — | GO Live Update UrlsAI | 30/9/2026 | 30/9/2026 | Contributor PHP Object Injection in Go Live Update Urls <= 7.0.8 versions. | |
| Aplazada | Alta (7.2) | 0.37% | — | Wpfactory Cost OF Goods FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions. | |
| Aplazada | Crítica (9.2) | 0.38% | — | SogoAI | 30/9/2026 | 30/9/2026 | sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account. This issue was… | |
| Aplazada | Crítica (9.3) | 0.41% | — | Sogo YHNAI | 30/9/2026 | 30/9/2026 | sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user" to be treated as sent by a verified user without performing password validation. Since Nginx does not strip this header, any client can supply it arbitrarily and gain access as any user, including a privileged… | |
| Aplazada | Alta (7.1) | 0.18% | — | Supsystic Easy Google MapsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions. | |
| Aplazada | Alta (7.1) | 0.32% | — | Gosub EngineAI | 30/9/2026 | 30/9/2026 | Uncontrolled recursion in the Gosub browser engine (gosub-engine) through 0.1.0 and main before commit 46868b3 allows a remote attacker to cause a Denial of Service (stack exhaustion and application crash) via an SVG document containing an excessive number of deeply nested elements. Because the engine does not limit… |