Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
25 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.65% | — | Forget-c Jellyfish AI Short Drama StudioAITiangolo FastapiAI | 18/9/2026 | 22/9/2026 | A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2. This affects an unknown function of the file backend/app/dependencies.py of the component FastAPI. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. The… | |
| Aplazada | Alta (8.8) | 1.1% | — | MarkerAITiangolo FastapiAI | 4/9/2026 | 23/9/2026 | marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitize the file.filename parameter. Unauthenticated attackers can supply filenames containing directory traversal sequences to write arbitrary files to any location or delete existing files on the system. | |
| Aplazada | Media (5.4) | 0.45% | — | Starlette AdminAITiangolo FastapiAIEncode StarletteAI | 26/8/2026 | 9/9/2026 | Starlette-Admin is a fast, beautiful and extensible administrative interface framework for FastAPI and Starlette applications. Prior to 0.16.1, the list API does not validate user-supplied order_by and structured where field names against the configured sortable_fields and searchable_fields allowlists. An… | |
| Aplazada | Alta (8.1) | 0.47% | — | Uxper GoloAI | 20/8/2026 | 20/8/2026 | Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions. | |
| Aplazada | Alta (7.5) | 0.51% | — | Uxper Golo FrameworkAI | 13/7/2026 | 13/7/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Golo Framework golo-framework allows PHP Local File Inclusion.This issue affects Golo Framework: from n/a through <= 1.7.3. | |
| Aplazada | Alta (8.7) | 0.81% | — | Hermes AgentAITiangolo FastapiAI | 17/6/2026 | 18/6/2026 | Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation. FastAPI HTTP middleware does not execute for WebSocket upgrade requests on /api/pty, /api/ws, /api/pub, and /api/events endpoints, enabling attackers to exploit… | |
| Aplazada | Media (5.3) | 0.60% | — | Zauberzeug NiceguiAITiangolo FastapiAIEncode StarletteAIEncode UvicornAI | 2/6/2026 | 22/7/2026 | NiceGUI is a Python-based UI framework. Prior to version 3.12.0, two FastAPI routes that serve per-component static assets in NiceGUI accept a sub-path parameter that may resolve to a directory rather than a file. Requests that resolve to a directory raise an unhandled RuntimeError inside Starlette's FileResponse,… | |
| Aplazada | Baja (2.1) | 0.19% | — | Vanna-ai VannaAITiangolo FastapiAIPalletsprojects FlaskAI | 2/4/2026 | 17/6/2026 | A flaw has been found in vanna-ai vanna up to 2.0.2. Affected by this issue is some unknown functionality of the component FastAPI/Flask Server. Executing a manipulation can lead to permissive cross-domain policy with untrusted domains. The attack can be launched remotely. The exploit has been published and may be… | |
| Aplazada | Crítica (9.8) | 0.48% | — | Uxper GoloAI | 25/3/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in uxper Golo golo allows Privilege Escalation.This issue affects Golo: from n/a through <= 1.7.0. | |
| Aplazada | Alta (7.1) | 0.18% | — | Uxper GoloAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Golo golo allows Reflected XSS.This issue affects Golo: from n/a through < 1.7.5. | |
| Aplazada | Baja (2.1) | 0.35% | — | Dbgpt Db-gptAITiangolo FastapiAI | 20/3/2026 | 17/6/2026 | A vulnerability has been found in eosphoros-ai DB-GPT up to 0.7.5. This issue affects the function module_plugin.refresh_plugins of the file packages/dbgpt-serve/src/dbgpt_serve/agent/hub/controller.py of the component FastAPI Endpoint. Such manipulation leads to unrestricted upload. It is possible to launch the… | |
| Aplazada | Alta (7.5) | 0.45% | — | Uxper GoloAIPHPAI | 22/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Golo golo allows PHP Local File Inclusion.This issue affects Golo: from n/a through < 1.7.5. | |
| Aplazada | Media (5.3) | 0.24% | — | Uxper GoloAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in uxper Golo golo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Golo: from n/a through < 1.7.5. | |
| Aplazada | Crítica (9.8) | 0.42% | — | Uxper GoloAI | 28/8/2025 | 25/9/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in uxper Golo golo allows Authentication Abuse.This issue affects Golo: from n/a through <= 1.7.0. | |
| Aplazada | Alta (7.1) | 0.18% | — | Uxper GoloAI | 28/8/2025 | 25/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Golo golo allows Reflected XSS.This issue affects Golo: from n/a through <= 1.7.1. | |
| Aplazada | Alta (7.6) | 0.24% | — | CadwynAITiangolo FastapiAI | 21/7/2025 | 17/6/2026 | Cadwyn creates production-ready community-driven modern Stripe-like API versioning in FastAPI. In versions before 5.4.3, the version parameter of the "/docs" endpoint is vulnerable to a Reflected XSS (Cross-Site Scripting) attack. This XSS would notably allow an attacker to execute JavaScript code on a user's session… | |
| Aplazada | Alta (8.8) | 0.28% | — | VisionatrixAIComfyuiAITiangolo FastapiAI | 23/6/2025 | 17/6/2026 | Visionatrix is an AI Media processing tool using ComfyUI. In versions 1.5.0 to before 2.5.1, the /docs/flows endpoint is vulnerable to a Reflected XSS (Cross-Site Scripting) attack allowing full takeover of the application and exfiltration of secrets stored in the application. The implementation uses the… | |
| Aplazada | Crítica (9.8) | 0.50% | — | Golo City Travel GuideAI | 3/6/2025 | 17/6/2026 | The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.7.0. This is due to the plugin not properly validating a user's identity prior to setting an authorization cookie. This makes it possible for… | |
| Aplazada | Alta (7.5) | 0.70% | — | Danswer-ai DanswerAITiangolo FastapiAIEncode StarletteAI | 20/3/2025 | 17/6/2026 | A vulnerability in danswer-ai/danswer version 0.9.0 allows for denial of service through memory exhaustion. The issue arises from the use of a vulnerable version of the starlette package (<=0.49) via fastapi, which was patched in fastapi version 0.115.3. The vulnerability can be exploited by sending multiple requests… | |
| Analizada | Crítica (9.8) | 0.45% | — | Uxper Golo | 7/3/2025 | 17/6/2026 | The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.6.10. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.7) | 0.65% | — | Encode StarletteAITiangolo FastapiAI | 15/10/2024 | 17/6/2026 | Starlette is an Asynchronous Server Gateway Interface (ASGI) framework/toolkit. Prior to version 0.40.0, Starlette treats `multipart/form-data` parts without a `filename` as text form fields and buffers those in byte strings with no size limit. This allows an attacker to upload arbitrary large form fields and cause… | |
| Modificada | Alta (8.1) | 0.72% | — | Tiangolo FastapiFedoraproject Fedora | 9/6/2021 | 17/6/2026 | FastAPI is a web framework for building APIs with Python 3.6+ based on standard Python type hints. FastAPI versions lower than 0.65.2 that used cookies for authentication in path operations that received JSON payloads sent by browsers were vulnerable to a Cross-Site Request Forgery (CSRF) attack. In versions lower… | |
| Modificada | Crítica (9.8) | 1.5% | — | Uxper Golo | 12/5/2021 | 17/6/2026 | An Arbitrary File Upload vulnerability was discovered in the Golo Laravel theme v 1.1.5. | |
| Modificada | Alta (8.8) | 1.5% | — | Logological General-purpose Preprocessor | 16/9/2018 | 17/6/2026 | GPP through 2.25 will try to use more memory space than is available on the stack, leading to a segmentation fault or possibly unspecified other impact via a crafted file. | |
| Modificada | Media (5.4) | 0.27% | — | Golosinassimpson Golosinas Simpson1 | 21/10/2014 | 17/6/2026 | The Golosinas Simpson1 (aka com.wGolosinasSimpson1) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |