Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2565▼ 302 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.4)0.22%—Gotham Block Extra LightAI14/1/202617/6/2026
The Gotham Block Extra Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,…
AplazadaMedia (6.5)0.36%—Gotham Block Extra LightAI14/1/202617/6/2026
The Gotham Block Extra Light plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.5.0 via the 'ghostban' shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to read the contents of arbitrary files on the server, which can…
AplazadaMedia (6.8)0.23%—Gotham GaiaAI19/12/202517/6/2026
Gotham Gaia application was found to be exposing multiple unauthenticated endpoints.
AplazadaMedia (6.8)0.46%—Gotham GaiaAI12/3/202417/6/2026
One of Gotham Gaia services was found to be vulnerable to a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker to bypass CSP and get a persistent cross site scripting payload on the stack.
ModificadaMedia (6.5)0.55%—Palantir Gotham Blackbird-witchcraftPalantir Gotham Static-assets-servlet29/1/202417/6/2026
Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on the file system.
ModificadaMedia (6.1)0.41%—Palantir Gotham-fe-bundlePalantir Titanium-browser-app-bundle27/9/202317/6/2026
Palantir Gotham was found to be vulnerable to a bug where under certain circumstances, the frontend could have applied an incorrect classification to a newly created property or link.
ModificadaMedia (5.4)0.37%—Palantir Gotham Cerberus12/9/202317/6/2026
The Gotham Cerberus service was found to have a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker with access to Gotham to launch attacks against other users. This vulnerability is resolved in Cerberus 100.230704.0-27-g031dd58 .
ModificadaMedia (6.8)0.26%—Palantir Gotham Chat IRC16/2/202317/6/2026
Improper Validation of Certificate with Host Mismatch vulnerability in Gotham Chat IRC helper of Palantir Gotham allows A malicious attacker in a privileged network position could abuse this to perform a man-in-the-middle attack. A successful man-in-the-middle attack would allow them to intercept, read, or modify…
ModificadaAlta (7.5)0.62%—Palantir Gotham16/2/202317/6/2026
Palantir Gotham versions prior to 3.22.11.2 included an unauthenticated endpoint that would load portions of maliciously crafted zip files to memory. An attacker could repeatedly upload a malicious zip file, which would allow them to exhaust memory resources on the dispatch server.
ModificadaAlta (7.5)0.62%—Palantir Gotham16/2/202317/6/2026
Palantir Gotham versions prior to 3.22.11.2 included an unauthenticated endpoint that would have allowed an attacker to exhaust the memory of the Gotham dispatch service.
ModificadaMedia (5.3)0.43%—Palantir Gotham16/2/202317/6/2026
Palantir Gotham included an unauthenticated endpoint that listed all active usernames on the stack with an active session. The affected services have been patched and automatically deployed to all Apollo-managed Gotham instances. It is highly recommended that customers upgrade all affected services to the latest…