Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2636▼ 212 respecto a la semana anterior
Críticas / altas1386▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.24% | — | PodgrabAI | 1/10/2026 | 2/10/2026 | Podgrab contains a missing authentication vulnerability in which the /ws WebSocket route is registered on the root gin engine instead of the BasicAuth-protected router group, allowing unauthenticated network clients to connect even when PASSWORD is configured. Attackers can join the allConnections set, capture… | |
| Aplazada | Alta (8.7) | 0.27% | — | PodgrabAI | 1/10/2026 | 2/10/2026 | Podgrab contains an unauthenticated denial-of-service vulnerability caused by unsynchronized concurrent access to shared maps (activePlayers and allConnections) in its WebSocket handler, where Wshandler and HandleWebsocketMessages goroutines read and write these maps without a mutex. A remote attacker can open… | |
| Aplazada | Media (6) | 0.21% | — | Aotuman Grab Wechat ArticlesAI | 18/8/2026 | 20/8/2026 | Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Handl UTM GrabberAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in HandL UTM Grabber <= 2.9.2 versions. | |
| Aplazada | Alta (8.6) | 0.16% | — | AudiograbberAI | 23/5/2026 | 23/7/2026 | Audiograbber 1.83 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting structured exception handling mechanisms. Attackers can craft malicious input in the Interpret or Album fields that triggers a buffer overflow, overwriting SEH pointers and executing injected… | |
| Aplazada | Alta (8.4) | 0.17% | — | Youtube Video Grabber Youtube DownloaderAI | 15/1/2026 | 17/6/2026 | YouTube Video Grabber, now referred to as YouTube Downloader, 1.9.9.1 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting the Structured Exception Handler. Attackers can craft a malicious payload of 712 bytes with SEH manipulation to trigger a bind shell connection… | |
| Analizada | Media (6.1) | 0.22% | — | Grabaperch Perch | 7/1/2026 | 17/6/2026 | A stored Cross-Site Scripting (XSS) vulnerability exists in Perch CMS version 3.2. An authenticated attacker with administrative privileges can inject malicious JavaScript code into the “Help button url” setting within the admin panel. The injected payload is stored and executed when any authenticated user clicks the… | |
| Aplazada | Media (5.4) | 0.20% | — | Merkulove UngrabberAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in merkulove UnGrabber ungrabber allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UnGrabber: from n/a through <= 3.1.3. | |
| Analizada | Media (5.1) | 0.24% | — | Grabaperch Perch | 15/12/2025 | 17/6/2026 | Perch CMS 3.2 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can craft SVG files with script tags that execute when the file is viewed, potentially stealing user session information or performing client-side attacks. | |
| Analizada | Alta (8.6) | 0.93% | — | Grabaperch Perch | 15/12/2025 | 17/6/2026 | Perch CMS 3.2 contains a remote code execution vulnerability that allows authenticated administrators to upload arbitrary PHP files through the assets management interface. Attackers can upload a malicious .phar file with embedded system command execution capabilities to execute arbitrary commands on the server. | |
| Aplazada | Alta (7.1) | 0.17% | — | Handl UTM Grabber TrackerAI | 10/12/2025 | 25/9/2026 | The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Aplazada | Alta (7.1) | 0.17% | — | Handl UTM Grabber TrackerAI | 10/12/2025 | 25/9/2026 | The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Media (6.3) | 0.11% | — | Yt-grabber-tuiAI | 17/10/2025 | 17/6/2026 | yt-grabber-tui is a C++ terminal user interface application for downloading YouTube content. yt-grabber-tui version 1.0 contains a Time-of-Check to Time-of-Use (TOCTOU) race condition (CWE-367) in the creation of the default configuration file config.json. In version 1.0, load_json_settings in Settings.hpp checks for… | |
| Aplazada | Alta (7.8) | 0.18% | — | YT Grabber TUIAIYt-dlp YT DLPAI | 13/10/2025 | 17/6/2026 | yt-grabber-tui is a terminal user interface application for downloading videos. In versions before 1.0-rc, the application allows users to configure the path to the yt-dlp executable via the path_to_yt_dlp configuration setting. An attacker with write access to the configuration file or the filesystem location of the… | |
| Aplazada | Alta (7.5) | 1.1% | — | Activepdf WebgrabberAI | 30/8/2025 | 16/6/2026 | activePDF WebGrabber version 3.8.2.0 contains a stack-based buffer overflow vulnerability in the GetStatus() method of the APWebGrb.ocx ActiveX control. By passing an overly long string to this method, a remote attacker can execute arbitrary code in the context of the vulnerable process. Although the control is not… | |
| Aplazada | Alta (7.1) | 0.22% | — | Andreyk Remote Images GrabberAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andreyk Remote Images Grabber remote-images-grabber allows Reflected XSS.This issue affects Remote Images Grabber: from n/a through <= 0.6. | |
| Aplazada | Media (4.3) | 0.17% | — | Neobie Grab & SaveAI | 12/6/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Lim Kai Yang Grab & Save.This issue affects Grab & Save: from n/a through 1.0.4. | |
| Analizada | Alta (7.8) | 0.13% | — | Dell Grab | 26/3/2024 | 17/6/2026 | Dell Grab for Windows, versions up to and including 5.0.4, contain Weak Application Folder Permissions vulnerability. A local authenticated attacker could potentially exploit this vulnerability, leading to privilege escalation, unauthorized access to application data, unauthorized modification of application data and… | |
| Analizada | Media (5.5) | 0.16% | — | Dell Grab | 26/3/2024 | 17/6/2026 | Dell Grab for Windows, versions 5.0.4 and below, contains a cleartext storage of sensitive information vulnerability in its appsync module. An authenticated local attacker could potentially exploit this vulnerability, leading to information disclosure that could be used to access the appsync application with elevated… | |
| Analizada | Media (5.5) | 0.16% | — | Dell Grab | 26/3/2024 | 17/6/2026 | Dell Grab for Windows, versions 5.0.4 and below, contains an improper file permissions vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading to the information disclosure of certain system information. | |
| Modificada | Media (6.1) | 0.43% | — | Neobie Grab & Save | 30/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lim Kai Yang Grab & Save allows Reflected XSS.This issue affects Grab & Save: from n/a through 1.0.4. | |
| Modificada | Media (5.5) | 0.86% | — | Shemes Grabit | 28/3/2022 | 16/6/2026 | A vulnerability, which was classified as problematic, was found in Shemes GrabIt up to 1.7.2 Beta 4. This affects the component NZB Date Parser. The manipulation of the argument date with the input 1000000000000000 as part of a NZB File leads to a denial of service. It is possible to initiate the attack remotely. The… | |
| Modificada | Media (4.8) | 0.95% | — | Cybercraftit Content-grabber | 10/10/2019 | 17/6/2026 | The content-grabber plugin 1.0 for WordPress has XSS via obj_field_name or obj_field_id. | |
| Modificada | Alta (8.8) | 0.80% | — | Haktansuren Handl UTM Grabber | 29/8/2019 | 17/6/2026 | The handl-utm-grabber plugin before 2.6.5 for WordPress has CSRF via add_option and update_option. | |
| Modificada | Media (4.8) | 0.59% | — | Grabaperch Perch | 28/10/2017 | 17/6/2026 | Perch Content Management System 3.0.3 allows unrestricted file upload (with resultant XSS) via the Asset Title field in conjunction with the Select File field. This is exploitable with a Limited Admin account. |