Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.88% | — | Irontec SngrepAI | 12/9/2026 | 23/9/2026 | sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other header fields to overflow stack buffers and cause crashes or execute… | |
| Aplazada | Media (4.8) | 0.12% | — | UgrepAI | 5/9/2026 | 23/9/2026 | ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files that cause the decompressor to read one byte past the allocated heap buffer, potentially crashing the process. | |
| Aplazada | Baja (1.1) | 0.08% | — | Yoanbernabeu GrepaiAIPostgresqlAI | 8/6/2026 | 23/7/2026 | A vulnerability was determined in yoanbernabeu grepai up to 0.35.0. The affected element is the function PostgresStore.LookupByContentHash of the file indexer/chunker.go of the component Postgres Embedding Cache. Executing a manipulation of the argument content_hash can lead to use of weak hash. The attack needs to be… | |
| Aplazada | Baja (1.3) | 0.16% | — | Yoanbernabeu GrepaiAIQdrantAI | 8/6/2026 | 23/7/2026 | A vulnerability has been found in yoanbernabeu grepai 0.35.0. This issue affects some unknown processing of the file indexer/chunker.go of the component Qdrant Backend. Such manipulation leads to use of weak hash. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is… | |
| Aplazada | Media (5.5) | 2.2% | — | Vetcoders MCP Server SemgrepAI | 30/4/2026 | 17/6/2026 | A vulnerability was detected in VetCoders mcp-server-semgrep 1.0.0. This affects the function analyze_results/filter_results/export_results/compare_results/scan_directory/create_rule of the file src/index.ts of the component MCP Interface. The manipulation of the argument ID results in os command injection. The attack… | |
| Aplazada | Media (4.1) | 0.19% | — | Openai Codex CLIAIRipgrepAI | 25/7/2025 | 17/6/2026 | OpenAI Codex CLI before 0.9.0 auto-approves ripgrep (aka rg) execution even with the --pre or --hostname-bin or --search-zip or -z flag. | |
| Analizada | Alta (8.6) | 2.4% | ⚠ Explotación activa | Reviewdog Action-ast-grepReviewdog Action-composite-templateReviewdog Action-setupReviewdog Action-shellcheck+2 | 19/3/2025 | 17/6/2026 | reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs. Other reviewdog actions that use `reviewdog/action-setup@v1` that would also be… | |
| Analizada | Alta (7.5) | 0.61% | — | Irontec Sngrep | 29/5/2024 | 17/6/2026 | Irontec Sngrep v1.8.1 was discovered to contain a heap buffer overflow via the function rtp_check_packet at /sngrep/src/rtp.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SIP packet. | |
| Analizada | Crítica (9.8) | 1.9% | — | Irontec Sngrep | 10/4/2024 | 17/6/2026 | A stack-buffer overflow vulnerability exists in all versions of sngrep since v1.4.1. The flaw is due to inadequate bounds checking when copying 'Content-Length' and 'Warning' headers into fixed-size buffers in the sip_validate_packet and sip_parse_extra_headers functions within src/sip.c. This vulnerability allows… | |
| Analizada | Crítica (9.8) | 1.8% | — | Irontec Sngrep | 10/4/2024 | 17/6/2026 | A buffer overflow vulnerability exists in all versions of sngrep since v0.4.2, due to improper handling of 'Call-ID' and 'X-Call-ID' SIP headers. The functions sip_get_callid and sip_get_xcallid in sip.c use the strncpy function to copy header contents into fixed-size buffers without checking the data length. This… | |
| Modificada | Alta (7.8) | 0.31% | — | Irontec Sngrep | 23/6/2023 | 17/6/2026 | Sngrep v1.6.0 was discovered to contain a heap buffer overflow via the function capture_ws_check_packet at /src/capture.c. | |
| Modificada | Alta (7.8) | 0.31% | — | Irontec Sngrep | 9/5/2023 | 17/6/2026 | Sngrep v1.6.0 was discovered to contain a heap buffer overflow via the function capture_packet_reasm_ip at /src/capture.c. | |
| Modificada | Alta (7.8) | 0.31% | — | Irontec Sngrep | 9/5/2023 | 17/6/2026 | Sngrep v1.6.0 was discovered to contain a stack buffer overflow via the function packet_set_payload at /src/packet.c. | |
| Modificada | Alta (7.5) | 1.1% | — | Bingrep Project Bingrep | 21/1/2022 | 17/6/2026 | Bingrep v0.8.5 was discovered to contain a memory allocation failure which can cause a Denial of Service (DoS). | |
| Modificada | Crítica (9.8) | 1.9% | — | Ripgrep Project Ripgrep | 11/6/2021 | 17/6/2026 | ripgrep before 13 on Windows allows attackers to trigger execution of arbitrary programs from the current working directory via the -z/--search-zip or --pre flag. | |
| Modificada | Baja (2.1) | 0.49% | — | GNU GrepOpensuse | 12/2/2015 | 17/6/2026 | The bmexec_trans function in kwset.c in grep 2.19 through 2.21 allows local users to cause a denial of service (out-of-bounds heap read and crash) via crafted input when using the -F option. | |
| Modificada | Media (6.8) | 3.1% | — | Beyondgrep ACK | 14/12/2013 | 17/6/2026 | ack 2.00 through 2.11_02 allows remote attackers to execute arbitrary code via a (1) --pager, (2) --regex, or (3) --output option in a .ackrc file in a directory to be searched. | |
| Modificada | Media (4.4) | 1.0% | — | GNU Grep | 3/1/2013 | 16/6/2026 | Multiple integer overflows in GNU Grep before 2.11 might allow context-dependent attackers to execute arbitrary code via vectors involving a long input line that triggers a heap-based buffer overflow. | |
| Modificada | Media (5) | 2.1% | — | Oscar Nierstrasz Htgrep | 14/11/2000 | 16/6/2026 | Htgrep CGI program allows remote attackers to read arbitrary files by specifying the full pathname in the hdr parameter. |