Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2857▼ 164 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
78 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.37% | — | Halo-dev HaloAI | 24/9/2026 | 24/9/2026 | A security vulnerability has been detected in halo-dev Halo up to 2.25.4/2.26.1. Affected is an unknown function of the file application/src/main/java/run/halo/app/content/comment/ReplyNotificationSubscriptionHelper.java of the component SpEL Handler. Such manipulation leads to improper neutralization. The attack may… | |
| Aplazada | Media (5.3) | 0.32% | — | HaloAI | 15/9/2026 | 23/9/2026 | Halo through 2.26.1 contains an open redirect vulnerability in the anonymous thumbnail endpoint that fails to validate the uri query parameter. Attackers can craft malicious links on the trusted Halo domain that redirect visitors to arbitrary external sites, enabling phishing attacks and abuse of redirect-based trust… | |
| Aplazada | Media (4.6) | 0.24% | — | HaloAI | 8/9/2026 | 14/9/2026 | In Halo <= 2.25.4, the plugin management feature allows users to install/update malicious plugins, which could let attackers execute any command with Halo process permissions. | |
| Aplazada | Crítica (9.3) | 0.30% | — | Halo CMSAI | 18/8/2026 | 31/8/2026 | Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the CorsConfigurer.java and the CsrfConfigurer.java components. This allows a remote attacker to execute arbitrary code. | |
| Aplazada | Alta (8.8) | 0.94% | — | HaloAISpringframeworkAI | 18/8/2026 | 31/8/2026 | An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migration.impl.MigrationServiceImpl.restoreWorkdir(), and org.springframework.util.FileSystemUtils.copyRecursively() components | |
| Aplazada | Crítica (9.8) | 0.93% | — | HaloAI | 17/8/2026 | 9/9/2026 | An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginApplicationContextFactory components | |
| Aplazada | Baja (2) | 0.49% | — | Halo-dev HaloAI | 18/7/2026 | 20/7/2026 | A vulnerability was detected in halo-dev halo up to 2.24.2. Affected by this vulnerability is the function Download of the file MigrationEndpoint.java of the component Files Backup Endpoint. Performing a manipulation results in path traversal. The attack is possible to be carried out remotely. The exploit is now… | |
| Aplazada | Crítica (9.3) | 0.32% | — | ZebradAIHalo2 GadgetsAIZcash PrimitivesAIOrchardproject OrchardAI+1 | 17/7/2026 | 17/7/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0, the variable-base scalar multiplication gadget in halo2_gadgets/src/ecc/chip/mul/incomplete.rs used assign_advice() for the base point without a copy constraint tying… | |
| Aplazada | Baja (2) | 0.54% | — | Halo-dev HaloAI | 10/7/2026 | 10/7/2026 | A vulnerability was identified in halo-dev halo up to 2.24.2. This affects the function ThemeUtils.unzipThemeTo of the file ThemeUtils.java of the component Theme Installation. Such manipulation of the argument metadata.name leads to path traversal. The attack may be launched remotely. The exploit is publicly… | |
| Aplazada | Media (5.5) | 0.51% | — | HaloAI | 25/6/2026 | 25/6/2026 | Halo is an open source website building tool. Prior to 2.24.3, a path traversal vulnerability in the backup download endpoint allows authenticated administrators to read arbitrary files from the server filesystem. The backup download endpoint (GET… | |
| Pendiente de análisis | Crítica (9.8) | 0.97% | — | Morsemicro HalowlinkAI | 5/6/2026 | 23/7/2026 | A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or potentially achieve Remote Code Execution via a crafted 802.11ah beacon… | |
| Pendiente de análisis | Crítica (9.8) | 0.97% | — | Morsemicro HalowlinkAI | 5/6/2026 | 23/7/2026 | A heap-based buffer overflow vulnerability in the dot11ah.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or potentially achieve Remote Code Execution via a crafted 802.11ah… | |
| Analizada | Media (6.8) | 0.19% | — | Morsemicro Halowlink 2 Firmware | 4/6/2026 | 22/7/2026 | An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.12 allows an unauthenticated attacker within radio range to disclose a small amount of kernel heap memory or cause a Denial of Service (kernel oops/panic) via a crafted 802.11ah… | |
| Aplazada | Media (4.3) | 0.28% | — | HaloAI | 30/4/2026 | 17/6/2026 | A Server-Side Request Forgery (SSRF) in the /plugins/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request. | |
| Aplazada | Media (6.5) | 0.35% | — | HaloAI | 30/4/2026 | 17/6/2026 | A Server-Side Request Forgery (SSRF) in the /themes/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request. | |
| Aplazada | Media (4.3) | 0.28% | — | HaloAI | 30/4/2026 | 17/6/2026 | A Server-Side Request Forgery (SSRF) in the /themes/-/install-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request. | |
| Aplazada | Media (5.4) | 0.24% | — | HaloAI | 30/4/2026 | 17/6/2026 | A Server-Side Request Forgery (SSRF) in the /plugins/-/install-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request. | |
| Analizada | Alta (7.5) | 0.47% | — | Halo | 12/2/2026 | 17/6/2026 | An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment submission endpoint | |
| Modificada | Baja (1.3) | 0.25% | — | Halo | 28/12/2025 | 17/6/2026 | A vulnerability was determined in Halo up to 2.21.10. This issue affects some unknown processing of the file /actuator of the component Configuration Handler. Executing a manipulation can lead to information disclosure. The attack may be performed from remote. This attack is characterized by high complexity. The… | |
| Aplazada | Baja (2.1) | 0.26% | — | Samunatsu HalobotAI | 15/12/2025 | 17/6/2026 | A vulnerability was determined in SamuNatsu HaloBot up to 026b01d4a896d93eaaf9d5163a287dc9f267515b. Affected is the function html_renderer of the file plugins/html_renderer/index.js of the component Inter-plugin API. Executing manipulation of the argument action can lead to dynamically-managed code resources. The… | |
| Analizada | Baja (2.1) | 0.24% | — | Fit2cloud Halo | 6/12/2025 | 17/6/2026 | A vulnerability has been found in fit2cloud Halo 2.21.10. Impacted is an unknown function. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond… | |
| Aplazada | Media (5.8) | 0.29% | — | Halo CMSAI | 29/10/2025 | 5/7/2026 | An unauthenticated server-side request forgery (SSRF) vulnerability in the Thumbnail via-uri endpoint of Halo CMS 2.21 allows a remote attacker to cause the server to issue HTTP requests to attacker-controlled URLs, including internal addresses. The endpoint performs a server-side GET to a user-supplied URI without… | |
| Analizada | Media (6.1) | 0.24% | — | Halo | 9/9/2025 | 17/6/2026 | Halo v2.20.17 and before is vulnerable to Cross Site Scripting (XSS) in /halo_host/archives/{name}. | |
| Analizada | Media (6.1) | 0.26% | — | Halo | 9/9/2025 | 17/6/2026 | Halo prior to 2.20.13 allows bypassing file type detection and uploading malicious files such as .exe and .html files. Specifically, .html files can trigger stored XSS vulnerabilities. This vulnerability is fixed in 2.20.13 | |
| Analizada | Crítica (9.1) | 0.37% | — | Halo | 9/9/2025 | 17/6/2026 | halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/attachments/-/upload-from-url. |