Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2535▼ 358 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.4) | 0.11% | — | Google Fuse-archiveAI | 28/9/2026 | 29/9/2026 | In Google fuse-archive versions prior to 1.24, an attacker who can prepend a directory to PATH or write a malicious binary to an attacker-controlled or writable directory appearing in PATH can hijack the execution pathway. This allows the attacker to execute arbitrary local code under the security context of the user… | |
| Pendiente de análisis | Baja (3.8) | 0.17% | — | Papercut HiveAIRicohAI | 24/9/2026 | 24/9/2026 | An input validation vulnerability exists in the PaperCut Hive embedded application for Ricoh devices. The application fails to properly sanitize input received during the NFC card reading process before passing it to the application's web view interface. A local attacker with physical access to the device and a… | |
| Aplazada | Alta (7.1) | 0.41% | — | Zenhive MPPAI | 22/9/2026 | 22/9/2026 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows a client holding an open payment channel to obtain paid resources without being charged. MPP.Session.Actions.accept_voucher/3 in lib/mpp/session/actions.ex treats a voucher whose cumulativeAmount equals the channel's already-accepted cumulative… | |
| Aplazada | Alta (8.2) | 0.57% | — | Zenhive MPPAI | 22/9/2026 | 22/9/2026 | Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscription activation credential to charge the payer repeatedly. The payer signs a Tempo KeyAuthorization over the chain id, key type, key id, expiry, limits and scopes only, with nothing tying it to the challenge that… | |
| Aplazada | Alta (8.8) | 0.37% | — | Toolhive CLIAIToolhive StudioAI | 18/9/2026 | 24/9/2026 | ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0, locally run MCP server containers use the default network permission profile without network isolation, permitting access to host.docker.internal while… | |
| Aplazada | Media (6.5) | 0.22% | — | Wp-property-hive PropertyhiveAI | 17/9/2026 | 17/9/2026 | Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions. | |
| Pendiente de análisis | Media (6.3) | 0.52% | — | Zenhive MPPAI | 16/9/2026 | 16/9/2026 | Use of Cache Containing Sensitive Information in ZenHive mpp allows a shared HTTP cache to store a paid response and serve it to clients that never paid. MPP.Plug.verify_credential in lib/mpp/plug.ex sets payment-receipt and cache-control: private on the connection before the wrapped application runs, and registers no… | |
| Pendiente de análisis | Media (6.3) | 0.52% | — | Zenhive MPPAI | 16/9/2026 | 16/9/2026 | Improper Validation of Unsafe Equivalence in Input in ZenHive mpp allows an unauthenticated remote client to pass the Tempo duplicate-submission gate twice with one signed transaction. MPP.Methods.Tempo reserves the pre-broadcast dedup slot on the caller-supplied hex in reserve_hash_atomic/2, keyed through store_key/1… | |
| Aplazada | Media (4.7) | 0.43% | — | ToolhiveAI | 15/9/2026 | 30/9/2026 | ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior to 0.31.0, remote.Handler.Authenticate in pkg/auth/remote/handler.go invokes discovery.DetectAuthenticationFromServer in pkg/auth/discovery/discovery.go, whose host-side HTTP clients trust… | |
| Aplazada | Baja (2.9) | 0.33% | — | ToolhiveAI | 15/9/2026 | 30/9/2026 | ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior to 0.29.1, networking.IsPrivateIP in pkg/networking/utilities.go omits the IPv6 NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48, so NAT64 addresses embedding private, loopback, or link-local IPv4… | |
| Pendiente de análisis | Baja (2.5) | 0.18% | — | LibarchiveAILibarchive BsdtarAI | 13/9/2026 | 22/9/2026 | libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-92wx-p669-8gr9. This relates to bsdtar. Exploitation envisions a marginally plausible scenario in which original-filename… | |
| Aplazada | Alta (8.3) | 0.52% | — | Zenhive MPPAI | 6/9/2026 | 8/9/2026 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for provisioning an access key on the client's own account. When the server sponsors Tempo payments,… | |
| Aplazada | Alta (8.3) | 0.52% | — | Zenhive MPPAI | 6/9/2026 | 8/9/2026 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for EIP-7702 account delegations of the client's choosing. When the server sponsors Tempo payments,… | |
| Aplazada | Alta (7.5) | 0.34% | — | Hivepress AuthenticationAI | 6/9/2026 | 8/9/2026 | The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_user function's Facebook authenticator resolving third-party identity by forwarding the attacker-supplied access_token to… | |
| Analizada | Crítica (9.1) | 1.0% | — | Apache Hive | 25/8/2026 | 28/9/2026 | Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authenticated remote attacker with CREATE TABLE privilege to cause the Hive server to fetch an attacker-controlled URL when resolving the avro.schema.url table property on an Avro table that is subsequently… | |
| Analizada | Alta (7.4) | 0.34% | — | Apache Hive | 25/8/2026 | 28/9/2026 | An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive 4.0.0 through 4.2.0 (and later unreleased branches) on deployments using HTTP transport with hive.server2.authentication=SAML allows an unauthenticated network attacker to authenticate as an arbitrary Hive user and… | |
| Analizada | Crítica (9.8) | 0.89% | — | Apache Hive | 25/8/2026 | 28/9/2026 | SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows authenticated users with access to Hive Metastore APIs to read, modify, or affect unintended partition metadata (including statistics updates, truncation targets, and file-metadata cache operations)… | |
| Aplazada | Baja (3.7) | 0.17% | — | HCL HiveAI | 25/8/2026 | 28/9/2026 | HCL Hive is affected by an information disclosure vulnerability, which could lead to an attacker gathering sensitive information about the host environment. | |
| Aplazada | Media (5.4) | 0.14% | — | HCL HiveAI | 25/8/2026 | 28/9/2026 | HCL Hive is affected by multiple infrastructure and network configuration vulnerabilities, which could lead to unauthorized lateral movement, container breakout, and sensitive data exposure within internal communications. | |
| Aplazada | Media (4.2) | 0.14% | — | HCL HiveAI | 25/8/2026 | 28/9/2026 | HCL Hive is affected by weak software supply chain governance, which could lead to the inclusion of vulnerable, unmaintained, or malicious third-party dependencies within the application environment. | |
| Aplazada | Alta (7.5) | 0.27% | — | HCL HiveAI | 24/8/2026 | 28/8/2026 | HCL Hive is affected by a use of vulnerable third-party components which could allow an attacker unauthorized access or compromise of the system by exploiting publicly documented security flaws. | |
| Aplazada | Media (5.3) | 0.21% | — | HCL HiveAI | 24/8/2026 | 28/8/2026 | HCL Hive is affected by a missing rate limit which could allow an attacker unauthorized access via brute-force or credential stuffing attacks, or cause a denial of service. | |
| Aplazada | Alta (7.5) | 0.23% | — | HCL HiveAI | 24/8/2026 | 29/9/2026 | HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, container breakout, and interception of sensitive internal communications. | |
| Aplazada | Alta (7.4) | 0.16% | — | HCL HiveAI | 24/8/2026 | 28/8/2026 | HCL Hive is affected by a cryptographic primitive with a risky implementation which could allow an attacker unauthorized lateral compromise or widespread credential leakage if a single internal component is breached. | |
| Aplazada | Media (4.3) | 0.22% | — | HCL HiveAI | 24/8/2026 | 28/8/2026 | HCL Hive is affected by an information exposure vulnerability where Swagger documentation was found exposed publicly. Although no sensitive information (e.g., credentials, PII) was discovered, exposing API documentation to unauthenticated users can increase the overall attack surface. |