Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2573▼ 368 respecto a la semana anterior
Críticas / altas1324▲ 44 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)97▼ 430 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6) | 0.41% | — | Sysadminsmedia HomeboxAI | 21/9/2026 | 29/9/2026 | HomeBox is a home inventory and organization system. Prior to 0.26.0, the default-on BlockBogonNets and BlockCloudMetadata notifier SSRF protections in backend/internal/sys/validate/notifier_url.go do not inspect IPv4 destinations embedded in the NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48. An authenticated user… | |
| Aplazada | Alta (8.1) | 0.45% | — | Sysadminsmedia HomeboxAI | 21/9/2026 | 23/9/2026 | HomeBox is a home inventory and organization system. Prior to 0.26.0, NotifierRepository.Update in backend/internal/data/repo/repo_notifier.go updates a notifier through UpdateOneID(id) without requiring the record's user ID to match the authenticated user. An authenticated user who supplies another tenant's notifier… | |
| Aplazada | Alta (8.1) | 0.49% | — | Sysadminsmedia HomeboxAI | 21/9/2026 | 23/9/2026 | HomeBox is a home inventory and organization system. Prior to 0.26.0, MaintenanceEntryRepository.Update and MaintenanceEntryRepository.Delete in backend/internal/data/repo/repo_maintenance_entry.go use UpdateOneID(id) and DeleteOneID(id) without verifying that the maintenance entry belongs to the authenticated user's… | |
| Aplazada | Media (5.4) | 0.29% | — | Sysadminsmedia HomeboxAI | 21/9/2026 | 29/9/2026 | HomeBox is a home inventory and organization system. Prior to 0.26.0, POST /v1/groups/members invokes HandleGroupMemberAdd and GroupService.AddMember using a caller-supplied userID without requiring an owner role, an invitation token, target-user consent, or target-user notification. Any authenticated user can force… | |
| Aplazada | Alta (8.1) | 0.49% | — | Sysadminsmedia HomeboxAI | 21/9/2026 | 23/9/2026 | HomeBox is a home inventory and organization system. Prior to 0.26.0, HandleWipeInventory in backend/app/api/handlers/v1/v1_ctrl_actions.go authorizes POST /v1/actions/wipe-inventory through the global ctx.User.IsOwner value instead of the caller's role in the active group, while the active group is selected through… | |
| Analizada | Alta (8.1) | 0.40% | — | Sysadminsmedia Homebox | 17/4/2026 | 17/6/2026 | HomeBox is a home inventory and organization system. Versions prior to 0.25.0 contain a vulnerability where the defaultGroup ID remained permanently assigned to a user after being invited to a group, even after their access to that group was revoked. While the web interface correctly enforced the access revocation and… | |
| Analizada | Alta (7.4) | 0.40% | — | Sysadminsmedia Homebox | 3/3/2026 | 17/6/2026 | HomeBox is a home inventory and organization system. Prior to 0.24.0, the authentication rate limiter (authRateLimiter) tracks failed attempts per client IP. It determines the client IP by reading, 1. X-Real-IP header, 2. First entry of X-Forwarded-For header, and 3. r.RemoteAddr (TCP connection address). These… | |
| Analizada | Media (4.3) | 0.28% | — | Sysadminsmedia Homebox | 3/3/2026 | 17/6/2026 | HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, the notifier functionality allows authenticated users to specify arbitrary URLs to which the application sends HTTP POST requests. No validation or restriction is applied to the supplied host, IP address, or port. Although the application does… | |
| Analizada | Media (5.4) | 0.25% | — | Sysadminsmedia Homebox | 3/3/2026 | 17/6/2026 | HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, a stored cross-site scripting (XSS) vulnerability exists in the item attachment upload functionality. The application does not properly validate or restrict uploaded file types, allowing an authenticated user to upload malicious HTML or SVG… | |
| Aplazada | Media (5.3) | 0.30% | — | Sysadminsmedia HomeboxAI | 2/7/2025 | 17/6/2026 | HomeBox is a home inventory and organization system. Prior to 0.20.1, HomeBox contains a missing authorization check in the API endpoints responsible for updating and deleting inventory item attachments. This flaw allows authenticated users to perform unauthorized actions on inventory item attachments that they do not… |