Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 303 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.37% | — | Huly PlatformAIPuppeteerAI | 14/9/2026 | 24/9/2026 | Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply arbitrary URLs to the print endpoint, which Puppeteer renders and returns as downloadable PDFs or images, enabling access to… | |
| Aplazada | Media (6.3) | 0.37% | — | Huly PlatformAI | 25/6/2026 | 14/7/2026 | Huly Platform through 0.7.423, fixed in commit 68cbf8a contains an authenticated server-side request forgery vulnerability in the /import endpoint of front pod that allows workspace users to make arbitrary server requests. Attackers can exploit this by supplying malicious URLs to fetch internal services, exfiltrate… | |
| Aplazada | Baja (2.1) | 0.20% | — | Hcengineering Huly PlatformAI | 15/6/2026 | 24/7/2026 | A vulnerability was found in hcengineering Huly Platform up to 0.7.0. Affected by this vulnerability is the function getAccountInfo of the file server/account/src/operations.ts of the component User Information Handler. The manipulation results in improper authorization. The attack may be launched remotely. The… | |
| Aplazada | Baja (2.1) | 0.21% | — | Hcengineering Huly PlatformAI | 15/6/2026 | 24/7/2026 | A vulnerability has been found in hcengineering Huly Platform up to 0.7.0. Affected is the function getMailboxSecret of the file server/account/src/operations.ts of the component RPC Interface. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to… | |
| Aplazada | Baja (2.1) | 0.34% | — | Hcengineering Huly PlatformAI | 6/4/2026 | 24/7/2026 | A vulnerability was identified in hcengineering Huly Platform 0.7.382. This affects an unknown part of the file server/front/src/index.ts of the component Import Endpoint. Such manipulation leads to server-side request forgery. The attack can be launched remotely. The exploit is publicly available and might be used.… | |
| Aplazada | Baja (2.9) | 0.39% | — | Hcengineering Huly PlatformAI | 6/4/2026 | 24/7/2026 | A vulnerability was determined in hcengineering Huly Platform 0.7.382. Affected by this issue is some unknown functionality of the file foundations/core/packages/token/src/token.ts of the component JWT Token Handler. This manipulation of the argument SERVER_SECRET with the input secret causes use of hard-coded… | |
| Aplazada | Media (6.5) | 0.53% | — | Huly PlatformAI | 25/10/2024 | 17/6/2026 | An arbitrary file upload vulnerability in Huly Platform v0.6.295 allows attackers to execute arbitrary code via uploading a crafted HTML file into chat group. | |
| Aplazada | Media (6.1) | 0.38% | — | Huly PlatformAI | 25/10/2024 | 17/6/2026 | An arbitrary file upload vulnerability in Huly Platform v0.6.295 allows attackers to execute arbitrary code via uploading a crafted HTML file into the tracker comments page. | |
| Aplazada | Media (6.1) | 0.38% | — | Huly PlatformAI | 3/4/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Huly Platform v.0.6.202 allows attackers to execute arbitrary code via upload of crafted SVG file to issues. | |
| Aplazada | Media (4.3) | 0.33% | — | Hcengineering Huly PlatformAI | 7/3/2024 | 17/6/2026 | Server Side Request Forgery (SSRF) vulnerability in hcengineering Huly Platform v.0.6.202 allows attackers to run arbitrary code via upload of crafted SVG file. |