Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.72% | — | Dayuanjiang Next-ai-draw-ioAI | 21/7/2026 | 22/7/2026 | Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp parameter | |
| Aplazada | Alta (7.8) | 0.63% | — | Dayuanjiang Next-ai-draw-ioAI | 21/7/2026 | 22/7/2026 | Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-server | |
| Aplazada | Alta (7.5) | 0.51% | — | Dayuanjiang Next-ai-draw-ioAI | 21/7/2026 | 22/7/2026 | An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component | |
| Aplazada | Crítica (9.8) | 0.62% | — | Dayuanjiang Next-ai-draw-ioAI | 21/7/2026 | 22/7/2026 | An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value | |
| Analizada | Media (5.5) | 0.15% | — | Dayuanjiang Next AI Draw.io | 21/4/2026 | 17/6/2026 | Next AI Draw.io is a next.js web application that integrates AI capabilities with draw.io diagrams. Prior to 0.4.15, the embedded HTTP sidecar contains three POST handlers (/api/state, /api/restore, and /api/history-svg) that process incoming requests by accumulating the entire request body into a JavaScript string… | |
| Analizada | Alta (8.8) | 0.30% | — | Bosch Rexroth Indraworks | 18/2/2026 | 17/6/2026 | A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious serialized data. Exploitation requires user interaction, specifically opening a specially crafted file, which then causes the… | |
| Analizada | Alta (8.8) | 0.30% | — | Bosch Rexroth Indraworks | 18/2/2026 | 17/6/2026 | A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious serialized data. Exploitation requires user interaction, specifically opening a specially crafted file, which then causes the… | |
| Analizada | Alta (8.8) | 0.38% | — | Bosch Rexroth IndraworksBosch Rexroth Ua.testclient | 18/2/2026 | 17/6/2026 | A vulnerability has been identified in the UA.Testclient utility, which is included in Rexroth IndraWorks. All versions prior to 15V24 are affected. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious serialized data. Exploitation requires user… | |
| Analizada | Alta (8.8) | 0.38% | — | Bosch Rexroth Indraworks | 18/2/2026 | 17/6/2026 | A vulnerability has been identified in the OPC.Testclient utility, which is included in Rexroth IndraWorks. All versions prior to 15V24 are affected. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious serialized data. Exploitation requires… | |
| Aplazada | Crítica (9.1) | 0.72% | — | Aidraw I DrawAI | 17/4/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in aidraw I Draw idraw allows Using Malicious Files.This issue affects I Draw: from n/a through <= 1.0. |