Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 6 respecto a la semana anterior
Críticas / altas1451▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.56% | — | KnownsAI | 10/9/2026 | 10/9/2026 | knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, allowing remote attackers to enumerate arbitrary directories on the host filesystem. Attackers can traverse the directory structure to locate project directories and identify targets for further exploitation. | |
| Aplazada | Alta (8.7) | 0.48% | — | KnownsAI | 10/9/2026 | 15/9/2026 | knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at another project directory and obtain write access capabilities. | |
| Aplazada | Alta (7.1) | 0.48% | — | KnownsAI | 10/9/2026 | 11/9/2026 | knowns through 0.33.0 fails to confine the path argument of the code.find MCP tool to the project root, allowing AI agent sessions to read source files anywhere on the host. Attackers can supply absolute paths or relative traversal sequences to the path argument and retrieve full file contents from outside the… | |
| Aplazada | Alta (8.6) | 0.65% | — | KnownsAI | 10/9/2026 | 10/9/2026 | knowns through 0.33.0 fails to properly validate template destination paths in the code generation template engine, allowing attackers to read and write arbitrary files outside the project root. Attackers can supply malicious templates that traverse directories to overwrite shell profiles, steal credentials, or… | |
| Pendiente de análisis | Alta (8.8) | 0.75% | — | KnownsAI | 9/9/2026 | 14/9/2026 | knowns (npm package) versions <= 0.29.1 contain a path traversal vulnerability in the Document API. The HTTP handler in internal/server/routes/docs.go normalizes the user-supplied document path with cleanDocPath(), which strips leading/trailing slashes and the .md suffix but does not neutralize ../ traversal… | |
| Aplazada | Alta (8.8) | 0.74% | — | KnownsAI | 7/9/2026 | 8/9/2026 | knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can supply traversal sequences in the name parameter to escape the imports directory and overwrite arbitrary files writable by the server process. | |
| Aplazada | Alta (7.2) | 0.77% | — | KnownsAI | 7/9/2026 | 10/9/2026 | knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the project root. Attackers can supply absolute paths or relative paths containing directory traversal sequences to write malicious content to sensitive… | |
| Aplazada | Alta (8.5) | 0.21% | — | KnownsAI | 7/9/2026 | 8/9/2026 | knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file. When a repository with a crafted configuration is opened, the unvalidated binary path is executed… | |
| Aplazada | Media (6.9) | 0.35% | — | KnownsAI | 7/9/2026 | 9/9/2026 | knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied destinations without validation. Attackers can enumerate internal hosts and cloud metadata endpoints by observing transport error messages that… | |
| Aplazada | Alta (8.7) | 0.98% | — | KnownsAI | 7/9/2026 | 14/9/2026 | knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files. Attackers can supply directory traversal sequences in the templateFile parameter to bypass path restrictions and read sensitive files like… | |
| Aplazada | Crítica (9.1) | 0.44% | — | LighttpdAIUnknown Vendor Product FirmwareAI | 4/8/2026 | 9/9/2026 | The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing. | |
| Aplazada | Alta (7.5) | 0.89% | — | Knowns-dev KnownsAI | 21/7/2026 | 22/7/2026 | Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc and update_doc tools. | |
| Aplazada | Alta (7.5) | 0.89% | — | Knowns-dev KnownsAI | 21/7/2026 | 22/7/2026 | Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the create_doc tool. | |
| Analizada | Crítica (9.2) | 0.72% | — | Withknown Known | 6/3/2026 | 17/6/2026 | Idno is a social publishing platform. Prior to version 1.6.4, a logic error in the API authentication flow causes the CSRF protection on the URL unfurl service endpoint to be trivially bypassed by any unauthenticated remote attacker. Combined with the absence of a login requirement on the endpoint itself, this allows… | |
| Analizada | Alta (8.6) | 0.92% | — | Withknown Known | 6/3/2026 | 17/6/2026 | Idno is a social publishing platform. Prior to version 1.6.4, there is a remote code execution vulnerability via chained import file write and template path traversal. This issue has been patched in version 1.6.4. | |
| Analizada | Crítica (9.8) | 1.2% | — | Withknown Known | 13/2/2026 | 17/6/2026 | Known is a social publishing platform. Prior to 1.6.3, a Critical Broken Authentication vulnerability exists in Known 1.6.2 and earlier. The application leaks the password reset token within a hidden HTML input field on the password reset page. This allows any unauthenticated attacker to retrieve the reset token for… | |
| Modificada | Crítica (9.8) | 1.4% | — | Unknown-corp Melty Blood Actress Again Current Code | 28/6/2024 | 17/6/2026 | Soft Circle French-Bread Melty Blood: Actress Again: Current Code through 1.07 Rev. 1.4.0 allows a remote attacker to execute arbitrary code on a client's machine via a crafted packet on TCP port 46318. | |
| Modificada | Alta (7.5) | 0.80% | — | Unknown-o Download-station | 10/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in unknown-o download-station up to 1.1.8. This issue affects some unknown processing of the file index.php. The manipulation of the argument f leads to path traversal: '../filedir'. The attack may be initiated remotely. The exploit has been disclosed… | |
| Modificada | Alta (8.8) | 1.5% | — | Withknown Known | 8/7/2022 | 17/6/2026 | Known v1.3.1+2020120201 was discovered to allow attackers to perform an account takeover via a host header injection attack. | |
| Modificada | Media (6.1) | 1.4% | — | Withknown Known | 8/7/2022 | 17/6/2026 | An issue in the isSVG() function of Known v1.2.2+2020061101 allows attackers to execute arbitrary code via a crafted SVG file. | |
| Modificada | Media (5.4) | 0.86% | — | Withknown Known | 8/7/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Known v1.2.2+2020061101 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Your Name text field. | |
| Modificada | Media (4.3) | 0.95% | — | Withknown Known | 8/7/2022 | 17/6/2026 | Known v1.3.1 was discovered to contain an Insecure Direct Object Reference (IDOR). | |
| Modificada | Alta (7.5) | 1.2% | — | Unknown Domain Shoutbox | 8/2/2006 | 16/6/2026 | SQL injection vulnerability in Unknown Domain Shoutbox 2005.07.21 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors. | |
| Modificada | Media (4.3) | 1.3% | — | Unknown Domain Shoutbox | 8/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Unknown Domain Shoutbox 2005.07.21 allow remote attackers to inject arbitrary web script or HTML, possibly via the (1) Handle or (2) Message fields. |