Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
72 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7) | 0.14% | — | LektorAI | 1/10/2026 | 2/10/2026 | Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that allows unauthenticated attackers to perform state-changing actions by sending cross-origin requests without CSRF tokens, Origin/Referer validation, CORS configuration, or Host allowlisting. Attackers can… | |
| Pendiente de análisis | Media (6.9) | 0.52% | — | Linuxfoundation Inspektor GadgetAI | 15/9/2026 | 30/9/2026 | Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. From 0.27.0 until 0.53.1, the uprobe library resolver can allow an unprivileged container to consume excessive CPU and block other containers from starting by supplying a… | |
| Pendiente de análisis | Baja (2.9) | 0.63% | — | Linuxfoundation Inspektor GadgetAI | 15/9/2026 | 30/9/2026 | Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. From 0.28.0 until 0.53.1, the USDT note parser in pkg/uprobetracer/usdt.go can allow an unprivileged container to crash or exhaust the memory of the privileged Inspektor Gadget… | |
| Aplazada | Alta (7.5) | 0.63% | — | LektorAI | 28/8/2026 | 1/9/2026 | A path traversal vulnerability exists in the built-in preview/development web server of Lektor <3.3.14 on Windows. An attacker with network access to the server can send a crafted HTTP request containing path traversal sequences to read arbitrary files accessible to the process, disclosing sensitive information such… | |
| Aplazada | Alta (7.3) | 0.16% | — | RedisAIContribsys FaktoryAI | 25/8/2026 | 9/9/2026 | Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the embedded Redis bootstrapper is vulnerable to an insecure temporary file flaw that lets a local unprivileged user hijack the Redis configuration and escalate to root. It writes its startup configuration to a fixed, predictable,… | |
| Aplazada | Alta (8.7) | 0.45% | — | Contribsys FaktoryAI | 25/8/2026 | 9/9/2026 | Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the server is vulnerable to an unauthenticated denial of service in which a single malformed command crashes the entire process. Its wire protocol is line-based, and several command handlers slice or index the received line at a fixed… | |
| Pendiente de análisis | Media (5.9) | 0.37% | — | Jetbrains KtorAI | 17/8/2026 | 28/8/2026 | In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible | |
| Aplazada | Media (6.5) | 0.22% | — | Vektor-inc VK ALL IN ONE Expansion UnitAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidekazu Ishikawa VK All in One Expansion Unit vk-all-in-one-expansion-unit allows Stored XSS.This issue affects VK All in One Expansion Unit: from n/a through <= 9.113.3. | |
| Analizada | Media (4.8) | 0.15% | — | Linuxfoundation Inspektor Gadget | 12/3/2026 | 17/6/2026 | Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. Prior to 0.50.1, in a situation where the ring-buffer of a gadget is – incidentally or maliciously – already full, the gadget will silently drop events. The… | |
| Aplazada | Media (6.4) | 0.20% | — | Vektor-inc VK ALL IN ONE Expansion UnitAI | 18/2/2026 | 17/6/2026 | The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vkExUnit_sns_title' parameter in all versions up to, and including, 9.112.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… | |
| Analizada | Media (6.9) | 0.73% | — | Linuxfoundation Inspektor Gadget | 12/2/2026 | 17/6/2026 | Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. String fields from eBPF events in columns output mode are rendered to the terminal without any sanitization of control characters or ANSI escape sequences. Therefore, a… | |
| Modificada | Media (6.3) | 0.27% | — | Farktor E-commerce Package | 12/2/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Farktor Software E-Commerce Services Inc. E-Commerce Package allows Manipulating User-Controlled Variables. This issue affects E-Commerce Package: through 27112025. | |
| Modificada | Media (6.1) | 0.23% | — | Farktor E-commerce Package | 12/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Farktor Software E-Commerce Services Inc. E-Commerce Package allows Cross-Site Scripting (XSS). This issue affects E-Commerce Package: through 27112025. | |
| Modificada | Crítica (9.8) | 0.37% | — | Farktor E-commerce Package | 12/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farktor Software E-Commerce Services Inc. E-Commerce Package allows Blind SQL Injection. This issue affects E-Commerce Package: through 27112025. | |
| Modificada | Media (6.6) | 1.4% | — | Linuxfoundation Inspektor Gadget | 29/1/2026 | 17/6/2026 | Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. The `ig` binary provides a subcommand for image building, used to generate custom gadget OCI images. A part of this functionality is implemented in the file… | |
| Aplazada | Media (6.5) | 0.16% | — | Vektor VK Google JOB Posting ManagerAI | 16/12/2025 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vektor,Inc. VK Google Job Posting Manager vk-google-job-posting-manager allows Stored XSS.This issue affects VK Google Job Posting Manager: from n/a through <= 1.2.22. | |
| Aplazada | Media (6.4) | 0.23% | — | Vektor-inc VK ALL IN ONE Expansion UnitAI | 18/11/2025 | 17/6/2026 | The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_veu_custom_css' parameter in all versions up to, and including, 9.112.1. This is due to insufficient input sanitization and output escaping on the user-supplied Custom CSS value. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.23% | — | Vektor-inc VK ALL IN ONE Expansion UnitAI | 18/11/2025 | 17/6/2026 | The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vkExUnit_cta_url' and 'vkExUnit_cta_button_text' parameters in all versions up to, and including, 9.112.1. This is due to a logic error in the CTA save function that reads sanitization callbacks from the wrong… | |
| Aplazada | Media (4.3) | 0.24% | — | Faktor Vier F4 Media TaxonomiesAI | 3/9/2025 | 17/6/2026 | Missing Authorization vulnerability in FAKTOR VIER F4 Media Taxonomies f4-media-taxonomies allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects F4 Media Taxonomies: from n/a through <= 1.1.4. | |
| Aplazada | Alta (7.2) | 0.46% | — | Risk Yazilim Teknolojileri Reel Sektor Hazine VE Risk Yonetimi YazilimiAI | 15/8/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Risk Yazılım Teknolojileri Ltd. Şti. Reel Sektör Hazine ve Risk Yönetimi Yazılımı allows SQL Injection, CAPEC - 7 - Blind SQL Injection. This issue affects Reel Sektör Hazine ve Risk Yönetimi Yazılımı: through 1.0.0.4. | |
| Aplazada | Media (6.5) | 0.39% | — | Vektor-inc VK Filter SearchAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vektor,Inc. VK Filter Search vk-filter-search allows Stored XSS.This issue affects VK Filter Search: from n/a through <= 2.20.2. | |
| Analizada | Media (5.3) | 0.32% | — | Jetbrains Ktor | 12/3/2025 | 17/6/2026 | In JetBrains Ktor before 3.1.1 an HTTP Request Smuggling was possible | |
| Aplazada | Media (4.3) | 0.33% | — | Vektor-inc VK BlocksAI | 7/3/2025 | 17/6/2026 | The VK Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.94.2.2 via the page content block. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including the content of private posts and… | |
| Aplazada | Alta (7.1) | 0.26% | — | Faktor Vier F4 Post TreeAI | 13/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FAKTOR VIER F4 Post Tree f4-tree allows Reflected XSS.This issue affects F4 Post Tree: from n/a through <= 1.1.18. | |
| Analizada | Media (4.8) | 0.30% | — | Vektor-inc VK ALL IN ONE Expansion Unit | 13/11/2024 | 17/6/2026 | Cross-site scripting vulnerability exists in VK All in One Expansion Unit versions prior to 9.100.1.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is accessing the web site using the product. |