Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2576▼ 298 respecto a la semana anterior
Críticas / altas1356▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

57 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5.8)0.35%—KumaAI15/9/202630/9/2026
Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, Universal mode kuma-dp connections to an HTTPS control plane disable TLS peer verification when --ca-cert-file is not supplied and KUMA_CONTROL_PLANE_CA_CERT is…
Pendiente de análisisMedia (5.5)0.27%—KumaAI15/9/202630/9/2026
Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, a kumactl profile manually configured for an HTTPS control plane without --ca-cert-file disables TLS peer verification and sends API tokens over the unverified…
AplazadaAlta (8.7)0.94%—Dockge.kuma DockgeAI20/8/202623/9/2026
Dockge validates a stack name only on the write path. In backend/stack.ts the allow-list check in validate(), which requires the name to match ^[a-z0-9_-]+$, is reached from save() alone, while the path getter returns path.join(this.server.stacksDir, this.name) and Stack.getStack builds path.join(server.stacksDir,…
Pendiente de análisisAlta (7)0.56%—Kong MeshAIKuma KDSAI17/8/202631/8/2026
On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attributed using the in-band, sender-controlled ControlPlane.Identifier rather than the authenticated zone identity derived from the connection. Authenticated zones can have the global control plane store and re-distribute…
Pendiente de análisisMedia (5.8)0.16%—Kong Kuma-dpAI12/8/202631/8/2026
When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane connects with TLS peer verification disabled, and the dataplane authentication token is sent over that unverified connection. An on-path actor can intercept the dataplane authentication token and…
Pendiente de análisisMedia (5.5)0.13%—Kumahq KumaAI12/8/202631/8/2026
When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS verification and sends API tokens over the unverified connection. An attacker on the network path between the operator and the control plane can intercept user or admin API tokens and then act…
Pendiente de análisisMedia (5.3)0.56%—Kong KumaAI12/8/202631/8/2026
The dataplane token validator in kuma-cp performs an unchecked Go type assertion on the JWT kid header. A token whose kid is a JSON number decodes as a float64 and triggers a runtime panic before any signature, claims, or authorization check runs. The panic terminates the entire kuma-cp process, HTTP API, the health…
Pendiente de análisisMedia (5.3)0.46%—Kuma-dpAIEnvoyAI12/8/202631/8/2026
When kuma-dp is configured with the Envoy admin API on a Unix domain socket, which is the default, its readiness service on TCP port 9902 - bound to all interfaces - forwards almost the entire Envoy admin API to any caller that can reach the port, with no authentication. An attacker with network access to a data…
AplazadaAlta (8.1)0.38%—Uptimekuma Uptime KumaAIMatomoAI5/8/202626/8/2026
Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo value as a bare, unquoted JavaScript expression inside a <script> block rendered on every public status page. A siteId value such as , once saved by an editor/admin, executes arbitrary JavaScript for…
AplazadaMedia (5.1)0.30%—KumaAI28/5/202617/6/2026
Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.25, 2.9.15, 2.11.13, 2.12.10, and 2.13.5, the default kuma-cp config leaks the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their…
AnalizadaMedia (6.6)0.19%—Saurabh-kumar Python-dotenv20/4/202617/6/2026
python-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, `set_key()` and `unset_key()` in python-dotenv follow symbolic links when rewriting `.env` files, allowing a local attacker to overwrite arbitrary files via a crafted symlink when a cross-device…
AplazadaMedia (6.5)0.22%—Manoj Kumar MK Google-directionsAIManoj Kumar MK Google-distance-calculatorAI8/4/202624/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Manoj Kumar MK Google Directions google-distance-calculator allows DOM-Based XSS.This issue affects MK Google Directions: from n/a through <= 3.1.1.
AplazadaMedia (5.3)0.29%—Pankaj Kumar Wpxmas-snowAI8/4/202624/7/2026
Missing Authorization vulnerability in Pankaj Kumar WpXmas-Snow wpxmas-snow allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpXmas-Snow: from n/a through <= 1.1.
AnalizadaMedia (6.5)0.46%—Uptime.kuma Uptime Kuma20/3/202617/6/2026
Uptime Kuma is an open source, self-hosted monitoring tool. In versions 1.23.0 through 2.2.0, the fix from GHSA-vffh-c9pq-4crh doesn't fully work to preventServer-side Template Injection (SSTI). The three mitigations added to the Liquid engine (root, relativeReference, dynamicPartials) only block quoted paths. If a…
AnalizadaMedia (5.3)0.86%—Uptime.kuma Uptime Kuma12/3/202617/6/2026
Uptime Kuma is an open source, self-hosted monitoring tool. From 2.0.0 to 2.1.3 , the GET /api/badge/:id/ping/:duration? endpoint in server/routers/api-router.js does not verify that the requested monitor belongs to a public group. All other badge endpoints check AND public = 1 in their SQL query before returning…
AplazadaAlta (7.1)0.12%—Ashwani Kumar GST FOR WoocommerceAI26/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Ashwani kumar GST for WooCommerce gst-for-woocommerce allows Stored XSS.This issue affects GST for WooCommerce: from n/a through <= 2.0.
AplazadaMedia (5.9)0.30%—Sureshkumarmukhiya Append Extensions ON PagesAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Suresh Kumar Mukhiya Append extensions on Pages append-extensions-on-pages allows Stored XSS.This issue affects Append extensions on Pages: from n/a through <= 1.1.2.
AplazadaAlta (7.1)0.13%—Subhash Kumar Database TO ExcelAI5/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Subhash Kumar Database to Excel database-to-excel allows Stored XSS.This issue affects Database to Excel: from n/a through <= 1.0.
AplazadaMedia (5.9)0.21%—Dilip Kumar Beauty Contact Popup FormAI27/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dilip kumar Beauty Contact Popup Form beauty-contact-popup-form allows Stored XSS.This issue affects Beauty Contact Popup Form: from n/a through <= 6.0.
AplazadaAlta (7.1)0.27%—M A Vinoth Kumar Category WidgetAI23/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M A Vinoth Kumar Category Widget category-widget allows Reflected XSS.This issue affects Category Widget: from n/a through <= 2.0.2.
AplazadaCrítica (9.9)0.54%—Nirmal Kumar RAM WP Remote ThumbnailAI10/4/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Nirmal Kumar Ram WP Remote Thumbnail wp-remote-thumbnail allows Upload a Web Shell to a Web Server.This issue affects WP Remote Thumbnail: from n/a through <= 1.3.2.
AplazadaMedia (6.5)0.30%—Sandeep Kumar WP Video PlaylistAI3/4/202517/6/2026
Missing Authorization vulnerability in Sandeep Kumar WP Video Playlist wp-video-playlist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Video Playlist: from n/a through <= 1.1.2.
AplazadaMedia (4.3)0.19%—Animesh Kumar Advanced Speed IncreaserAI1/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Animesh Kumar Advanced Speed Increaser advanced-speed-increaser.This issue affects Advanced Speed Increaser: from n/a through <= 2.2.1.
AplazadaAlta (7.1)0.39%—Abhishek Kumar FrizzlyAI1/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Abhishek Kumar Frizzly frizzly allows Reflected XSS.This issue affects Frizzly: from n/a through <= 1.1.0.
AnalizadaMedia (6.9)0.53%—Anujkumar Bank Locker Management System24/3/202517/6/2026
A vulnerability, which was classified as critical, has been found in PHPGurukul Bank Locker Management System 1.0. Affected by this issue is some unknown functionality of the file /add-lockertype.php. The manipulation of the argument lockerprice leads to sql injection. The attack may be launched remotely. The exploit…