Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▼ 88 respecto a la semana anterior
Críticas / altas1419▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.5) | 0.19% | — | Amazon Language ServersAI | 23/6/2026 | 23/6/2026 | Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur when a local user opens a workspace with a maliciously crafted symlink that resolves to a file path outside the workspace trust boundary. To remediate this issue, users… | |
| Pendiente de análisis | Alta (8.5) | 0.23% | — | Amazon Language ServersAI | 23/6/2026 | 23/6/2026 | Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically executed. This issue requires the… | |
| Analizada | Alta (8.4) | 0.24% | — | Vercel Turborepo Language Server Protocol | 15/5/2026 | 17/6/2026 | Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14000, the Turborepo LSP VS Code extension could execute shell commands derived from workspace-controlled values. The extension used string-based command execution for Turborepo daemon commands and task runs. A malicious… | |
| Analizada | Crítica (9.8) | 0.41% | — | Gitlab Language Server | 28/7/2025 | 17/6/2026 | Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query execution | |
| Modificada | Crítica (9.8) | 0.49% | — | Jupyter Language Server Protocol Integration | 18/1/2024 | 17/6/2026 | jupyter-lsp is a coding assistance tool for JupyterLab (code navigation + hover suggestions + linters + autocompletion + rename) using Language Server Protocol. Installations of jupyter-lsp running in environments without configured file system access control (on the operating system level), and with jupyter-server… | |
| Modificada | Alta (7.5) | 0.89% | — | Dotnetfoundation C# Language Server Protocol | 17/7/2023 | 17/6/2026 | A vulnerability has been found in OmniSharp csharp-language-server-protocol up to 0.19.6 and classified as problematic. This vulnerability affects the function CreateSerializerSettings of the file src/JsonRpc/Serialization/SerializerBase.cs of the component JSON Serializer. The manipulation leads to resource… | |
| Modificada | Alta (8.8) | 0.76% | — | Snyk CLISnyk Language ServerSnyk Security | 30/11/2022 | 17/6/2026 | The package snyk before 1.1064.0 are vulnerable to Code Injection when analyzing a project. An attacker who can convince a user to scan a malicious project can include commands in a build file such as build.gradle or gradle-wrapper.jar, which will be executed with the privileges of the application. This vulnerability… | |
| Modificada | Alta (8.8) | 2.0% | — | XML Language Server Project XML Server ProjectEclipse Wild WEB DeveloperTheia XML Extension Project Theia XML Extension | 23/10/2019 | 17/6/2026 | XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows XXE via a crafted XML document, with resultant SSRF (as well as SMB connection initiation that can lead to NetNTLM challenge/response capture for password… | |
| Modificada | Media (6.5) | 2.8% | — | XML Language Server Project XML Server ProjectEclipse Wild WEB DeveloperTheia XML Extension Project Theia XML Extension | 23/10/2019 | 17/6/2026 | XMLLanguageService.java in XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows a remote attacker to write to arbitrary files via Directory Traversal. |