Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2769▲ 8 respecto a la semana anterior
Críticas / altas1461▲ 292 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 416 respecto a la semana anterior
76 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.55% | — | LeafwikiAI | 26/8/2026 | 24/9/2026 | LeafWiki extracts an uploaded ZIP archive without limiting how much data it will write. ZipExtractor.ExtractToDir in internal/importer/zip_extractor.go opens each entry and copies it to the destination with io.Copy, which runs to the end of the decompressed stream, so only the size of the uploaded archive is bounded… | |
| Aplazada | Media (4.8) | 0.39% | — | LeafwikiAI | 21/8/2026 | 9/9/2026 | LeafWiki is a self-hosted wiki. Prior to version 0.10.2, page titles returned by the search API could be rendered as raw HTML in the frontend. A user with editor or administrator permissions could create or modify a page title containing an HTML/JavaScript payload. When another user searched for a matching term, the… | |
| Aplazada | Alta (8.8) | 0.55% | — | LeafwikiAI | 21/8/2026 | 9/9/2026 | LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a path traversal vulnerability in LeafWiki’s asset rename functionality. An authenticated user with editor permissions could move files that are accessible to the LeafWiki server process into a page’s asset directory. This could allow sensitive local… | |
| Aplazada | Alta (8.8) | 0.42% | — | LeafwikiAI | 21/8/2026 | 9/9/2026 | LeafWiki is a self-hosted wiki. Versions 0.1.0 through 0.10.0 have a privilege escalation vulnerability in the user update API. An authenticated user could update their own account role and escalate privileges from a regular user, such as `viewer`, to `admin`. Exploitation requires a valid authenticated LeafWiki user… | |
| Aplazada | Alta (7.1) | 0.25% | — | Hupe13 Extensions FOR Leaflet MAPAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hupe13 Extensions for Leaflet Map extensions-leaflet-map allows DOM-Based XSS.This issue affects Extensions for Leaflet Map: from n/a through <= 5.1. | |
| Aplazada | Crítica (9) | 0.54% | — | ThymeleafAI | 12/5/2026 | 17/6/2026 | Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to 3.1.5.RELEASE, a security bypass vulnerability exists in the expression execution mechanisms of Thymeleaf. Although the library provides mechanisms to avoid the execution of potentially dangerous expressions in some specific… | |
| Modificada | Crítica (9) | 1.2% | — | Thymeleaf | 17/4/2026 | 18/8/2026 | Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly neutralize specific… | |
| Modificada | Crítica (9) | 0.94% | — | Thymeleaf | 17/4/2026 | 4/8/2026 | Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly restrict the scope of… | |
| Modificada | Media (6.1) | 0.19% | — | Leafletjs Leaflet | 14/4/2026 | 17/6/2026 | Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This method renders user-supplied input as raw HTML without sanitization, allowing attackers to inject arbitrary JavaScript code through event handler attributes (e.g., <img src=x… | |
| Aplazada | Media (6.4) | 0.35% | — | Hupe13 Extensions FOR Leaflet MAPAI | 8/4/2026 | 24/7/2026 | The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'elevation-track' shortcode in all versions up to, and including, 4.14. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.22% | — | Bozdoz Leaflet-mapAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bozdoz Leaflet Map leaflet-map allows Stored XSS.This issue affects Leaflet Map: from n/a through <= 3.4.4. | |
| Aplazada | Media (6.4) | 0.33% | — | Dsgvo Snippet FOR Leaflet MAP AND ITS ExtensionsAI | 26/3/2026 | 17/6/2026 | The DSGVO snippet for Leaflet Map and its Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `leafext-cookie-time` and `leafext-delete-cookie` shortcodes in all versions up to, and including, 3.1. This is due to insufficient input sanitization and output escaping on user supplied… | |
| Pendiente de análisis | Media (6.9) | 0.59% | — | Nanoleaf LinesAI | 25/3/2026 | 17/6/2026 | Nanoleaf Lines 12.3.2 does not authenticate firmware file uploads. A remote, unauthenticated attacker can upload firmware files on the device and consume storage resources. Fixed in 12.3.6. | |
| Aplazada | Media (5.5) | 0.47% | — | Trueleaf ApiflowAI | 21/3/2026 | 17/6/2026 | A vulnerability was determined in trueleaf ApiFlow 0.9.7. The impacted element is the function validateUrlSecurity of the file packages/server/src/service/proxy/http_proxy.service.ts of the component URL Validation Handler. This manipulation causes server-side request forgery. Remote exploitation of the attack is… | |
| Analizada | Media (6.9) | 0.34% | — | Vapor Leafkit | 18/3/2026 | 17/6/2026 | LeafKit is a templating language with Swift-inspired syntax. Prior to version 1.14.2, HTML escaping doesn't work correctly when a template prints a collection (Array / Dictionary) via `#(value)`. This can result in XSS, allowing potentially untrusted input to be rendered unescaped. Version 1.14.2 fixes the issue. | |
| Analizada | Media (6.1) | 0.29% | — | Vapor Leafkit | 20/2/2026 | 17/6/2026 | Leafkit is a templating language with Swift-inspired syntax. Prior to 1.4.1, htmlEscaped in leaf-kit will only escape html special characters if the extended grapheme clusters match, which allows bypassing escaping by using an extended grapheme cluster containing both the special html character and some additional… | |
| Aplazada | Crítica (9.8) | 0.32% | — | Leafcolor Applay ShortcodesAI | 20/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in leafcolor Applay - Shortcodes applay-shortcodes allows Object Injection.This issue affects Applay - Shortcodes: from n/a through <= 3.7. | |
| Aplazada | Media (6.8) | 0.20% | — | Bosch Infotainment ECUAINissan Leaf ZE1AI | 15/2/2026 | 17/6/2026 | There is a misconfiguration vulnerability inside the Infotainment ECU manufactured by BOSCH. The vulnerability happens during the startup phase of a specific systemd service, and as a result, the following developer features will be activated: the disabled firewall and the launched SSH server. First identified on… | |
| Aplazada | Media (6.7) | 0.12% | — | Nissan Leaf ZE1AI | 15/2/2026 | 17/6/2026 | The system suffers from the absence of a kernel module signature verification. If an attacker can execute commands on behalf of root user (due to additional vulnerabilities), then he/she is also able to load custom kernel modules to the kernel space and execute code in the kernel context. Such a flaw can lead to… | |
| Aplazada | Crítica (9.3) | 0.17% | — | Bosch Infotainment ECUAIBosch Rh850AINissan Leaf ZE1AI | 15/2/2026 | 17/6/2026 | The Infotainment ECU manufactured by Bosch uses a RH850 module for CAN communication. RH850 is connected to infotainment over the INC interface through a custom protocol. There is a vulnerability during processing requests of this protocol on the V850 side which allows an attacker with code execution on the… | |
| Aplazada | Media (6.5) | 0.29% | — | Bosch Infotainment ECUAINissan Leaf ZE1AIRedbendAI | 22/1/2026 | 17/6/2026 | The Infotainment ECU manufactured by Bosch which is installed in Nissan Leaf ZE1 – 2020 uses a Redbend service for over-the-air provisioning and updates. HTTPS is used for communication with the back-end server. Due to usage of the default configuration for the underlying SSL engine, the server root certificate is not… | |
| Aplazada | Media (4) | 0.27% | — | Nissan LeafAI | 22/1/2026 | 17/6/2026 | The anti-theft protection mechanism can be bypassed by attackers due to weak response generation algorithms for the head unit. It is possible to reveal all 32 corresponding responses by sniffing CAN traffic or by pre-calculating the values, which allow to bypass the protection. First identified on Nissan Leaf ZE1… | |
| Aplazada | Media (6.5) | 0.15% | — | Hupe13 Extensions FOR Leaflet MAPAI | 21/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hupe13 Extensions for Leaflet Map extensions-leaflet-map allows DOM-Based XSS.This issue affects Extensions for Leaflet Map: from n/a through <= 4.8. | |
| Aplazada | Media (6.4) | 0.22% | — | Hupe13 Extensions FOR Leaflet MAPAI | 4/11/2025 | 17/6/2026 | The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `geojsonmarker` shortcode in all versions up to, and including, 4.7. This is due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.41% | — | MAP Block LeafletAI | 29/5/2025 | 17/6/2026 | The Map Block Leaflet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… |