Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2638▼ 297 respecto a la semana anterior
Críticas / altas1351▲ 82 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.55% | — | Lemmy-uiAIMarkdown-it-html5-embedAI | 19/8/2026 | 9/9/2026 | Lemmy is a link aggregator and forum for the fediverse. Prior to lemmy-ui 0.19.19-beta.1, LemmyNet/lemmy-ui renders Markdown in src/shared/markdown.ts for post bodies, comment bodies, private messages, and community and site sidebars through mdToHtml, which returns a raw __html object that Inferno injects without a… | |
| Aplazada | Media (5.3) | 0.48% | — | Join-lemmy LemmyAI | 19/8/2026 | 9/9/2026 | Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-alpha.18, Lemmy blocks new private messages from a sender after the recipient blocks that sender, but the edit path skips the same block check. create_private_message checks the recipient's block list with PersonActions::read_block… | |
| Aplazada | Media (6.5) | 0.43% | — | Join-lemmy LemmyAI | 19/8/2026 | 9/9/2026 | Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-alpha.18, a lower-ranked remote moderator can remove a higher-ranked moderator by sending a signed ActivityPub Remove activity to the target instance. The local API uses LocalUser::is_higher_mod_or_admin_check to enforce moderator rank,… | |
| Aplazada | Media (6.9) | 0.59% | — | Join-lemmy LemmyAI | 19/8/2026 | 9/9/2026 | Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, Lemmy's login endpoint in crates/api/api/src/local_user/login.rs returns different errors depending on whether the username_or_email value exists. LocalUserView::find_by_email_or_name propagates a NotFound response for an… | |
| Aplazada | Media (6.5) | 0.56% | — | Actix-webAINginxAIJoin-lemmy LemmyAI | 19/8/2026 | 9/9/2026 | Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, actix-web ConnectionInfo::realip_remote_addr reads the first value of X-Forwarded-For as the client address used by raw_ip_key in crates/utils/src/rate_limit/mod.rs. Lemmy's bundled docker/nginx.conf uses… | |
| Aplazada | Media (5.1) | 0.55% | — | Join-lemmy LemmyAI | 19/8/2026 | 9/9/2026 | Lemmy is a link aggregator and forum for the fediverse. From 0.19.18 until 0.19.19 and 1.0.0-alpha.20, a community moderator can feature or unfeature posts in other communities through federated CollectionAdd and CollectionRemove activities using CollectionType::Featured. After verify_mod_action authorizes the actor… | |
| Aplazada | Media (6.5) | 0.35% | — | Join-lemmy LemmyAI | 8/5/2026 | 17/6/2026 | Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy fetches metadata for user-supplied post URLs and, under the default StoreLinkPreviews image mode, downloads the preview image through local pict-rs. While the top-level page URL is checked against internal IP ranges, the extracted… | |
| Aplazada | Media (6.3) | 0.29% | — | Join-lemmy LemmyAI | 8/5/2026 | 17/6/2026 | Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy allows an authenticated low-privileged user to create a link post through POST /api/v3/post. When a post is created in a public community, the backend asynchronously sends a Webmention to the attacker-controlled link target. The… | |
| Aplazada | Media (6.5) | 0.38% | — | Activitypub-federation-rustAIJoin-lemmy LemmyAI | 27/3/2026 | 17/6/2026 | Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.7.0-beta.9, the `v4_is_invalid()` function in `activitypub-federation-rust` (`src/utils.rs`) does not check for `Ipv4Addr::UNSPECIFIED` (0.0.0.0). An unauthenticated attacker controlling a remote domain can point it to 0.0.0.0, bypass the SSRF… | |
| Aplazada | Alta (7.7) | 0.44% | — | Activitypub FederationAIPict-rsAIJoin-lemmy LemmyAI | 6/3/2026 | 17/6/2026 | Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on activitypub_federation, a framework for ActivityPub federation in Rust. Prior to version 0.19.16, the GET /api/v4/image/{filename} endpoint is vulnerable to unauthenticated SSRF through parameter… | |
| Aplazada | Media (4) | 0.42% | — | Activitypub FederationAIJoin-lemmy LemmyAI | 10/2/2025 | 17/6/2026 | Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on activitypub_federation, a framework for ActivityPub federation in Rust. This vulnerability, which is present in versions 0.6.2 and prior of activitypub_federation and versions 0.19.8 and prior of… | |
| Modificada | Media (6.5) | 0.51% | — | Join-lemmy Lemmy | 24/1/2024 | 17/6/2026 | Lemmy is a link aggregator and forum for the fediverse. Starting in version 0.17.0 and prior to version 0.19.1, users can report private messages, even when they're neither sender nor recipient of the message. The API response to creating a private message report contains the private message itself, which means any… |