Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2531▼ 362 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
307 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.33% | — | Elixir-mint MintAI | 28/9/2026 | 30/9/2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize an intermediary and the Mint client on a pooled connection, poisoning the responses to subsequent requests that share the connection. message_body/1 in… | |
| Aplazada | Media (6.3) | 0.33% | — | Elixir-mint MintAI | 28/9/2026 | 30/9/2026 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server to make the client hold up to about 16 MiB per connection in frames it should reject, consuming client memory. Mint.HTTP2.Frame.decode_next/2 in lib/mint/http2/frame.ex compares a frame with the… | |
| Aplazada | Alta (8.2) | 0.42% | — | Elixir-mint MintAI | 28/9/2026 | 29/9/2026 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server to exhaust memory on the client host and cause a denial of service. Mint.HTTP2 enforces the client's max_header_list_size setting only on the compressed size of an inbound header block, while RFC… | |
| Aplazada | Media (6.3) | 0.52% | — | Elixir-mint MintAI | 19/9/2026 | 22/9/2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on a pooled connection, enabling response-queue poisoning against subsequent requests that share the connection.… | |
| Pendiente de análisis | Alta (8.2) | 0.52% | — | Elixir ProtobufAI | 17/9/2026 | 24/9/2026 | Elixir protobuf is a pure Elixir implementation of Google Protobuf. From 0.8.0 until 0.16.1, services that decode attacker-controlled protobuf bytes with Protobuf.Decoder can be taken offline when the schema contains a self-referential or cyclic message type. In lib/protobuf/decoder.ex,… | |
| Aplazada | Media (6.3) | 0.52% | — | Elixir-mint MintAI | 4/9/2026 | 8/9/2026 | Inefficient Algorithmic Complexity vulnerability in elixir-mint mint allows a remote HTTP server to exhaust CPU on the client host and cause a denial of service. parse_hex_prefix/2 in lib/mint/http1/parse.ex folds each hex digit of a chunked response's chunk-size field into an arbitrary-precision accumulator with acc… | |
| Aplazada | Alta (8.2) | 0.52% | — | Elixir-mint MintAI | 4/9/2026 | 8/9/2026 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a remote HTTP server to exhaust memory on the client host and cause a denial of service. Two HTTP/1 response-parser states accumulate server data without any cap. In lib/mint/http1.ex, decode_status_line/4 stores the… | |
| Aplazada | Media (5.3) | 0.41% | — | Joomshaper Helix UltimateAI | 31/8/2026 | 31/8/2026 | Joomla Extension - joomshaper.com - Open Redirect via Base64 Return Parameter in Helix Ultimate < 2.2.10 - Return redirect parameters accepted arbitrary Base64 strings without verifying whether the resolved target was an internal site URL via Uri::isInternal. | |
| Aplazada | Alta (8.9) | 0.43% | — | Joomshaper Helix UltimateAI | 31/8/2026 | 31/8/2026 | Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in Helix Ultimate < 2.2.10 - Image uploads previously validated only file extension and basic size parameters. Non-image files disguised with raster extensions could be uploaded. Added strict MIME verification and GD binary raster… | |
| Aplazada | Alta (8.6) | 0.42% | — | Joomshaper Helix UltimateAI | 31/8/2026 | 31/8/2026 | Joomla Extension - joomshaper.com - Stored Cross-Site Scripting (XSS) in MegaMenu Layout Container & Embed Inputs in Helix Ultimate < 2.2.10 - Unsanitized column and item configuration values stored within the MegaMenu layout JSON were rendered without complete contextual escaping, allowing injection of malicious… | |
| Aplazada | Media (5.1) | 0.39% | — | Joomshaper Helix UltimateAI | 31/8/2026 | 31/8/2026 | Joomla Extension - joomshaper.com - Broken Access Control & Missing Authorization in MegaMenu Settings in Helix Ultimate < 2.2.10 - The AJAX endpoint save-megamenu-settings failed to enforce item-level and menu-level edit permissions (core.edit on com_menus.item.{id} or core.admin). An authenticated user could submit… | |
| Aplazada | Media (5.1) | 0.39% | — | Joomshaper Helix UltimateAI | 31/8/2026 | 31/8/2026 | Joomla Extension - joomshaper.com - Broken Object-Level Authorization in Blog Image Deletion in Helix Ultimate < 2.2.10 - `Blog::remove_image()` checked whether the user was authorized to edit the article ID passed in the request, but did not verify whether the specified image path (src) belonged to that article. On… | |
| Aplazada | Baja (2.1) | 0.33% | — | Soarkey StudentmanagementAISoarkey XueshengxinxiguanlixitongAI | 31/8/2026 | 1/9/2026 | A security flaw has been discovered in Soarkey StudentManagement and 学生信息管理系统 up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. This affects the function CourseDao.course_ranking of the file code/src/dao/CourseDao.java. Performing a manipulation of the argument cno results in sql injection. It is possible to initiate… | |
| Aplazada | Media (5.9) | 0.18% | — | Ematia ElixirAI | 28/8/2026 | 1/9/2026 | Uncontrolled Recursion vulnerability in the Elixir standard library allows an attacker who controls a list passed to inspect/1, List.to_string/1, or List.to_charlist/1 to exhaust a BEAM node's memory. Inspect.List's charlist branch in lib/elixir/lib/inspect.ex classifies a list as a charlist using… | |
| En análisis | Crítica (9.3) | 0.30% | — | TriliumAIMind ElixirAIElectronAI | 27/8/2026 | 9/9/2026 | Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter sanitizes HTML only for text notes and excludes the mindMap note type, whose JSON content is stored without sanitization, allowing an attacker-supplied import archive to embed a… | |
| Rechazada | Sin puntuar | — | — | Calix ExosAICalix GS7 XGSAI | 21/8/2026 | 15/9/2026 | Rejected reason: Vendor could not replicate the vul, and reporter is unavailable to comment. | |
| Aplazada | Alta (7.3) | 0.10% | — | Netflix LemurAI | 18/8/2026 | 8/9/2026 | Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/certificates/upload allowed a non-read-only user to create a duplicate row using another certificate body, authority_id, serial, or external_id without requiring permission on the underlying authority. PUT /api/1/certificates//revoke authorized the… | |
| Aplazada | Media (4.3) | 0.23% | — | Netflix LemurAI | 18/8/2026 | 8/9/2026 | Lemur manages TLS certificate creation. Prior to 1.9.3, CertificateExport placed its CertificatePermission ownership check inside the plugin.requires_key branch for POST /api/1/certificates//export. A plugin declaring requires_key false bypassed that check, and the handler still passed cert.private_key as an argument… | |
| Aplazada | Media (6.5) | 0.10% | — | Netflix LemurAI | 18/8/2026 | 8/9/2026 | Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/authorities with type=subca did not require AuthorityPermission on the parent authority when ADMIN_ONLY_AUTHORITY_CREATION was false. AssociatedAuthoritySchema resolved the caller-supplied parent and passed it through authority creation to… | |
| Aplazada | Alta (8.1) | 0.32% | — | Netflix LemurAI | 18/8/2026 | 8/9/2026 | Lemur manages TLS certificate creation. From 0.5.0 until 1.9.3, certificate create, upload, and edit requests accepted replaces[] or replacements identifiers that AssociatedCertificateSchema resolved with fetch_objects without a CertificatePermission check. Assigning those objects to Certificate.replaces invoked an… | |
| Aplazada | Alta (7.7) | 0.31% | — | Netflix LemurAI | 18/8/2026 | 8/9/2026 | Lemur manages TLS certificate creation. Prior to 1.9.3, GET /api/1/destinations and GET /api/1/destinations/ relied only on authentication while sibling write handlers required admin_permission. DestinationOutputSchema returned raw options and copied them into pluginOptions without redacting sensitive values. The… | |
| Aplazada | Alta (7.7) | 0.28% | — | Netflix LemurAI | 18/8/2026 | 8/9/2026 | Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_acme_url enforced ACME_DIRECTORY_HOST_ALLOWLIST when an authority was created, but PUT /api/1/authorities/ passed options to lemur/authorities/service.py without applying the same check. A user holding an authority role could replace the stored acme_url… | |
| Aplazada | Alta (7.4) | 0.22% | — | Netflix LemurAI | 18/8/2026 | 8/9/2026 | Lemur manages TLS certificate creation. Prior to 1.9.3, an authority-role member could update acme_url through PUT /api/1/authorities/ without revalidation and direct setup_acme_client_no_retry to an attacker-controlled ACME server. ACME directory and order responses contain newNonce, newOrder, authorizations, and… | |
| Aplazada | Media (6.3) | 0.18% | — | Netflix LemurAI | 18/8/2026 | 8/9/2026 | Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_revocation_url in lemur/certificates/verify.py checked the original CRL or OCSP URL but the later request could reach a different destination. The CRL requests.get call followed HTTP redirects without validating each Location target, so a public… | |
| Aplazada | Crítica (9.9) | 0.29% | — | Netflix LemurAI | 18/8/2026 | 8/9/2026 | Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url without an effective server-side destination restriction and trigger AcmeHandler.setup_acme_client to make backend requests. An attacker could target cloud instance metadata or internal services from… |