Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2564▼ 301 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

10 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.1)0.54%—Leandrocp MdexAI29/6/202630/6/2026
Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in leandrocp mdex allows cross-site scripting via unsanitized URL schemes in Quill Delta output. 'Elixir.MDEx':to_delta/2 converts Markdown into a Quill Delta. 'Elixir.MDEx.DeltaConverter':default_convert_node/3 in…
AplazadaMedia (6.9)0.24%—Leandrocp MdexAILeandrocp Mdex NativeAI29/6/202630/6/2026
Uncontrolled Recursion vulnerability in leandrocp mdex allows denial of service via deeply nested Markdown input. mdex converts between an Elixir %MDEx.Document{} struct and Comrak's internal AST using two mutually recursive Rust functions, ex_document_to_comrak_ast and comrak_ast_to_ex_document, in the NIF source…
AplazadaMedia (6.9)0.18%—Leandrocp MdexAILeandrocp Mdex NativeAI29/6/202630/6/2026
Missing Release of Memory after Effective Lifetime vulnerability in leandrocp mdex and mdex_native allows an attacker who controls a rendered document to cause a denial of service through unbounded native memory exhaustion. The native rendering code permanently leaks memory when rendering a document that contains…
AplazadaAlta (8.2)0.18%—Leandrocp MdexAI29/6/202630/6/2026
Allocation of Resources Without Limits or Throttling vulnerability in leandrocp MDEx allows Excessive Allocation. MDEx.parse_document/2 accepts a {:json, json} source. In lib/mdex.ex, the private json_to_node/1 function passes the attacker-controlled node_type value to Module.concat/1, which calls String.to_atom/1 and…
AplazadaMedia (6.9)0.18%—Leandrocp MdexAILeandrocp Mdex NativeAI29/6/202629/6/2026
Memory Allocation with Excessive Size Value vulnerability in leandrocp mdex allows an unauthenticated attacker to cause a denial of service through unbounded memory allocation. comrak_nif::lumis_adapter::LumisAdapter::parse_highlight_lines in native/comrak_nif/src/lumis_adapter.rs eagerly expands a user-controlled…
AplazadaBaja (2.3)0.69%—Leandrocp MdexAILeandrocp Mdex NativeAI29/6/202629/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in leandrocp MDEx allows stored or reflected cross-site scripting via attacker-controlled Markdown. When syntax highlighting and full info-string forwarding (render: [full_info_string: true]) are enabled, the Lumis…
ModificadaMedia (6.1)0.86%—Ximdex13/6/201817/6/2026
The /edit URI in the DMS component in Ximdex 4.0 has XSS via the Ciudad or Nombre parameter.
ModificadaMedia (6.1)0.86%—Ximdex13/6/201817/6/2026
xowl/request.php in Ximdex 4.0 has XSS via the content parameter.
ModificadaMedia (6.1)0.86%—Ximdex8/6/201817/6/2026
xfind/search in Ximdex 4.0 has XSS via the filter[n][value] parameters for non-negative values of n, as demonstrated by n equal to 0 through 12.
ModificadaMedia (6.1)0.82%—Ximdex5/6/201817/6/2026
index.php?action=createaccount in Ximdex 4.0 has XSS via the sname or fname parameter.