Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 301 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.54% | — | Leandrocp MdexAI | 29/6/2026 | 30/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in leandrocp mdex allows cross-site scripting via unsanitized URL schemes in Quill Delta output. 'Elixir.MDEx':to_delta/2 converts Markdown into a Quill Delta. 'Elixir.MDEx.DeltaConverter':default_convert_node/3 in… | |
| Aplazada | Media (6.9) | 0.24% | — | Leandrocp MdexAILeandrocp Mdex NativeAI | 29/6/2026 | 30/6/2026 | Uncontrolled Recursion vulnerability in leandrocp mdex allows denial of service via deeply nested Markdown input. mdex converts between an Elixir %MDEx.Document{} struct and Comrak's internal AST using two mutually recursive Rust functions, ex_document_to_comrak_ast and comrak_ast_to_ex_document, in the NIF source… | |
| Aplazada | Media (6.9) | 0.18% | — | Leandrocp MdexAILeandrocp Mdex NativeAI | 29/6/2026 | 30/6/2026 | Missing Release of Memory after Effective Lifetime vulnerability in leandrocp mdex and mdex_native allows an attacker who controls a rendered document to cause a denial of service through unbounded native memory exhaustion. The native rendering code permanently leaks memory when rendering a document that contains… | |
| Aplazada | Alta (8.2) | 0.18% | — | Leandrocp MdexAI | 29/6/2026 | 30/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in leandrocp MDEx allows Excessive Allocation. MDEx.parse_document/2 accepts a {:json, json} source. In lib/mdex.ex, the private json_to_node/1 function passes the attacker-controlled node_type value to Module.concat/1, which calls String.to_atom/1 and… | |
| Aplazada | Media (6.9) | 0.18% | — | Leandrocp MdexAILeandrocp Mdex NativeAI | 29/6/2026 | 29/6/2026 | Memory Allocation with Excessive Size Value vulnerability in leandrocp mdex allows an unauthenticated attacker to cause a denial of service through unbounded memory allocation. comrak_nif::lumis_adapter::LumisAdapter::parse_highlight_lines in native/comrak_nif/src/lumis_adapter.rs eagerly expands a user-controlled… | |
| Aplazada | Baja (2.3) | 0.69% | — | Leandrocp MdexAILeandrocp Mdex NativeAI | 29/6/2026 | 29/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in leandrocp MDEx allows stored or reflected cross-site scripting via attacker-controlled Markdown. When syntax highlighting and full info-string forwarding (render: [full_info_string: true]) are enabled, the Lumis… | |
| Modificada | Media (6.1) | 0.86% | — | Ximdex | 13/6/2018 | 17/6/2026 | The /edit URI in the DMS component in Ximdex 4.0 has XSS via the Ciudad or Nombre parameter. | |
| Modificada | Media (6.1) | 0.86% | — | Ximdex | 13/6/2018 | 17/6/2026 | xowl/request.php in Ximdex 4.0 has XSS via the content parameter. | |
| Modificada | Media (6.1) | 0.86% | — | Ximdex | 8/6/2018 | 17/6/2026 | xfind/search in Ximdex 4.0 has XSS via the filter[n][value] parameters for non-negative values of n, as demonstrated by n equal to 0 through 12. | |
| Modificada | Media (6.1) | 0.82% | — | Ximdex | 5/6/2018 | 17/6/2026 | index.php?action=createaccount in Ximdex 4.0 has XSS via the sname or fname parameter. |