Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 48 respecto a la semana anterior
Críticas / altas1479▲ 371 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
231 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.33% | — | Elixir-mint MintAI | 28/9/2026 | 30/9/2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize an intermediary and the Mint client on a pooled connection, poisoning the responses to subsequent requests that share the connection. message_body/1 in… | |
| Aplazada | Media (6.3) | 0.33% | — | Elixir-mint MintAI | 28/9/2026 | 30/9/2026 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server to make the client hold up to about 16 MiB per connection in frames it should reject, consuming client memory. Mint.HTTP2.Frame.decode_next/2 in lib/mint/http2/frame.ex compares a frame with the… | |
| Aplazada | Alta (8.2) | 0.42% | — | Elixir-mint MintAI | 28/9/2026 | 29/9/2026 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server to exhaust memory on the client host and cause a denial of service. Mint.HTTP2 enforces the client's max_header_list_size setting only on the compressed size of an inbound header block, while RFC… | |
| Aplazada | Alta (8.2) | 0.27% | — | ABB Mint WorkbenchAI | 23/9/2026 | 23/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Mint Workbench I. This issue affects Mint Workbench I: through 5876. | |
| Aplazada | Media (6.3) | 0.52% | — | Elixir-mint MintAI | 19/9/2026 | 22/9/2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on a pooled connection, enabling response-queue poisoning against subsequent requests that share the connection.… | |
| Pendiente de análisis | Media (5.5) | 0.28% | — | Mintplexlabs AnythingllmAI | 10/9/2026 | 10/9/2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.16.1 and earlier, the manager role can store meta_page_title or meta_page_favicon through /api/admin/system-preferences, and MetaGenerator inserts those values into production homepage HTML… | |
| Aplazada | Media (4.9) | 0.31% | — | Mail MintAI | 9/9/2026 | 9/9/2026 | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to SQL Injection via the 'status' parameter in all versions up to, and including, 1.31.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Aplazada | Crítica (9.1) | 0.42% | — | Bifrost Vtoken-mintingAIBifrost SlpxAI | 8/9/2026 | 10/9/2026 | The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying that the caller is authorized to mint on behalf of that channel. This allows an… | |
| Aplazada | Crítica (9.8) | 0.66% | — | Mail MintAI | 5/9/2026 | 8/9/2026 | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the 'handle_form_submission' function. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.3) | 0.52% | — | Elixir-mint MintAI | 4/9/2026 | 8/9/2026 | Inefficient Algorithmic Complexity vulnerability in elixir-mint mint allows a remote HTTP server to exhaust CPU on the client host and cause a denial of service. parse_hex_prefix/2 in lib/mint/http1/parse.ex folds each hex digit of a chunked response's chunk-size field into an arbitrary-precision accumulator with acc… | |
| Aplazada | Alta (8.2) | 0.52% | — | Elixir-mint MintAI | 4/9/2026 | 8/9/2026 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a remote HTTP server to exhaust memory on the client host and cause a denial of service. Two HTTP/1 response-parser states accumulate server data without any cap. In lib/mint/http1.ex, decode_status_line/4 stores the… | |
| Aplazada | Media (5.3) | 0.46% | — | PeppermintAI | 3/9/2026 | 9/9/2026 | Peppermint through 0.5.5 contains an authorization bypass vulnerability in the GET /api/v1/auth/user/:id/logout endpoint that allows authenticated attackers to delete sessions for any user by supplying arbitrary user IDs. Attackers can forcibly log out any user including administrators by calling the logout handler… | |
| Aplazada | Crítica (9.3) | 0.64% | — | PeppermintAI | 3/9/2026 | 9/9/2026 | Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user IDs and access protected endpoints without credentials. | |
| Aplazada | Media (6.5) | 0.27% | — | Mail MintAI | 3/9/2026 | 3/9/2026 | Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Mail MintAI | 3/9/2026 | 5/9/2026 | Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions. | |
| Aplazada | Alta (8.8) | 0.42% | — | PeppermintAI | 11/8/2026 | 3/9/2026 | A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-administrative user to reconfigure the platform global OIDC/SSO settings via an unprotected configuration endpoint. The endpoint performs no administrative role check before applying new OIDC issuer… | |
| Aplazada | Alta (8.1) | 0.37% | — | PeppermintAI | 11/8/2026 | 3/9/2026 | A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 exists because the Config.roles_active flag defaults to false, causing all permission checks on ticket, client, and user handlers to behave as no-ops on default installations. All authenticated users bypass ownership and… | |
| Aplazada | Media (5.9) | 0.35% | — | Mintplexlabs AnythingllmAI | 10/8/2026 | 18/9/2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.0.0 to 1.15.0, AnythingLLM's unauthenticated account-recovery flow in server/utils/PasswordRecovery/index.js uses recoverAccount() to deduplicate the raw recoveryCodes values before… | |
| Aplazada | Media (4.3) | 0.39% | — | Advancedformintegration Advanced Form IntegrationAI | 28/7/2026 | 28/7/2026 | The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.3) | 0.52% | — | Elixir MintAI | 16/7/2026 | 16/7/2026 | Inconsistent interpretation of HTTP requests (HTTP response smuggling) vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on the same pooled connection, enabling response-queue poisoning against subsequent requests that share the connection.… | |
| Aplazada | Media (6.3) | 0.50% | — | Elixir-mint MintAI | 14/7/2026 | 15/7/2026 | Allocation of resources without limits vulnerability in elixir-mint mint allows a remote HTTP/2 server to exhaust memory on the client host and cause a denial of service. The Mint.HTTP2.handle_continuation/3 function in lib/mint/http2.ex accumulates the header-block fragment carried by each HTTP/2 CONTINUATION frame… | |
| Aplazada | Alta (8.2) | 0.50% | — | Elixir MintAI | 14/7/2026 | 15/7/2026 | Allocation of resources without limits vulnerability in elixir-mint mint allows a remote HTTP server to exhaust memory on the client host and cause a denial of service. The Mint.HTTP1.decode_headers/5 and Mint.HTTP1.decode_trailer_headers/4 functions in lib/mint/http1.ex accumulate every parsed response header and… | |
| Aplazada | Media (4.9) | 0.51% | — | Mail MintAI | 10/7/2026 | 14/7/2026 | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to generic SQL Injection via the 'recipients' parameter in all versions up to, and including, 1.24.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on… | |
| Aplazada | Media (4.9) | 0.44% | — | Mailmint Mail MintAI | 9/7/2026 | 9/7/2026 | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to time-based SQL Injection via the 'contact_ids' parameter in all versions up to, and including, 1.24.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation… | |
| Aplazada | Alta (8.7) | 0.55% | — | Elixir-mint HpaxAI | 6/7/2026 | 6/7/2026 | Inefficient Algorithmic Complexity vulnerability in elixir-mint hpax allows unauthenticated denial-of-service via unbounded HPACK integer decoding. hpax decodes HPACK variable-length integers with no upper bound on the decoded value or the number of continuation octets. 'Elixir.HPAX.Types':decode_remaining_integer/3… |