Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 302 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.70% | — | Will-moss IsaiahAI | 13/7/2026 | 15/7/2026 | A vulnerability has been found in will-moss Isaiah up to 1.36.9. This affects an unknown function of the file app/main.go of the component Websocket Connection Authentication. The manipulation leads to improper authentication. The attack can be initiated remotely. The pull request to fix this issue awaits acceptance. | |
| Aplazada | Media (6.9) | 0.54% | — | Will-moss IsaiahAI | 13/7/2026 | 13/7/2026 | A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file app/server/server/server.go of the component Master Websocket Handler. Executing a manipulation of the argument Agent can lead to missing authorization. It is possible to launch the attack remotely.… | |
| Analizada | Alta (8.2) | 0.41% | — | Rezmoss Axios4go | 7/1/2026 | 17/6/2026 | axios4go is a Go HTTP client library. Prior to version 0.6.4, a race condition vulnerability exists in the shared HTTP client configuration. The global `defaultClient` is mutated during request execution without synchronization, directly modifying the shared `http.Client`'s `Transport`, `Timeout`, and `CheckRedirect`… | |
| Aplazada | Media (5.9) | 0.18% | — | Alex Moss Google-plus-commentsAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Moss Google+ Comments google-plus-comments allows Stored XSS.This issue affects Google+ Comments: from n/a through <= 1.0. | |
| Aplazada | Media (5.9) | 0.22% | — | Mosswebworks MWW Disclaimer ButtonsAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jennifer Moss MWW Disclaimer Buttons mww-disclaimer-buttons allows Stored XSS.This issue affects MWW Disclaimer Buttons: from n/a through <= 3.41. | |
| Analizada | Baja (2.1) | 0.38% | — | Mossle Lemon | 25/8/2025 | 17/6/2026 | A weakness has been identified in xuhuisheng lemon up to 1.13.0. This affects the function uploadImage of the file CmsArticleController.java of the component com.mossle.cms.web.CmsArticleController.uploadImage. This manipulation of the argument Upload causes unrestricted upload. The attack can be initiated remotely.… | |
| Aplazada | Alta (8.6) | 0.28% | — | Deep-project MossAI | 21/8/2025 | 17/6/2026 | Moss before v0.15 has a file upload vulnerability. The "upload" function configuration allows attackers to upload files of any extension to any location on the target server. | |
| Aplazada | Media (6.5) | 0.27% | — | Alex Moss Peadig Google +1 ButtonAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Moss Peadig’s Google +1 Button google-1 allows DOM-Based XSS.This issue affects Peadig’s Google +1 Button: from n/a through <= 0.1.2. | |
| Analizada | Crítica (9.8) | 0.43% | — | Deep-project Moss | 3/2/2025 | 17/6/2026 | Moss v0.1.3 version has an SQL injection vulnerability that allows attackers to inject carefully designed payloads into the order parameter. | |
| Modificada | Media (4.8) | 0.34% | — | Mosswebworks MWW Disclaimer Buttons | 15/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moss Web Works MWW Disclaimer Buttons allows Stored XSS.This issue affects MWW Disclaimer Buttons: from n/a through 3.0.2. | |
| Modificada | Media (6.1) | 0.72% | — | Mossle Lemon | 22/12/2021 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the Editing component of lemon V1.10.0 allows attackers to execute arbitrary web scripts or HTML. | |
| Modificada | Media (6.1) | 0.72% | — | Mossle Lemon | 22/12/2021 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the potrtalItemName parameter in \web\PortalController.java of lemon V1.10.0 allows attackers to execute arbitrary web scripts or HTML. | |
| Modificada | Media (5.4) | 0.72% | — | Buddyboss Buddymoss Media | 9/9/2019 | 17/6/2026 | The buddyboss-media plugin through 3.2.3 for WordPress has stored XSS. | |
| Modificada | Alta (7.5) | 1.2% | — | Mossle Lemon | 15/10/2018 | 17/6/2026 | com/mossle/cdn/CdnController.java in lemon 1.9.0 allows attackers to upload arbitrary files because the copyMultipartFileToFile method in CdnUtils only checks for a ../ substring, and does not validate the file type and spaceName parameter. | |
| Modificada | Alta (10) | 12% | — | Andromede AdromedeircdDaniel Moss MethaneHans Westerhof DigatechWenet Ircd-ru+1 | 7/8/2003 | 16/6/2026 | Format string vulnerability in (1) Bahamut IRCd 1.4.35 and earlier, and other IRC daemons based on Bahamut including (2) digatech 1.2.1, (3) methane 0.1.1, (4) AndromedeIRCd 1.2.3-Release, and (5) ircd-RU, when running in debug mode, allows remote attackers to cause a denial of service and possibly execute arbitrary… |