Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 300 respecto a la semana anterior
Críticas / altas1348▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
171 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.24% | — | NanosvgAI | 24/9/2026 | 25/9/2026 | NanoSVG 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__curveDivs() during SVG stroke rasterization. A specially crafted SVG document containing an extremely large stroke-width can cause floating-point rounding to produce a zero subdivision angle. The subsequent arc division yields infinity,… | |
| Aplazada | Alta (7.5) | 0.39% | — | NanosvgAI | 24/9/2026 | 24/9/2026 | NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in the rasterizer's nsvg__addActive() function. A specially crafted SVG document containing sufficiently large geometry coordinates can cause fixed-point-scaled edge coordinates to exceed the range representable by int. The rasterizer… | |
| Aplazada | Sin puntuar | 0.16% | — | NanosvgAI | 24/9/2026 | 24/9/2026 | NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__pathArcTo() when parsing SVG arc commands. A specially crafted SVG document containing extreme arc radius values can cause intermediate arc calculations to produce a NaN delta angle. The function subsequently converts this NaN… | |
| Pendiente de análisis | Alta (8.6) | 0.31% | — | NanomsgAI | 24/9/2026 | 24/9/2026 | Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version header, through snprintf. | |
| Aplazada | Alta (7) | 0.35% | — | Emqx NanomqAI | 18/9/2026 | 24/9/2026 | NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's broker-side MQTT v5 nmq_subinfo_decode() function in nng/src/sp/protocol/mqtt/mqtt_parser.c reuses len_of_varint from the outer Properties Length while parsing each SUBSCRIPTION_IDENTIFIER. A remote client can send a SUBSCRIBE packet with a multi-byte Properties… | |
| Aplazada | Baja (2) | 0.34% | — | Emqx NanomqAI | 18/9/2026 | 18/9/2026 | NanoMQ is an MQTT broker. Prior to 0.24.14, the NanoMQ client function nni_mqtt_msg_decode_unsubscribe() in nng/src/supplemental/mqtt/mqtt_codec.c does not handle a failed read_uint16() while counting topics in a malformed UNSUBSCRIBE packet. A zero-length topic followed by trailing data can leave buf.curpos unchanged… | |
| Aplazada | Baja (3.7) | 0.44% | — | Emqx NanomqAI | 18/9/2026 | 18/9/2026 | NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's MQTT v5 property decoder in nng/src/supplemental/mqtt/mqtt_codec.c uses property_append() to walk the entire linked list for each property added by decode_buf_properties(). A remote unauthenticated client can supply a PUBLISH or SUBSCRIBE packet containing many User… | |
| Aplazada | Crítica (9.2) | 0.45% | — | Hkuds NanobotAI | 16/9/2026 | 17/9/2026 | HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instructing the bot to fetch cloud metadata endpoints, localhost services, and RFC 1918… | |
| Aplazada | Media (6.9) | 0.56% | — | Hkuds NanobotAI | 14/9/2026 | 15/9/2026 | A vulnerability was identified in HKUDS nanobot up to 0.2.1. The affected element is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. Such manipulation leads to argument injection. It is possible to launch the attack remotely. The name of the… | |
| Aplazada | Media (5.3) | 0.41% | — | Hkuds NanobotAI | 14/9/2026 | 14/9/2026 | A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. This manipulation causes incomplete blacklist. It is possible to initiate the attack remotely. Patch name:… | |
| Aplazada | Baja (2.1) | 0.43% | — | Nanoco NanoclawAI | 14/9/2026 | 16/9/2026 | A vulnerability was found in nanocoai NanoClaw up to 2.1.17. This issue affects the function forwardAttachedFiles of the file src/modules/agent-to-agent/agent-route.ts of the component Attachment Handler. The manipulation results in link following. The attack may be performed from remote. The exploit has been made… | |
| Aplazada | Media (4.1) | 0.18% | — | Conprosys Nano SeriesAI | 14/9/2026 | 16/9/2026 | Plaintext storage of a password issue exists in CONPROSYS nano Series . If this vulnerability is exploited, an attacker with physical access to the product may obtain credentials. | |
| Aplazada | Media (5.3) | 0.46% | — | Conprosys Nano SeriesAI | 14/9/2026 | 16/9/2026 | Out-of-bounds write vulnerability exists in CONPROSYS nano Series. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition. | |
| Aplazada | Media (5.1) | 0.24% | — | Conprosys Nano SeriesAI | 14/9/2026 | 16/9/2026 | Cross-site scripting vulnerability exists in CONPROSYS nano Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | |
| Aplazada | Media (5.3) | 0.23% | — | NanoxmlAI | 8/9/2026 | 9/9/2026 | The API is prone to XML external entity (XXE) injection. By default, XML external entity support is enabled. This issue affects NanoXML: 2.2.3. | |
| Aplazada | Alta (8.6) | 0.28% | — | Oxford Nanopore MinknowAI | 2/9/2026 | 8/9/2026 | Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication. | |
| Aplazada | Alta (7.4) | 0.30% | — | NanoidAI | 11/8/2026 | 9/9/2026 | nanoid is a secure, URL-friendly, unique string ID generator for JavaScript. Prior to versions 3.3.12 and 5.1.11, the nanoid(size) function in index.js and index.cjs coerces the user-influenced size parameter to a signed 32-bit integer, allowing a value of 2147483648 to become -2147483648 and corrupt the process-wide… | |
| Aplazada | Baja (2.1) | 0.37% | — | Hkuds NanobotAI | 7/8/2026 | 14/8/2026 | A vulnerability has been found in HKUDS nanobot up to 0.2.1. This affects the function _download_image_data_url of the file nanobot/providers/image_generation.py of the component Provider-returned Image URL Handler. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely.… | |
| Aplazada | Baja (1.9) | 0.17% | — | Hkuds NanobotAI | 7/8/2026 | 12/8/2026 | A flaw has been found in HKUDS nanobot up to 0.2.1. The impacted element is the function ExecTool._prepare_command of the file nanobot/agent/tools/shell.py of the component Login-shell Environment Handler. Executing a manipulation can lead to information disclosure. The attack requires local access. The exploit has… | |
| Aplazada | Baja (2) | 0.47% | — | Hkuds NanobotAI | 7/8/2026 | 12/8/2026 | A vulnerability was detected in HKUDS nanobot up to 0.2.1. The affected element is the function connect_mcp_servers of the file nanobot/agent/tools/mcp.py of the component MCP enabledTools Scope Handler. Performing a manipulation results in improper access controls. The attack is possible to be carried out remotely.… | |
| Aplazada | Baja (2.1) | 2.3% | — | Hkuds NanobotAI | 7/8/2026 | 12/8/2026 | A security vulnerability has been detected in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component Shell Allowlist Handler. Such manipulation leads to os command injection. The attack can be executed remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.37% | — | Nanoco NanoclawAI | 6/8/2026 | 12/8/2026 | A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. Affected is the function handleCreateAgent of the file src/modules/agent-to-agent/create-agent.ts of the component Child-Agent Creation. Performing a manipulation results in improper privilege management. Remote exploitation of the attack is possible. The… | |
| Aplazada | Media (5.5) | 0.61% | — | Nanoco NanoclawAI | 6/8/2026 | 12/8/2026 | A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknown part of the file container/agent-runner/src/mcp-tools/core.ts of the component send_file. Such manipulation leads to path traversal. The attack can be executed remotely. The exploit has been disclosed publicly and may… | |
| Aplazada | Crítica (9.8) | 0.55% | — | NanomodbusAI | 5/8/2026 | 26/8/2026 | nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_identification_basic / recv_read_device_identification_res in nanomodbus.c. A fixed 3-element stack array order[3] = {0,1,2} maps object IDs to buffer indices. The server-supplied object_id field (0-255,… | |
| Aplazada | Alta (8.6) | 0.39% | — | NanomodbusAI | 5/8/2026 | 26/8/2026 | nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus client-side recv_read_device_identification_res function (FC 0x2B/MEI 0x0E, Read Device Identification) in nanomodbus.c. The server-supplied object_length field (0-246) is validated only against the remaining PDU size (res_size_left) and is never… |