Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2748▲ 38 respecto a la semana anterior
Críticas / altas1479▲ 369 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

1316 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.3)——Vercel Next.jsAI2/10/20262/10/2026
Next.js is a React framework for building full-stack web applications. From 16.3.0 until 16.3.8, pending use cache fills for the same key are shared without separating Draft Mode requests from regular requests. An overlapping regular request can receive unauthenticated unpublished content from an editor's Draft Mode…
Pendiente de análisisMedia (6.3)——Vercel Next.jsAI2/10/20262/10/2026
Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated or Incremental Static Regeneration pages can key a response cache entry without sufficiently binding it to the source route. A request…
Pendiente de análisisBaja (2.3)——Vercel Next.jsAI2/10/20262/10/2026
Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the next dev development server exposes a Model Context Protocol endpoint without reliably restricting cross-site requests. A malicious website visited by a developer can reach the endpoint and read the project's disk…
Pendiente de análisisMedia (6.3)——Vercel Next.jsAI2/10/20262/10/2026
Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the `next dev` development server exposes a Model Context Protocol endpoint without reliably restricting cross-site requests. A malicious website visited by a developer can reach the endpoint and read the project's disk…
Pendiente de análisisMedia (6.3)——Vercel Next.jsAI2/10/20262/10/2026
Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, applications with a root-level catch-all page and statically generated or Incremental Static Regeneration routes can use a shared response cache key that is insufficiently scoped to the source route. A single…
Pendiente de análisisAlta (8.3)——Vercel Next.jsAI2/10/20262/10/2026
Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, Image Optimization can follow attacker-controlled DNS resolution for a remote URL that matches images.remotePatterns, allowing the optimized image fetch to reach private IP addresses after the URL passes the allow-list…
Pendiente de análisisMedia (6.3)0.32%—Vercel Next.jsAI1/10/20262/10/2026
Next.js versions from 16.3.0 to 16.3.7 warm `use cache` handlers using `next/root-params` and can leak their return value to pages with different root params. With Cache Components enabled (cacheComponents: true), a 'use cache' function that calls another 'use cache' function that reads a root param can be keyed…
AplazadaAlta (7.5)0.40%—Nextgen GalleryAI30/9/202630/9/2026
Unauthenticated Arbitrary File Download in NextGEN Gallery <= 4.5.0 versions.
AplazadaMedia (6.4)0.16%—Nextendweb Smart Slider 3AI30/9/202630/9/2026
The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-href' parameter in all versions up to, and including, 3.5.1.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to…
AplazadaMedia (6.9)0.50%—Notionnext-org NotionnextAI28/9/202628/9/2026
A security vulnerability has been detected in notionnext-org NotionNext up to 4.10.10. Affected by this issue is the function cleanCache of the file pages/api/cache.js of the component Authentication Guard. The manipulation of the argument token leads to missing authentication. The attack may be initiated remotely.…
AplazadaMedia (5.9)0.19%—Nextscripts Social Networks Auto PosterAI27/9/202628/9/2026
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an administrator has granted access to its posting features to export the site's configured social account credentials,…
AplazadaMedia (5.3)0.22%—Frappe ErpnextAI23/9/202629/9/2026
Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values reference whitelisted methods before passing them to frappe.call(). Accounts Managers can supply arbitrary dotted Python paths to invoke non-whitelisted internal server-side methods and read their return…
Pendiente de análisisAlta (7.7)0.38%—RTI Connext ProfessionalAI22/9/202623/9/2026
Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation. This issue affects Connext Professional: from 7.6.0 before 7.7.0.1.
Pendiente de análisisCrítica (10)0.31%—RTI Connext ProfessionalAI22/9/202623/9/2026
Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, from 4.3x…
Pendiente de análisisMedia (6.8)0.10%—RTI Connext ProfessionalAI22/9/202622/9/2026
Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, from 5.0.0 before…
Pendiente de análisisAlta (7.3)0.08%—RTI Connext ProfessionalAI22/9/202622/9/2026
Integer Overflow or Wraparound, Improper Access Control vulnerability in RTI Connext Professional (Core Libraries) allows Shared Resource Manipulation. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*.
Pendiente de análisisCrítica (9.2)0.21%—RTI Connext ProfessionalAI22/9/202622/9/2026
Use of Externally-Controlled Format String vulnerability in RTI Connext Professional (Core Libraries) allows Format String Injection. This issue affects Connext Professional: from 7.5.0 before 7.7.0.1, from 7.3.0.10 before 7.3.1.6.
Pendiente de análisisMedia (6.9)0.25%—RTI Connext ProfessionalAI22/9/202622/9/2026
Off-by-one Error, Out-of-bounds Write vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6.
Pendiente de análisisAlta (8.7)0.25%—RTI Connext ProfessionalAI22/9/202622/9/2026
Incorrect Calculation vulnerability in RTI Connext Professional (Core Libraries) allows Abuse Existing Functionality. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, from…
Pendiente de análisisMedia (6.8)0.10%—RTI Connext ProfessionalAI22/9/202622/9/2026
Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.3.0 before 7.3.1.6, from…
Pendiente de análisisAlta (8.3)0.26%—RTI Connext ProfessionalAI22/9/202622/9/2026
Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.3 before 5.2.*.
Pendiente de análisisMedia (6.8)0.10%—RTI Connext ProfessionalAI22/9/202622/9/2026
Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.3.0 before 7.3.1.6.
Pendiente de análisisMedia (6.9)0.10%—RTI Connext ProfessionalAI22/9/202622/9/2026
Double Free vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.1.0 before 7.3.1.6.
AplazadaAlta (7.1)0.42%—Frappe ErpnextAI20/9/202621/9/2026
Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authenticated attackers can call get_projectwise_timesheet_data, get_timesheet_detail_rate, and get_timesheet endpoints to…
AplazadaMedia (4.3)0.27%—Nextcloud DeckAI18/9/202618/9/2026
The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission to manage the referenced board.