Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
65 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.3) | 0.52% | — | Ninenines CowlibAI | 18/8/2026 | 16/9/2026 | Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header directive smuggling via unescaped special characters in cow_link:link/1. cow_link:do_link/1 in cowlib interpolates the target URI, rel value, and attribute keys directly into the serialized Link: header value without escaping… | |
| Aplazada | Media (6.9) | 0.67% | — | Ninenines CowboyAI | 28/7/2026 | 30/7/2026 | Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an unauthenticated remote attacker to exhaust connection process memory over HTTP/1.1. The HTTP/1.1 handler in cowboy_http enforces the max_headers limit by counting the number of distinct header names in a map… | |
| Aplazada | Alta (8.7) | 0.51% | — | Ninenines CowlibAINinenines CowboyAIRabbitmqAI | 28/7/2026 | 30/7/2026 | Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP/3 peer to exhaust memory on the vulnerable server (or client) and cause a denial of service. The HPACK and QPACK prefixed-integer decoder cow_hpack_common:dec_big_int/3 in src/cow_hpack_common.hrl… | |
| Analizada | Media (6.3) | 0.43% | — | Ninenines Cowlib | 8/6/2026 | 17/8/2026 | Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in ninenines cowlib allows HTTP response splitting via non-VCHAR bytes in structured-fields string values. cow_http_struct_hd:escape_string/2 in cowlib only escapes \ and ", passing all other bytes through… | |
| Analizada | Alta (8.7) | 0.64% | — | Ninenines GUN | 8/6/2026 | 18/8/2026 | Unexpected Status Code or Return Value vulnerability in ninenines gun (gun_http module) allows a malicious HTTP server to force the client into raw protocol mode via an unsolicited 101 Switching Protocols response. In gun_http:handle_inform/8, when a 101 Switching Protocols response is received over HTTP/1.1, the… | |
| Analizada | Alta (8.7) | 0.64% | — | Ninenines GUN | 8/6/2026 | 18/8/2026 | Uncontrolled Resource Consumption vulnerability in ninenines gun (gun_http module) allows a malicious server to exhaust client memory via unbounded HTTP/1.1 response buffering. In gun_http:handle/5, three clauses accumulate incoming TCP data into the connection's buffer field using binary concatenation with no… | |
| Analizada | Media (6.3) | 0.20% | — | Ninenines GUN | 8/6/2026 | 18/8/2026 | Origin Validation Error vulnerability in ninenines gun (gun_http2 module) allows cross-origin cookie injection via unvalidated HTTP/2 PUSH_PROMISE authority. In gun_http2:push_promise_frame/7, the :authority pseudo-header from an incoming PUSH_PROMISE frame is stored verbatim into the promised stream record without… | |
| Aplazada | Alta (8.2) | 0.53% | — | Ninenines CowboyAI | 13/5/2026 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows denial of service via unbounded buffer accumulation in multipart header parsing. cowboy_req:read_part/3 in src/cowboy_req.erl accumulates incoming request bytes into a Buffer binary with no upper-bound check. When… | |
| Aplazada | Alta (8.2) | 0.64% | — | Ninenines CowlibAI | 13/5/2026 | 17/6/2026 | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in ninenines cowlib allows unauthenticated remote denial of service via memory exhaustion. cow_spdy:inflate/2 in cowlib passes peer-supplied compressed bytes directly to zlib:inflate/2 with no output size bound. The SPDY header compression… | |
| Analizada | Alta (8.7) | 0.79% | — | Ninenines Cowlib | 11/5/2026 | 17/6/2026 | Uncontrolled Resource Consumption vulnerability in ninenines cowlib (cow_http_te module) allows Excessive Allocation. The chunked transfer-encoding parser in cow_http_te accepts an unbounded number of hex digits in the chunk-size field. Each digit causes a bignum multiplication (Len * 16 + digit), so parsing N hex… | |
| Modificada | Baja (2.1) | 0.21% | — | Ninenines Cowlib | 11/5/2026 | 18/8/2026 | Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request splitting and cookie smuggling via unvalidated cookie name and value fields. cow_cookie:cookie/1 in cowlib builds a client-side Cookie: request header from a list of name-value pairs without validating… | |
| Analizada | Media (6.3) | 0.46% | — | Ninenines Cowlib | 11/5/2026 | 17/6/2026 | Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows SSE event splitting and injection via unvalidated field values. cow_sse:event/1 in cowlib guards the id and event fields against \n but not against bare \r, and the internal prefix_lines/2 function used for data and… | |
| Analizada | Media (5.3) | 0.19% | — | CGM Clininet | 2/3/2026 | 17/6/2026 | The CGM CLININET application respond without essential security HTTP headers, exposing users to client‑side attacks such as clickjacking, MIME sniffing, unsafe caching, weak cross‑origin isolation, and missing transport security controls. | |
| Analizada | Media (5.3) | 0.18% | — | CGM Clininet | 2/3/2026 | 17/6/2026 | The CGM CLININET application does not implement any mechanisms that prevent clickjacking attacks, neither HTTP security headers nor HTML-based frame‑busting protections were detected. As a result, an attacker can embed the application inside a maliciously crafted IFRAME and trick users into performing unintended… | |
| Analizada | Alta (7.1) | 0.22% | — | CGM Clininet | 2/3/2026 | 17/6/2026 | The CGM CLININET application uses direct, sequential object identifiers "MessageID" without proper authorization checks. By modifying the parameter in the GET request, an attacker can access messages and attachments belonging to other users. | |
| Aplazada | Crítica (9.4) | 0.57% | — | CGM ClininetAI | 2/3/2026 | 17/6/2026 | In the endpoints "/cgi-bin/CliniNET.prd/utils/usrlogstat_simple.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", "/cgi-bin/CliniNET.prd/utils/userlogstat2.pl", and "/cgi-bin/CliniNET.prd/utils/dblogstat.pl", the parameters are not sufficiently normalized, which enables code injection. | |
| Analizada | Crítica (9) | 0.09% | — | CGM Clininet | 2/3/2026 | 17/6/2026 | The CGM CLININET system provides smart card authentication; however, authentication is conducted locally on the client device, and, in reality, only the certificate number is used for access verification. As a result, possession of the certificate number alone is sufficient for authentication, regardless of the actual… | |
| Aplazada | Crítica (9) | 0.26% | — | CGM ClininetAI | 2/3/2026 | 17/6/2026 | The vulnerability enables an attacker to fully bypass authentication in CGM CLININET and gain access to any active user account by supplying only the username, without requiring a password or any other credentials. Obtaining a session ID is sufficient for session takeover and grants access to the system with the… | |
| Aplazada | Alta (8.8) | 0.19% | — | CGM NetraadAICGM ClininetAI | 2/3/2026 | 17/6/2026 | SQL Injection vulnerability in "imageserver" module when processing C-FIND queries in CGM NETRAAD software allows attacker connected to PACS gaining access to database, including data processed by GCM CLININET software.This issue affects CGM NETRAAD with imageserver module in versions before 7.9.0. | |
| Aplazada | Media (6.5) | 0.35% | — | Ninetheme ElectronAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Ninetheme Electron electron allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Electron: from n/a through <= 1.8.2. | |
| Aplazada | Alta (8.1) | 0.64% | — | Ninetheme AnarkaliAI | 22/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ninetheme Anarkali anarkali allows PHP Local File Inclusion.This issue affects Anarkali: from n/a through <= 1.0.9. | |
| Aplazada | Crítica (9) | 0.18% | — | CGM ClininetAI | 27/8/2025 | 17/6/2026 | The paths "/cgi-bin/CliniNET.prd/utils/userlogstat.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", and "/cgi-bin/CliniNET.prd/utils/dblogstat.pl" expose data containing session IDs. | |
| Aplazada | Crítica (9) | 0.18% | — | Clininetworks ClininetworkAI | 27/8/2025 | 17/6/2026 | Unauthenticated access to the "/cgi-bin/CliniNET.prd/GetActiveSessions.pl" endpoint allows takeover of any user session logged into the system, including users with admin privileges. | |
| Aplazada | Alta (7.3) | 0.17% | — | CGM ClininetAIMicrosoft WindowsAI | 27/8/2025 | 17/6/2026 | The vulnerability consists of a session ID leak when saving a file downloaded from CGM CLININET. The identifier is exposed through a built-in Windows security feature that stores additional metadata in an NTFS alternate data stream (ADS) for all files downloaded from potentially untrusted sources. | |
| Analizada | Media (4.8) | 0.61% | — | Jupo Mezzanine | 23/7/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the component /blog/blogpost/add of Mezzanine CMS v6.1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into a blog post. |