Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

45 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.60%—Ntop NdpiAI24/9/202624/9/2026
nDPI 5.1.0 contains a memory access issue in the DNS dissector and serializer deserialization code. Specially crafted network input can cause byte-buffer addresses at odd offsets to be cast to uint16_t or wider integer pointers and directly dereferenced without alignment checks. This results in undefined behavior and…
AplazadaAlta (8.6)0.27%—BentopdfAI24/9/202629/9/2026
BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, the certificate and timestamp CORS proxy in cloudflare/cors-proxy-worker.js uses isPrivateOrReservedHost() to validate a supplied hostname separately from the DNS resolution used by fetch(targetUrl), allowing an attacker-controlled…
AplazadaBaja (3.4)0.31%—BentopdfAI24/9/202630/9/2026
BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, deserializeWorkflow() accepts the Timestamp node's tsaUrl control from imported JSON without schema or destination validation. When a user imports the crafted workflow and runs it against a PDF, timestampPdf() sends an RFC 3161…
AplazadaAlta (8.8)0.33%—NtopngAI21/9/202629/9/2026
ntopng is a web-based network traffic monitoring application. Prior to 6.7.260718, scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua and scripts/lua/rest/v2/get/system/configurations/download_backup.lua allow any authenticated non-admin user to list and download system-configuration backups…
AplazadaAlta (8.1)0.53%—NtopngAI21/9/202623/9/2026
ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_blacklist.lua in scripts/lua/rest/v2/edit/system/edit_blacklist.lua lacks an administrator check and calls lists_utils.editList for any authenticated user. The list_name, list_enabled, url, and…
AplazadaAlta (8.8)0.65%—NtopngAI21/9/202623/9/2026
ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability-scan endpoints scripts/lua/rest/v2/add/host/to_scan.lua and scripts/lua/rest/v2/exec/host/schedule_vulnerability_scan.lua accept the scan_ports parameter without an administrator gate and pass it through…
AplazadaAlta (8.3)0.59%—Ntop NdpiAI4/9/202623/9/2026
ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Attackers can trigger the overflow by supplying crafted network packet data including TLS SNI, HTTP headers, or DNS names that reach the vulnerable…
AplazadaAlta (7.1)0.52%—NtopngAI4/9/202623/9/2026
ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings. Attackers can issue POST requests to the delete pools endpoint to irreversibly destroy every host pool, removing traffic policy bindings and…
AplazadaAlta (7.1)0.45%—NtopngAI4/9/202623/9/2026
ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured notification endpoints and recipients, silencing all alerts.
AplazadaAlta (7.1)0.38%—NtopngAI3/9/20269/9/2026
ntopng is a web-based network traffic monitoring application. In versions 6.7.0 through 6.7.260717, two REST v2 endpoints that manage ntopng's tag/badge feature — `POST /lua/rest/v2/delete/tag/tag.lua` and `POST /lua/rest/v2/edit/tag/tag.lua` — perform no authorization check at all. Any authenticated user, including a…
AnalizadaAlta (8.8)0.63%—Tugcantopaloglu Openclaw Agent Dashboard30/7/20263/9/2026
OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages processed through the sessions API. Attackers can craft a message…
AnalizadaCrítica (9.3)0.63%—Tugcantopaloglu Openclaw Agent Dashboard30/7/20263/9/2026
OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is recorded verbatim in the audit log. When an administrator opens the…
AplazadaAlta (7.1)0.25%—Flintop Free-gifts-for-woocommerceAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Flintop Free Gifts for WooCommerce free-gifts-for-woocommerce allows Stored XSS.This issue affects Free Gifts for WooCommerce: from n/a through <= 13.1.0.
AplazadaBaja (1.9)0.17%—Tugcantopaloglu Godot-mcpAI13/7/202613/7/2026
A security flaw has been discovered in tugcantopaloglu godot-mcp 2.0.0. Affected by this vulnerability is the function validatePath of the file build/index.js of the component run_project. The manipulation of the argument projectPath results in path traversal. Attacking locally is a requirement. The exploit has been…
AnalizadaCrítica (9.8)0.55%—Ntopng2/7/20268/7/2026
ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under…
AplazadaAlta (7)0.46%—BentopdfAI7/5/202617/6/2026
BentoPDF is a client-side PDF toolkit that is self hostable. Prior to version 2.8.3, a cross-site scripting vulnerability was identified in BentoPD. An attacker may be able to execute arbitrary JavaScript in certain circumstances in Markdown to PDF Tool. This issue has been patched in version 2.8.3.
AnalizadaAlta (7.1)0.27%—Tiefpunkt Meintopf20/3/202517/6/2026
The mEintopf WordPress plugin through 0.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
AnalizadaAlta (8.4)0.18%—Ntop Ndpi3/2/202517/6/2026
nDPI through 4.12 has a potential stack-based buffer overflow in ndpi_address_cache_restore in lib/ndpi_cache.c.
AplazadaAlta (7.1)0.39%—Markugwuanyi Contentoptin LiteAI22/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in markugwuanyi ContentOptin Lite contentoptin allows Reflected XSS.This issue affects ContentOptin Lite: from n/a through <= 1.1.
AplazadaMedia (6.2)0.29%—NtopngAI21/11/202417/6/2026
A heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function.
ModificadaMedia (5.4)0.31%—Chrisyee Momentopress FOR Momento3606/11/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Chris Yee MomentoPress for Momento360 plugin <= 1.0.1 versions.
ModificadaAlta (8.8)1.8%—Ntop Ndpi1/7/202117/6/2026
ntop nDPI 3.4 has a stack-based buffer overflow in processClientServerHello.
ModificadaAlta (7.5)2.1%—Ntop NdpiDebian Linux1/7/202017/6/2026
In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c.
ModificadaCrítica (9.8)1.2%—Ntop Ndpi1/7/202017/6/2026
In nDPI through 3.2, ndpi_reset_packet_line_info in lib/ndpi_main.c omits certain reinitialization, leading to a use-after-free.
ModificadaCrítica (9.8)1.2%—Ntop Ndpi1/7/202017/6/2026
In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c.