Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.5) | 0.41% | — | Copier-org CopierAI | 15/9/2026 | 2/10/2026 | A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing malicious symlinks can escape the target extraction directory and create files outside the intended destination. Buildah itself uses chroot hardening and is not affected. | |
| Aplazada | Alta (7.5) | 0.44% | — | Copier-org CopierAI | 31/7/2026 | 9/9/2026 | Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-directory segments or encoded path separators in a template URL can match a configured trusted repository prefix before an HTTP server or Git transport decodes the path, allowing unsafe template features… | |
| Aplazada | Alta (8.8) | 0.26% | — | Copier-org CopierAI | 8/7/2026 | 10/7/2026 | Copier is a library and CLI app for rendering project templates. In versions 9.5.0 through 9.15.1, the `trust` setting's prefix match (`copier/_settings.py`) compares the template URL against a trusted prefix with a raw `str.startswith` and no path normalization, while the URL is normalized when the template is… | |
| Analizada | Media (5.5) | 0.21% | — | Copier-org Copier | 2/4/2026 | 24/7/2026 | Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are… | |
| Analizada | Media (4.4) | 0.37% | — | Copier-org Copier | 2/4/2026 | 24/7/2026 | Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template… | |
| Analizada | Media (6.9) | 0.26% | — | Copier-org Copier | 21/1/2026 | 17/6/2026 | Copier is a library and CLI app for rendering project templates. Prior to version 9.11.2, Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the `--UNSAFE,--trust` flag. As it turns out, a safe… | |
| Analizada | Media (6.8) | 0.24% | — | Copier-org Copier | 21/1/2026 | 17/6/2026 | Copier is a library and CLI app for rendering project templates. Prior to version 9.11.2, Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the `--UNSAFE,--trust` flag. As it turns out, a safe… | |
| Aplazada | Media (4.4) | 0.18% | — | WP Delete Post CopiesAI | 21/11/2025 | 30/9/2026 | The WP Delete Post Copies plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to… | |
| Aplazada | Media (6.9) | 0.26% | — | Copier-org CopierAI | 18/8/2025 | 17/6/2026 | Copier library and CLI app for rendering project templates. From 7.1.0 to before 9.9.1, Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the --UNSAFE,--trust flag. As it turns out, a safe… | |
| Aplazada | Alta (8.5) | 0.26% | — | Copier-org CopierAI | 18/8/2025 | 17/6/2026 | Copier library and CLI app for rendering project templates. Prior to 9.9.1, a safe template can currently read and write arbitrary files because Copier exposes a few pathlib.Path objects in the Jinja context which have unconstrained I/O methods. This effectively renders the security model w.r.t. filesystem access… | |
| Aplazada | Media (5.4) | 0.43% | — | Etruel WP Delete Post CopiesAI | 7/1/2025 | 17/6/2026 | Missing Authorization vulnerability in etruel WP Delete Post Copies etruel-del-post-copies allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Delete Post Copies: from n/a through <= 5.5. | |
| Aplazada | Alta (7.1) | 0.35% | — | Obtaininfotech Multisite Content Copier UpdaterAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Obtain Infotech Multisite Content Copier/Updater allows Reflected XSS.This issue affects Multisite Content Copier/Updater: from n/a through 1.5.0. | |
| Modificada | Media (6.1) | 0.80% | — | Obtaininfotech Multisite Content Copier/updater | 14/3/2022 | 17/6/2026 | The WordPress Multisite Content Copier/Updater WordPress plugin before 2.1.2 does not sanitise and escape the s parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue in the network dashboard | |
| Modificada | Media (6.1) | 0.80% | — | Obtaininfotech Multisite Content Copier/updater | 7/3/2022 | 17/6/2026 | The WordPress Multisite Content Copier/Updater WordPress plugin before 2.1.0 does not sanitise and escape the wmcc_content_type, wmcc_source_blog and wmcc_record_per_page parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues | |
| Modificada | Alta (7.2) | 0.53% | — | NRL Opie | 27/7/2011 | 16/6/2026 | opielogin.c in opielogin in OPIE 2.4.1-test1 and earlier does not check the return value of the setuid system call, which allows local users to gain privileges by arranging for an account to already be running its maximum number of processes. | |
| Modificada | Alta (7.2) | 0.53% | — | NRL Opie | 27/7/2011 | 16/6/2026 | Multiple off-by-one errors in opiesu.c in opiesu in OPIE 2.4.1-test1 and earlier might allow local users to gain privileges via a crafted command line. | |
| Modificada | Alta (9.3) | 22% | — | FreebsdNRL Opie | 28/5/2010 | 16/6/2026 | Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-PRERELEASE and other platforms, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long username, as demonstrated by a… |