Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2573▼ 324 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 435 respecto a la semana anterior
78 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.26% | — | Meta ProxygenAI | 28/9/2026 | 30/9/2026 | In proxygen from v2024.10.28.00 until v2026.09.28.00, WebTransportImpl::terminateSessionStreams (WebTransportImpl::destroy in releases before v2025.08.18.00) failed to unregister read callbacks for streams that were no longer open before destroying them. The transport could then invoke a read callback that had been… | |
| Aplazada | Media (5.3) | 0.25% | — | Facebook ProxygenAI | 28/9/2026 | 30/9/2026 | In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::onWebTransportBidiStream APIs could return stream handles that the stream handler had already freed. HQSession then installed those handles as transport read callbacks, which could lead to use of… | |
| Aplazada | Alta (7.3) | 0.19% | — | Facebook ProxygenAI | 28/9/2026 | 1/10/2026 | In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calling the base QuicWtSessionBase::closeSession method. The base method notifies the session handler, which may release the last reference to the session and destroy it. | |
| Aplazada | Alta (7.5) | 0.26% | — | MoxygenAI | 28/9/2026 | 30/9/2026 | In moxygen before commit 004123dd24c3, MoQSession::dataStreamReadLoop keeps using a stream read handle after reading a FIN, which invalidates the handle under proxygen's WebTransport API. A remote peer can trigger the stale use by opening a data stream that names an unknown track alias and carries the FIN in the same… | |
| Aplazada | Alta (7.5) | 0.57% | — | Facebook ProxygenAI | 23/7/2026 | 23/7/2026 | Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETTINGS_INITIAL_WINDOW_SIZE to 0 or withholding WINDOW_UPDATE frames, causing the server to buffer complete response bodies in memory… | |
| Aplazada | Alta (7.2) | 0.19% | — | OxygenAI | 28/3/2026 | 17/6/2026 | The Oxygen Theme theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.8 via the laborator_calc_route AJAX action. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used… | |
| Analizada | Alta (7.7) | 0.80% | — | Franklioxygen Mytube | 27/3/2026 | 17/6/2026 | MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.72, an unauthenticated attacker can lock out administrator and visitor accounts from password-based authentication by triggering failed login attempts. The application exposes three password verification endpoints, all of… | |
| Analizada | Alta (8.9) | 0.70% | — | Franklioxygen Mytube | 27/3/2026 | 17/6/2026 | MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.71, an unauthenticated attacker can register an arbitrary passkey and subsequently authenticate with it to obtain a full admin session. The application exposes passkey registration endpoints without requiring prior… | |
| Analizada | Alta (7.4) | 0.59% | — | Franklioxygen Mytube | 27/3/2026 | 17/6/2026 | MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.69, an authorization bypass in the `/api/settings/import-database` endpoint allows attackers with low-privilege credentials to upload and replace the application's SQLite database entirely, leading to a full compromise of the… | |
| Analizada | Alta (8.8) | 0.50% | — | Oxygenz Clipbucket | 18/3/2026 | 17/6/2026 | ClipBucket v5 is an open source video sharing platform. An authenticated time-based blind SQL injection vulnerability exists in ClipBucket prior to 5.5.3 #80 within the `actions/ajax.php` endpoint. Due to insufficient input sanitization of the `userid` parameter, an authenticated attacker can execute arbitrary SQL… | |
| Analizada | Media (5.7) | 0.32% | — | Oxygenz Clipbucket | 27/2/2026 | 17/6/2026 | ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, collection item operations are vulnerable to authorization flaws, allowing a normal authenticated user to modify another user’s collection items. This affects both add item (/actions/add_to_collection.php) due to missing authorization… | |
| Analizada | Baja (2) | 0.26% | — | Oxygenz Clipbucket | 27/2/2026 | 17/6/2026 | ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, a normal authenticated user can store the XSS payload. The payload is triggered by administrator. Version 5.5.3 #59 fixes the issue. | |
| Aplazada | Alta (7.2) | 0.20% | — | Laborator OxygenAI | 20/2/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Laborator Oxygen oxygen allows Server Side Request Forgery.This issue affects Oxygen: from n/a through <= 6.0.8. | |
| Analizada | Media (5) | 0.31% | — | Oxygenz Clipbucket | 12/2/2026 | 17/6/2026 | ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #45, in Clip Bucket V5, The Remote Play allows creating video entries that reference external video URLs without uploading the video files to the server. However, by specifying an internal network host in the video URL, an SSRF can be triggered,… | |
| Analizada | Crítica (9.3) | 0.41% | — | Oxygenz Clipbucket | 10/2/2026 | 17/6/2026 | ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #40, a Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability exists in ClipBucket's avatar and background image upload functionality. The application moves uploaded files to a web-accessible location before validating them, creating… | |
| Analizada | Media (5.3) | 0.33% | — | Franklioxygen Mytube | 24/1/2026 | 17/6/2026 | MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below have a Mass Assignment vulnerability in the settings management functionality due to insufficient input validation. The application's saveSettings() function accepts arbitrary key-value pairs without validating property… | |
| Analizada | Alta (8.7) | 0.36% | — | Franklioxygen Mytube | 24/1/2026 | 17/6/2026 | MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below do not safeguard against authorization bypass, allowing guest users to download the complete application database. The application fails to properly validate user permissions on the database export endpoint, enabling… | |
| Analizada | Media (5.3) | 0.36% | — | Franklioxygen Mytube | 19/1/2026 | 17/6/2026 | MyTube is a self-hosted downloader and player for several video websites. Prior to version 1.7.71, a rate limiting bypass via `X-Forwarded-For` header spoofing allows unauthenticated attackers to bypass IP-based rate limiting on general API endpoints. Attackers can spoof client IPs by manipulating the… | |
| Analizada | Crítica (9.8) | 0.65% | — | Franklioxygen Mytube | 19/1/2026 | 17/6/2026 | MyTube is a self-hosted downloader and player for several video websites. A vulnerability present in version 1.7.65 and poetntially earlier versions allows unauthenticated users to bypass the mandatory authentication check in the roleBasedAuthMiddleware. By simply not providing an authentication cookie (making… | |
| Analizada | Crítica (9.8) | 1.7% | — | Oxygenz Clipbucket | 8/1/2026 | 17/6/2026 | ClipBucket v5 is an open source video sharing platform. Versions 5.5.2-#187 and below allow an attacker to perform Blind SQL Injection through the add comment section within a channel. When adding a comment within a channel, there is a POST request to the /actions/ajax.php endpoint. The obj_id parameter within the… | |
| Modificada | Crítica (9.8) | 0.51% | — | Oxygenz Clipbucket | 22/12/2025 | 5/7/2026 | ClipBucket 5.5.2 is affected by an improper access control issue where the product is shipped or deployed with hardcoded default administrative credentials. An unauthenticated remote attacker can log in to the administrative panel using these default credentials, resulting in full administrative control of the… | |
| Analizada | Media (5.3) | 0.29% | — | Facebook Proxygen | 2/12/2025 | 17/6/2026 | Sending an HTTP request/response body with greater than 2^31 bytes triggers an infinite loop in proxygen::coro::HTTPQuicCoroSession which blocks the backing event loop and unconditionally appends data to a std::vector per-loop iteration. This issue leads to unbounded memory growth and eventually causes the process to… | |
| Analizada | Media (6.5) | 0.40% | — | Oxygenz Clipbucket | 29/11/2025 | 17/6/2026 | ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 - #164, an authorization bypass vulnerability in the AJAX flagging system allows any unauthenticated user to flag any content (users, videos, photos, collections) on the platform. This can lead to mass flagging attacks, content disruption,… | |
| Analizada | Alta (8.8) | 0.36% | — | Oxygenz Clipbucket | 20/11/2025 | 17/6/2026 | ClipBucket v5 is an open source video sharing platform. In ClipBucket version 5.5.2, a change to network.class.php causes the application to dynamically build the server URL from the incoming HTTP Host header when the configuration base_url is not set. Because Host is a client-controlled header, an attacker can supply… | |
| Analizada | Alta (7.2) | 0.25% | — | Oxygenz Clipbucket | 7/11/2025 | 17/6/2026 | ClipBucket v5 is an open source video sharing platform. In versions 5.5.2-#146 and below, the Manage Playlists feature is vulnerable to stored Cross-site Scripting (XSS),specifically in the Playlist Name field. An authenticated low-privileged user can create a playlist with a malicious name containing HTML/JavaScript… |