Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2571▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 107 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 0.36% | — | Golang PlaygroundAI | 25/9/2026 | 29/9/2026 | A malicious txtar could escape the intended execution context and force arbitrary writes to the playground host's trusted filesystem. Disjointly, one of the three possible paths to invoke go vet on the playground host did not correctly restrict the execution environment. This permitted a Go process to make a read for… | |
| Aplazada | Media (4.4) | 0.32% | — | Quick PlaygroundAI | 6/6/2026 | 23/7/2026 | The Quick Playground plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.4. This is due to the `qckply_data()` function passing the user-supplied `filename` POST parameter directly to `file_get_contents()` without any validation, sanitization, or path restriction. This makes… | |
| Aplazada | Alta (7.5) | 1.2% | — | Quick PlaygroundAI | 15/5/2026 | 17/6/2026 | The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. This is due to insufficient path validation in the qckply_zip_theme() function, which appends a user-controlled 'stylesheet' parameter directly to the theme root directory path without sanitizing directory… | |
| Pendiente de análisis | Media (5.4) | 0.09% | — | Electronhub AI PlaygroundAI | 12/5/2026 | 17/6/2026 | Uncontrolled search path for some AI Playground software before version 3.0.0 alpha within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially… | |
| Aplazada | Crítica (9.8) | 8.1% | — | Quick PlaygroundAI | 9/4/2026 | 17/6/2026 | The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insufficient authorization checks on REST API endpoints that expose a sync code and allow arbitrary file uploads. This makes it possible for unauthenticated attackers to retrieve… | |
| Aplazada | Media (5.4) | 0.10% | — | Electronhub AI PlaygroundAI | 10/2/2026 | 17/6/2026 | Uncontrolled search path for some AI Playground before version 2.6.1 beta within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via… | |
| Aplazada | Media (5.4) | 0.11% | — | Electronhub AI PlaygroundAI | 12/8/2025 | 17/6/2026 | Incorrect default permissions for some AI Playground software before version v2.3.0 alpha may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (6.1) | 0.36% | — | Electronhub AI Playground | 30/7/2025 | 17/6/2026 | playground.electronhub.ai v1.1.9 was discovered to contain a cross-site scripting (XSS) vulnerability. | |
| Aplazada | Alta (8.8) | 0.37% | — | Allenai AI2 PlaygroundAI | 22/7/2025 | 17/6/2026 | Ai2 playground web service (playground.allenai.org) LLM chat through 2025-06-03 is vulnerable to Insecure Direct Object Reference (IDOR), allowing attackers to gain sensitvie information via enumerating thread keys in the URL. | |
| Aplazada | Media (6.1) | 0.28% | — | Chatplayground AIAI | 22/7/2025 | 17/6/2026 | Self Cross-Site Scripting (XSS) vulnerability in ChatPlayground.ai through 2025-05-24, allows attackers to execute arbitrary code and gain sensitive information via a crafted SVG file contents sent through the chat component. | |
| Modificada | Media (4.7) | 1.2% | — | Graphql Playground | 4/11/2021 | 17/6/2026 | GraphQL Playground is a GraphQL IDE for development of graphQL focused applications. All versions of graphql-playground-react older than graphql-playground-react@1.7.28 are vulnerable to compromised HTTP schema introspection responses or schema prop values with malicious GraphQL type names, exposing a dynamic XSS… | |
| Modificada | Alta (7.5) | 1.4% | — | Playgroundsessions Playground Sessions | 23/11/2020 | 17/6/2026 | Playground Sessions v2.5.582 (and earlier) for Windows, stores the user credentials in plain text allowing anyone with access to UserProfiles.sol to extract the email and password. | |
| Modificada | Alta (7.4) | 7.2% | — | Prisma Graphql-playground-htmlPrisma Graphql-playground-middleware-expressPrisma Graphql-playground-middleware-hapiPrisma Graphql-playground-middleware-koa+1 | 8/6/2020 | 17/6/2026 | GraphQL Playground (graphql-playground-html NPM package) before version 1.6.22 have a severe XSS Reflection attack vulnerability. All unsanitized user input passed into renderPlaygroundPage() method could trigger this vulnerability. This has been patched in graphql-playground-html version 1.6.22. Note that some of the… | |
| Modificada | Media (4.3) | 2.6% | — | Aspplayground.net | 17/8/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in calendar.asp in ASPPlayground.NET Forum Advanced Edition 2.4.5 Unicode, and possibly other versions before October 15, 2006, allows remote attackers to inject arbitrary web script or HTML via the calendarID parameter. |