Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2818▲ 71 respecto a la semana anterior
Críticas / altas1488▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
–

7 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.6)0.37%—CheerioAIMicrosoft PlaywrightAIPuppeteerAIFlowiseai FlowiseAI15/9/202617/9/2026
Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection. Attackers can provide arbitrary URLs to fetch cloud metadata, internal services, and private network resources with response content returned as…
AplazadaMedia (6.9)0.43%—PlaywrightcaptureAI3/9/20268/9/2026
PlaywrightCapture contains a server-side request forgery (SSRF) vulnerability in its favicon retrieval functionality. When only_global_lookup is enabled, the application validates the initial favicon URL to prevent requests to localhost, loopback, or other non-public network addresses. However, redirects followed by…
AplazadaMedia (5.1)0.47%—Lookyloo PlaywrightcaptureAI11/8/202626/8/2026
A Server-Side Request Forgery (SSRF) vulnerability existed in Lookyloo's PlaywrightCapture when the only_global_lookup option was enabled. PlaywrightCapture implements this option to prevent captures from accessing local, loopback, or otherwise non-public network resources. However, favicon retrieval was performed…
AnalizadaMedia (6.6)0.54%—Lookyloo Playwright Capture13/5/202617/6/2026
PlaywrightCapture is a simple replacement for splash using playwright. Prior to 1.39.6, PlaywrightCapture did not sufficiently restrict navigations and resource requests initiated by rendered pages. An attacker-controlled page could abuse browser-side redirection mechanisms, such as window.location.href, to make the…
AplazadaAlta (7.2)1.2%—Microsoft Playwright MCP ServerAI7/1/202630/9/2026
Microsoft Playwright MCP Server versions prior to 0.0.40 fails to validate the Origin header on incoming connections. This allows an attacker to perform a DNS rebinding attack via a victim’s web browser and send unauthorized requests to a locally running MCP server, resulting in unintended invocation of MCP tool…
ModificadaMedia (5.3)0.23%—Microsoft Playwright14/10/202517/6/2026
Improper verification of cryptographic signature in Github: Playwright allows an unauthorized attacker to perform spoofing over an adjacent network.
AnalizadaCrítica (9.8)0.68%—Microsoft Azure Playwright31/3/202517/6/2026
Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network.