Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2586▼ 297 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
81 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.3) | 0.35% | — | MaplibreAIGrafana GeomapAI | 17/9/2026 | 18/9/2026 | A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escalation to Org Admin. | |
| Aplazada | Media (6.3) | 0.39% | — | AiosmtplibAI | 12/9/2026 | 23/9/2026 | aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines. Attackers can craft malicious addresses containing spaces and angle brackets to append parameters like AUTH, NOTIFY, or ORCPT to envelope… | |
| Aplazada | Crítica (10) | 0.52% | — | Maplibre GL JSAI | 3/9/2026 | 9/9/2026 | MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap while removeAttributes() removes attributes from the same collection, shifting indexes and skipping an adjacent dangerous attribute. An attacker… | |
| Aplazada | Alta (8.2) | 0.45% | — | Cpp-httplibAI | 28/8/2026 | 9/9/2026 | cpp-httplib is a C++ header-only HTTP/HTTPS library. In versions 0.33.0 through 0.50.0, the TLS-enabled WebSocket client frees the TLS session before closing the WebSocket that still uses it, producing a use-after-free. In WebSocketClient::shutdown_and_close the SSL object is freed and the pointer cleared, but the… | |
| Aplazada | Media (5.3) | 0.46% | — | CPP HttplibAI | 28/8/2026 | 9/9/2026 | cpp-httplib is a C++ header-only HTTP/HTTPS library. In version 0.49.0, the chunked-response trailer output path writes trailer header names and values directly to the socket without validating them, allowing CRLF sequences in a trailer field to inject additional headers or split the HTTP response. Unlike every other… | |
| Aplazada | Media (5.9) | 0.40% | — | AiosmtplibAI | 20/8/2026 | 18/9/2026 | aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib/protocol.py consumes the server's 220 response and starts the TLS handshake without clearing SMTPProtocol._buffer. An active network attacker can place attacker-chosen SMTP response lines after the… | |
| Aplazada | Media (6.9) | 0.53% | — | AiosmtplibAI | 18/8/2026 | 18/9/2026 | aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.1, SMTP.mail(), SMTP.rcpt(), SMTP.vrfy(), and SMTP.expn() send caller-supplied addresses without rejecting embedded CR or LF bytes. Data after the line break is framed as additional standalone SMTP command lines, allowing an attacker who… | |
| Analizada | Alta (7.4) | 0.26% | — | Yhirose Cpp-httplib | 10/7/2026 | 14/7/2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In affected Mbed TLS backend versions from 0.31.0 through 0.46.1 and wolfSSL backend versions from 0.33.0 through 0.46.1, when cpp-httplib is built with CPPHTTPLIB_MBEDTLS_SUPPORT or CPPHTTPLIB_WOLFSSL_SUPPORT and a client connects to an… | |
| Modificada | Alta (7.5) | 0.66% | — | Httplib2 Project Httplib2 | 8/7/2026 | 20/8/2026 | httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allowing a malicious or compromised HTTP server to return a small compressed payload… | |
| Analizada | Alta (8.7) | 0.49% | — | Yhirose Cpp-httplib | 29/5/2026 | 22/7/2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, When the server has called Server::set_trusted_proxies() with a non-empty trusted-proxy list, an attacker can send an HTTP request that includes an X-Forwarded-For header whose value parses to no valid IP segments. The… | |
| Modificada | Crítica (9.9) | 0.41% | — | Yhirose Cpp-httplib | 29/5/2026 | 22/7/2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's server parses an incoming request, it applies percent-decoding to every header value except Location and Referer. The validity check (is_field_value) is run before decoding, so encoded %0D%0A passes… | |
| Modificada | Alta (7.5) | 0.49% | — | Yhirose Cpp-httplib | 29/5/2026 | 22/7/2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, negative chunk-size in chunked Transfer-Encoding causes unbounded memory allocation and process crash. The ChunkedDecoder::read_payload function in cpp-httplib (httplib.h) parses the chunk-size field of HTTP chunked… | |
| Pendiente de análisis | Media (5.9) | 0.68% | — | Python FtplibAI | 13/5/2026 | 13/8/2026 | The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpeername()[0]), ftpcp() still calls parse227() directly and passes the raw attacker-controllable IP address and port to… | |
| Analizada | Media (6.5) | 0.28% | — | Yhirose Cpp-httplib | 31/3/2026 | 24/7/2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.40.0, cpp-httplib is vulnerable to HTTP Request Smuggling. The server's static file handler serves GET responses without consuming the request body. On HTTP/1.1 keep-alive connections, the unread body bytes remain on… | |
| Analizada | Alta (7.4) | 0.35% | — | Yhirose Cpp-httplib | 27/3/2026 | 17/6/2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.39.0, the cpp-httplib HTTP client forwards stored Basic Auth, Bearer Token, and Digest Auth credentials to arbitrary hosts when following cross-origin HTTP redirects (301/302/307/308). A malicious or compromised server can… | |
| Analizada | Alta (8.1) | 0.25% | — | Yhirose Cpp-httplib | 16/3/2026 | 17/6/2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.2, when a cpp-httplib client is configured with a proxy and set_follow_location(true), any HTTPS redirect it follows will have TLS certificate and hostname verification silently disabled on the new connection. The client… | |
| Analizada | Alta (7.5) | 0.55% | — | Yhirose Cpp-httplib | 11/3/2026 | 17/6/2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.1, when a cpp-httplib client uses the streaming API (httplib::stream::Get, httplib::stream::Post, etc.), the library calls std::stoull() directly on the Content-Length header value received from the server with no input… | |
| Analizada | Media (5.9) | 0.59% | — | Yhirose Cpp-httplib | 7/3/2026 | 17/6/2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.37.0, cpp-httplib uses std::regex (libstdc++) to parse RFC 5987 encoded filename* values in multipart Content-Disposition headers. The regex engine in libstdc++ implements backtracking via deep recursion, consuming one… | |
| Analizada | Alta (7.5) | 0.62% | — | Yhirose Cpp-httplib | 4/3/2026 | 17/6/2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.35.0, cpp-httplib (httplib.h) does not enforce Server::set_payload_max_length() on the decompressed request body when using HandlerWithContentReader (streaming ContentReader) with Content-Encoding: gzip (or other supported… | |
| Analizada | Media (5.3) | 0.43% | — | Yhirose Cpp-httplib | 4/3/2026 | 17/6/2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.35.0, when a request handler throws a C++ exception and the application has not registered a custom exception handler via set_exception_handler(), the library catches the exception and writes its message directly into the HTTP… | |
| Aplazada | Media (5.9) | 0.37% | — | Python PoplibAI | 20/1/2026 | 17/6/2026 | The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters. | |
| Aplazada | Media (5.9) | 0.42% | — | Python ImaplibAI | 20/1/2026 | 6/8/2026 | The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters. | |
| Analizada | Alta (8.7) | 0.40% | — | Yhirose Cpp-httplib | 12/1/2026 | 17/6/2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.30.1, a Denial of Service (DoS) vulnerability exists in cpp-httplib due to the unsafe handling of compressed HTTP request bodies (Content-Encoding: gzip, br, etc.). The library validates the payload_max_length against… | |
| Analizada | Alta (7.7) | 0.41% | — | Yhirose Cpp-httplib | 1/1/2026 | 17/6/2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.30.0, the ``write_headers`` function does not check for CR & LF characters in user supplied headers, allowing untrusted header value to escape header lines. This vulnerability allows attackers to add extra headers,… | |
| Aplazada | Media (4.4) | 0.19% | — | EmplibotAI | 13/12/2025 | 17/6/2026 | The Emplibot – AI Content Writer with Keyword Research, Infographics, and Linking | SEO Optimized | Fully Automated plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.9 via the emplibot_call_webhook_with_error() and emplibot_process_zip_data() functions. This… |