Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
102 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.58% | — | PocketbaseAI | 16/9/2026 | 30/9/2026 | Pocketbase is an open source web backend written in go. Prior to 0.22.48 and 0.39.7, PocketBase's panic-recovery middleware covers regular request handling but not internal child and worker goroutines. A panic in one of these internal goroutines can escape recovery and terminate the server process, causing a denial of… | |
| Aplazada | Baja (1.8) | 0.14% | — | Manabi Pocket FOR ParentsAI | 15/9/2026 | 16/9/2026 | Android application "ManabiPocket for Parents" contains an improper access control vulnerability in one of its components. A malicious application installed on the user's Android device may exploit the affected component via an Intent, potentially allowing the malicious application to obtain sensitive information from… | |
| Pendiente de análisis | Media (6.9) | 0.55% | — | PocketsphinxAI | 14/9/2026 | 30/9/2026 | PocketSphinx is a small speech recognizer. Prior to 5.1.1, the trie language-model loaders in src/lm/ngram_model_trie.c do not adequately validate boundary conditions in ARPA, DMP, and binary format headers, and the acoustic-model loaders in src/mdef.c and src/util/bio.c use sscanf with unbounded string fields.… | |
| Aplazada | Alta (7.1) | 0.44% | — | Pocketmine-mpAI | 9/9/2026 | 9/9/2026 | PocketMine-MP versions before 5.39.2 fail to limit JSON payload size in ModalFormResponsePacket handling, allowing authenticated players to cause denial of service. Attackers can send modal form response packets with massive JSON arrays to exhaust server memory and CPU resources, rendering the server unresponsive. | |
| Aplazada | Media (6.3) | 0.35% | — | Pocketmine-mpAI | 9/9/2026 | 10/9/2026 | PocketMine-MP versions before 5.39.2 fail to validate entity despawn state when processing attack packets from clients. Attackers can exploit a race condition by attacking a disconnecting player to trigger multiple death handlers, causing inventory items and experience to drop multiple times for duplication. | |
| Aplazada | Media (5.3) | 0.35% | — | Pocketmine-mpAI | 9/9/2026 | 9/9/2026 | PocketMine-MP versions before 5.39.2 contain a network amplification vulnerability in ActorEventPacket handling that allows clients to trigger consuming animations for all visible players. Attackers can send crafted ActorEventPacket messages to spam animation events to other clients and waste server CPU and memory… | |
| Aplazada | Alta (8.7) | 0.61% | — | Pocketmine-mpAI | 9/9/2026 | 14/9/2026 | PocketMine-MP before 5.41.1 contains a denial of service vulnerability in LoginPacket processing where large or complex structures in unknown clientData JWT properties cause excessive logging without sanitization. Attackers can send crafted LoginPackets with deeply nested or massive object structures to trigger… | |
| Aplazada | Alta (8.7) | 0.47% | — | Pocketmine-mpAI | 9/9/2026 | 9/9/2026 | PocketMine-MP versions before 5.43.1 fail to properly validate the Certificate field during offline login authentication. Unauthenticated players can trigger an uninitialized property access error that crashes the server. | |
| Aplazada | Baja (2.3) | 0.38% | — | Pocketmine-mpAI | 9/9/2026 | 10/9/2026 | PocketMine-MP versions before 5.44.2 fail to properly validate multiple ResourcePackClientResponsePacket packets with STATUS_COMPLETED status during resource pack handling. Malicious clients can send batches of these packets to repeatedly trigger pre-spawn progression, creating duplicate Player objects and amplifying… | |
| Aplazada | Media (6.9) | 0.40% | — | Pocketmine-mpAI | 9/9/2026 | 9/9/2026 | PocketMine-MP versions before 5.25.2 fail to limit the explode() function in packet parsing, allowing malicious clients to waste server resources. Attackers can send crafted packets with excessive delimiters to consume CPU and memory through sign editing, JWT parsing, and command parsing endpoints. | |
| Aplazada | Alta (7.1) | 0.31% | — | Pocketmine-mpAI | 9/9/2026 | 10/9/2026 | PocketMine-MP before 5.32.1 fails to validate uniqueness of pack UUIDs in ResourcePackClientResponsePacket STATUS_SEND_PACKS handling, allowing authenticated clients to trigger duplicate pack transmissions. Attackers can send multiple copies of valid pack UUIDs in a single packet to exhaust server memory and cause… | |
| Aplazada | Alta (8.7) | 0.43% | — | Pocketmine-mpAI | 9/9/2026 | 14/9/2026 | PocketMine-MP before 5.11.1 contains a denial of service vulnerability in LoginPacket JSON processing that allows remote attackers to crash the server by sending malformed JSON data. Attackers can exploit improper object initialization from scalar JSON types to trigger unset required properties, causing the… | |
| Aplazada | Alta (7.1) | 0.38% | — | Pocketmine-mpAI | 9/9/2026 | 9/9/2026 | PocketMine-MP versions before 4.8.1 fail to validate dye color IDs in banner NBT data during deserialization. Attackers can provide invalid color values in inventory transactions or via commands to trigger undefined offset errors and crash the server. | |
| Aplazada | Media (5.3) | 0.33% | — | Pocketmine-mpAI | 9/9/2026 | 10/9/2026 | PocketMine-MP versions before 4.12.5 contain a denial-of-service vulnerability in ModalFormResponsePacket processing that allows attackers to cause server resource exhaustion by sending large JSON payloads. Attackers can send numerous oversized modal form response packets to consume CPU time and prevent the server… | |
| Aplazada | Media (5.3) | 0.38% | — | Pocketmine-mpAI | 9/9/2026 | 9/9/2026 | PocketMine-MP before 4.18.0-ALPHA2 fails to rate-limit mismatch type InventoryTransactionPacket requests, allowing attackers to trigger excessive inventory synchronization. Attackers can send numerous mismatch transactions to force the server to transmit large amounts of serialized inventory data, consuming… | |
| Aplazada | Media (6.9) | 0.64% | — | Pocketmine-mpAI | 9/9/2026 | 18/9/2026 | PocketMine-MP versions before 5.42.1 contain a denial of service vulnerability in the LoginPacket handler that allows remote attackers to flood warning messages by injecting numerous junk properties into the clientData JWT. Attackers can craft malicious login packets with excessive unknown properties to waste server… | |
| Aplazada | Alta (7.1) | 0.38% | — | Pocketmine-mpAI | 9/9/2026 | 18/9/2026 | PocketMine-MP versions before 5.11.2 contain a denial of service vulnerability in BookEditPacket handling that crashes the server when an invalid inventory slot value is provided. Attackers can send a crafted BookEditPacket with an inventory slot greater than 35 to trigger an unhandled exception and crash the server. | |
| Aplazada | Alta (8.7) | 0.35% | — | Pocketmine-mpAIJsonmapperAI | 9/9/2026 | 30/9/2026 | PocketMine-MP versions before 4.20.5 contain a denial of service vulnerability in LoginPacket JSON parsing due to improper validation in the JsonMapper dependency. Attackers can send malformed JSON structures in LoginPacket to crash the server. | |
| Aplazada | Alta (7.1) | 0.38% | — | Pocketmine-mpAI | 9/9/2026 | 30/9/2026 | PocketMine-MP versions >= 4.20.0 before 4.22.3 (and before 5.2.1 in the 5.x branch) fail to validate NBT tag types in BlockActorDataPacket. A player can crash the server by sending a packet containing sign NBT data with an incorrect tag type, triggering an unhandled UnexpectedTagTypeException that terminates the… | |
| Aplazada | Alta (8.7) | 0.34% | — | Pocketmine-mpAI | 9/9/2026 | 30/9/2026 | PocketMine-MP versions before 5.3.1 and 4.23.1 contain a denial of service vulnerability in LoginPacket JSON parsing due to improper null value handling in arrays. Attackers can send malformed JSON with unexpected null elements in LoginPacket to crash the server. | |
| Aplazada | Alta (8.7) | 0.22% | — | Pocketmine-mpAI | 9/9/2026 | 30/9/2026 | PocketMine-MP versions before 5.3.1 and 4.23.1 fail to validate that the identityPublicKey in LoginPacket uses the required secp384r1 elliptic curve. Attackers can provide LoginPackets with keys using different curves or non-EC key types to pass login verification but trigger an uncaught exception during ECDH key… | |
| Aplazada | Alta (7.1) | 0.42% | — | Pocketmine-mpAI | 7/9/2026 | 14/9/2026 | PocketMine-MP before 3.26.5 and 4.0.x before 4.0.5 does not limit book page text length, page count, or author/title length. A player who obtains a writable book can create oversized NBT ('book bombs'), causing excess bandwidth consumption and server crashes (exceeding the 1 MB chunk size limit when saving… | |
| Aplazada | Alta (8.7) | 0.47% | — | Pocketmine-mpAI | 7/9/2026 | 8/9/2026 | PocketMine-MP versions before 3.26.5 and 4.0.5 fail to validate the length of skin data fields submitted by players, allowing uncapped values to exceed the 32767 byte TAG_String limit. Attackers can submit oversized skin data fields like skinID or geometryName to trigger exceptions during NBT data serialization,… | |
| Aplazada | Media (5.3) | 0.23% | — | Pocketmine-mpAI | 7/9/2026 | 10/9/2026 | PocketMine-MP 3.x (before 3.27.0) does not implement Minecraft Bedrock protocol encryption, so the server cannot verify that a connecting client possesses the private key corresponding to its login token. An attacker who captures a valid login from another player's session (for example by tricking the player into… | |
| Aplazada | Alta (7.1) | 0.68% | — | Pocketmine-mpAI | 7/9/2026 | 8/9/2026 | PocketMine-MP before 4.0.6 does not validate facing values in PlayerActionPacket (for START_BREAK and CRACK_BREAK actions) or in UseItemTransactionData (typically within InventoryTransactionPacket). A remote authenticated attacker can send crafted packets with invalid facing values (e.g., negative or out-of-range) to… |