Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2543▼ 416 respecto a la semana anterior
Críticas / altas1316▲ 27 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
64 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.5) | 0.39% | — | TinypoolAI | 2/10/2026 | 2/10/2026 | Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads filename from a caller-supplied options object in pool.run(task, options) without requiring an own property, so a polluted Object.prototype.filename can replace the intended worker module. Applications are affected only… | |
| Aplazada | Crítica (9.5) | 0.50% | — | TinypoolAI | 2/10/2026 | 2/10/2026 | Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.1, Tinypool constructs ThreadPool.options from a normal options object and reads the execArgv and env worker options in dist/index.js, allowing values inherited from a polluted Object.prototype to be copied into own properties and passed to… | |
| Pendiente de análisis | Media (6.9) | 0.31% | — | Pgpool-iiAI | 30/9/2026 | 30/9/2026 | Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node. | |
| Pendiente de análisis | Media (5.3) | 0.18% | — | Pgpool-iiAI | 30/9/2026 | 30/9/2026 | Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information. | |
| Pendiente de análisis | Alta (8.7) | 0.29% | — | Pgpool-iiAI | 30/9/2026 | 30/9/2026 | A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process. | |
| Pendiente de análisis | Alta (8.7) | 0.32% | — | Pgpool-iiAI | 30/9/2026 | 30/9/2026 | A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termination. | |
| Pendiente de análisis | Alta (7.1) | 0.25% | — | Pgpool-iiAI | 30/9/2026 | 30/9/2026 | An out-of-bounds write vulnerability exists in Pgpool-II, which may allow an authenticated attacker to cause abnormal process termination. | |
| Pendiente de análisis | Media (6.9) | 0.15% | — | Pgpool-iiAI | 30/9/2026 | 30/9/2026 | An improper certificate validation vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to bypass client certificate authentication. | |
| Pendiente de análisis | Alta (8.7) | 0.34% | — | Pgpool-iiAI | 30/9/2026 | 30/9/2026 | An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker to cause abnormal process termination or arbitrary code execution. | |
| Aplazada | Alta (7.1) | 0.16% | — | Stablebit DrivepoolAI | 7/8/2026 | 12/8/2026 | A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code of the file C:\Program Files\StableBit\DrivePool\DrivePool.Service.exe of the component DrivePoolService. Such manipulation leads to permission issues. The attack must be carried out locally. The… | |
| Aplazada | Media (6.1) | 0.39% | — | Antoineh Football PoolAI | 5/8/2026 | 12/8/2026 | The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `shouttext` POST parameter of the Shoutbox widget in all versions up to, and including, 2.13.4 due to insufficient input sanitization and output escaping. When a shoutbox form submission fails the nonce check (or `shouttext`… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wppool FormychatAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL FormyChat social-contact-form allows Stored XSS.This issue affects FormyChat: from n/a through <= 2.15.3. | |
| Aplazada | Media (4.3) | 0.20% | — | Wppool FlextableAI | 25/5/2026 | 24/7/2026 | Missing Authorization vulnerability in WPPOOL FlexTable allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexTable: from n/a through 3.24.0. | |
| Aplazada | Alta (8.7) | 0.45% | — | Redaxo MediapoolAIRedaxo CMSAI | 23/5/2026 | 23/7/2026 | Redaxo CMS Mediapool Addon 5.5.1 and older contains an arbitrary file upload vulnerability that allows authenticated users to bypass file extension blacklist restrictions. Attackers with editor accounts can upload executable files by using obfuscated extensions like php71 or php53 to evade the blacklist filter and… | |
| Pendiente de análisis | Alta (8.7) | 0.97% | — | Amazon Cognito User PoolAIAmazon OPS WheelAI | 24/4/2026 | 17/6/2026 | Improperly controlled modification of dynamically-determined object attributes in the Cognito User Pool configuration in AWS Ops Wheel before PR #165 allows remote authenticated users to escalate to deployment admin privileges and manage Cognito user accounts via a crafted UpdateUserAttributes API call that sets the… | |
| Aplazada | Alta (7.5) | 0.25% | — | Ghostpool GaugeAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in GhostPool Gauge gauge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gauge: from n/a through <= 6.56.4. | |
| Aplazada | Alta (7.5) | 0.25% | — | Ghostpool Aardvark PluginAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in GhostPool Aardvark Plugin aardvark-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Aardvark Plugin: from n/a through <= 2.19. | |
| Aplazada | Alta (7.1) | 0.24% | — | Ghostpool AardvarkAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhostPool Aardvark aardvark allows Reflected XSS.This issue affects Aardvark: from n/a through <= 4.6.3. | |
| Aplazada | Media (5.4) | 0.24% | — | Smartdatasoft Pool ServicesAI | 22/1/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Pool Services pool-services allows Server Side Request Forgery.This issue affects Pool Services: from n/a through <= 3.3. | |
| Aplazada | Alta (8.1) | 0.45% | — | Octoprint-spoolmanagerAIOctoprintAI | 23/10/2025 | 17/6/2026 | OctoPrint-SpoolManager is a plugin for managing spools and all their usage metadata. In versions 1.8.0a2 and older of the testing branch and versions 1.7.7 and older of the stable branch, the APIs of the OctoPrint-SpoolManager plugin do not correctly enforce authentication or authorization checks. This issue has been… | |
| Aplazada | Media (6.4) | 0.19% | — | Eulerpool Research SystemsAI | 30/9/2025 | 17/6/2026 | The Eulerpool Research Systems plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'aaq' shortcode in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.5) | 0.17% | — | Antoineh Football PoolAI | 9/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AntoineH Football Pool football-pool allows Stored XSS.This issue affects Football Pool: from n/a through <= 2.12.6. | |
| Aplazada | Media (6.5) | 0.24% | — | Antoineh Football PoolAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AntoineH Football Pool football-pool allows Stored XSS.This issue affects Football Pool: from n/a through <= 2.12.5. | |
| Modificada | Media (4.8) | 0.25% | — | Antoineh Football Pool | 19/6/2025 | 17/6/2026 | The Football Pool plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.12.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Aplazada | Crítica (9.3) | 0.91% | — | Pgpool-iiAI | 19/5/2025 | 17/6/2026 | Pgpool-II provided by PgPool Global Development Group contains an authentication bypass by primary weakness vulnerability. if the vulnerability is exploited, an attacker may be able to log in to the system as an arbitrary user, allowing them to read or tamper with data in the database, and/or disable the database. |