Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3072▲ 552 respecto a la semana anterior
Críticas / altas1458▲ 273 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
–

176 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.61%—Uber KrakenAI16/9/202624/9/2026
Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated attackers to traverse outside the configured storage root. Attackers can use percent-encoded parent-directory segments in the tag parameter to read arbitrary files accessible to the testfs backend…
AplazadaCrítica (9)0.18%—Eclipse AeriosAIKrakendAI2/9/20263/9/2026
In the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance included in the API Gateway component had the disable_jwk_security parameter hard-coded to true, with no option to override it through the Helm chart configuration. This setting disables TLS…
Pendiente de análisisAlta (7.1)0.26%—Bendix Ec80 Brake ECUAI28/8/20263/9/2026
Bendix EC80 Brake ECU is vulnerable to an out-of-bounds write, which could allow an attacker to deliver a payload that could establish an arbitrary write primitive, which could crash the ECU.
AplazadaCrítica (9.1)0.24%—KrakenAI18/8/202624/9/2026
Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache, relying only on CRC32 checksums for piece validation. Attackers on the agent-to-agent path or malicious peers can supply substituted content with forged CRC32…
AplazadaBaja (2.9)0.58%—Localhostlabs KarakeepAI18/8/202620/8/2026
A vulnerability was determined in karakeep-app karakeep up to 0.32.0. The impacted element is an unknown function of the file apps/web/server/auth.ts of the component OAuth Sign-In. This manipulation causes improper authentication. It is possible to initiate the attack remotely. The complexity of an attack is rather…
AplazadaBaja (2.9)0.65%—Localhostlabs KarakeepAI18/8/202620/8/2026
A vulnerability was found in karakeep-app karakeep up to 0.32.0. The affected element is the function authorize of the file apps/web/server/auth.ts of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts. The attack may be performed from remote. This…
AplazadaAlta (7.6)0.38%—Localhostlabs KarakeepAI26/5/202624/7/2026
Karakeep is a elf-hostable bookmark-everything app. A Server-Side Request Forgery (SSRF) protection bypass vulnerability was identified in versions prior to 0.32.0 affecting redirect-following processing components. Although the application implements protections intended to prevent requests toward internal/private…
Pendiente de análisisAlta (7.5)0.65%—Amazon Braket SDKAI22/5/202623/7/2026
Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remote authenticated user with S3 write access to the job output bucket to achieve arbitrary code execution on any machine that processes job results. We recommend you upgrade to amazon-braket-sdk version…
AplazadaBaja (1.3)0.41%—Krakend-ceAIKrakend-eeAI25/2/202617/6/2026
Improper Resource Shutdown or Release vulnerability in KrakenD, SLU KrakenD-CE (CircuitBreaker modules), KrakenD, SLU KrakenD-EE (CircuitBreaker modules). This issue affects KrakenD-CE: before 2.13.1; KrakenD-EE: before 2.12.5.
AnalizadaMedia (6.1)0.39%—Localhostlabs Karakeep25/2/202617/6/2026
Karakeep is a elf-hostable bookmark-everything app. In version 0.30.0, when the Reddit metascraper plugin returns `readableContentHtml`, the HTML parsing subprocess uses it directly without running it through DOMPurify. Every other content source in the crawler goes through Readability + DOMPurify, but the Reddit path…
AnalizadaBaja (2.7)0.31%—Arksine Moonraker22/1/202617/6/2026
Moonraker is a Python web server providing API access to Klipper 3D printing firmware. In versions 0.9.3 and below, instances configured with the "ldap" component enabled are vulnerable to LDAP search filter injection techniques via the login endpoint. The 401 error response message can be used to determine whether or…
AplazadaAlta (7.1)0.18%—Rakessh Ads24 LiteAI29/12/20251/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rakessh Ads24 Lite wp-ad-management allows Reflected XSS.This issue affects Ads24 Lite: from n/a through <= 1.0.
AplazadaMedia (6.5)0.36%—Localhostlabs KarakeepAI14/10/202517/6/2026
karakeep v0.26.0 to v0.7.0 was discovered to contain a Server-Side Request Forgery (SSRF).
AnalizadaCrítica (9.8)0.55%—Axosoft Gitkraken Desktop4/8/202517/6/2026
The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to misconfigured Electron Fuses. Specifically, the following insecure settings were observed: RunAsNode is enabled and EnableNodeCliInspectArguments is not disabled. These configurations allow the application to be executed in Node.js mode,…
AplazadaMedia (4.3)0.44%—Webraketen Internal Links ManagerAI24/1/202517/6/2026
Missing Authorization vulnerability in webraketen Internal Links Manager seo-automated-link-building allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Internal Links Manager: from n/a through <= 2.5.2.
AplazadaMedia (4.3)0.65%—Kraken.io Image OptimizerAI9/12/202417/6/2026
Missing Authorization vulnerability in Karim Salman Kraken.io Image Optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kraken.io Image Optimizer: from n/a through 2.6.7.
ModificadaAlta (7.8)1.3%—Gitkraken Gitlens28/11/202317/6/2026
An issue in GitKraken GitLens before v.14.0.0 allows an attacker to execute arbitrary code via a crafted file to the Visual Studio Codes workspace trust component.
ModificadaMedia (6.5)0.68%—Kraken.io Image Optimizer1/2/202317/6/2026
The Kraken.io Image Optimizer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX actions in versions up to, and including, 2.6.8. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to reset image optimizations.
ModificadaAlta (7.5)0.80%—Uber Kraken20/1/202317/6/2026
kraken <= 0.1.4 has an arbitrary file read vulnerability via the component testfs.
ModificadaAlta (8.8)0.36%—Kraken.io Image Optimizer23/9/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Kraken.io Image Optimizer plugin <= 2.6.5 at WordPress.
ModificadaMedia (4.3)0.57%—KrakendLuraproject Lura1/8/202217/6/2026
Lura and KrakenD-CE versions older than v2.0.2 and KrakenD-EE versions older than v2.0.0 do not sanitize URL parameters correctly, allowing a malicious user to alter the backend URL defined for a pipe when remote users send crafty URL requests. The vulnerability does not affect KrakenD itself, but the consumed backend…
ModificadaMedia (6.4)1.4%—Ruby-lang RakeCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+124/2/202017/6/2026
There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`.
ModificadaMedia (5.4)0.82%—Jenkins Brakeman12/2/202017/6/2026
Jenkins Brakeman Plugin 0.12 and earlier did not escape values received from parsed JSON files when rendering them, resulting in a stored cross-site scripting vulnerability exploitable by users able to control the Brakeman post-build step input data.
ModificadaCrítica (9.8)1.4%—Airbrake Ruby6/9/201917/6/2026
The Airbrake Ruby notifier 4.2.3 for Airbrake mishandles the blacklist_keys configuration option and consequently may disclose passwords to unauthorized actors. This is fixed in 4.2.4 (also, 4.2.2 and earlier are unaffected).
ModificadaMedia (5.9)1.3%—Airbrake31/5/201817/6/2026
The airbrake module 0.3.8 and earlier defaults to sending environment variables over HTTP. Environment variables can often times contain secret keys and other sensitive values. A malicious user could be on the same network as a regular user and intercept all the secret keys the user is sending. This goes against…