Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2727▼ 85 respecto a la semana anterior
Críticas / altas1416▲ 186 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)101▼ 398 respecto a la semana anterior
–

105 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.5)0.13%—Root Browser ClassicAI24/9/202625/9/2026
Root Browser Classic 3.3.0 passes the path of a selected SQLite database to an operating-system shell without safely separating the filename from the command.
AplazadaBaja (2)0.30%—Rootcodeinc Roo-codeAI28/8/202628/8/2026
A security vulnerability has been detected in RooCodeInc Roo-Code up to 3.51.1. This affects the function fetch_instructions of the file malicious_mcp_server.py of the component MCP Integration Trust Model. The manipulation leads to code injection. The attack is possible to be carried out remotely. The exploit has…
AplazadaAlta (7)0.27%—CorootAI25/8/202623/9/2026
Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to register clients pointing to attacker-controlled hosts. Attackers can send authorization URLs to signed-in users, capture their authorization codes upon consent…
AplazadaBaja (2.4)0.15%—BrootAI20/8/202624/9/2026
broot renders each file and directory name in its interactive tree view exactly as read from the filesystem. Names are converted with a plain to_string_lossy() call in src/tree_build/builder.rs and in TreeLine::unprune in src/tree/tree_line.rs, and no control-character filtering exists anywhere in the code, even…
AplazadaMedia (5.4)0.24%—Cube-root Directory-serveAI10/8/20263/9/2026
A stored cross-site scripting (XSS) vulnerability in cube-root/directory-serve through 1.3.7 allows an attacker to inject arbitrary JavaScript into the web interface by uploading a file with a crafted filename containing HTML attribute-breaking characters.
AplazadaCrítica (9.1)0.74%—Cube Root Directory ServeAI10/8/202628/8/2026
A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to delete arbitrary files outside the intended served directory when the application is run with the --delete option.
AplazadaAlta (8.2)0.18%—Proot-distroAI29/7/202630/7/2026
proot-distro is a utility for managing proot containers. Prior to version 5.1.6, proot-distro restore accepted hardlink entries whose linkname referenced another installed container and did not verify that the hardlink source container matched the destination container being restored, allowing a crafted restore…
AplazadaAlta (8.2)0.19%—Proot-distroAI29/7/202630/7/2026
proot-distro is a utility for managing proot containers. Prior to version 5.1.5, proot-distro install extracted plain tarball root filesystems through _extract_plain_tar() in proot_distro/commands/install.py and Docker layers through _apply_layer() in proot_distro/helpers/docker.py without validating…
AplazadaAlta (8.5)0.22%—UprootAI18/7/202628/8/2026
uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime. Some file-controlled streamer metadata fields (for example, streamer element names) are interpolated into the generated Python source without safe quoting via repr() or the !r format specifier.…
Pendiente de análisisMedia (5.3)0.21%—Avast Windows Anti RootkitAIAVG Windows Anti RootkitAI8/5/202617/6/2026
The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) due to a double fetch vulnerability at aswArPot+0xbb94.
Pendiente de análisisAlta (7.8)0.18%—Avast Windows Anti RootkitAIAVG Windows Anti RootkitAI8/5/202617/6/2026
The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) due to a double fetch vulnerability at aswArPot+0xc4a3.
Pendiente de análisisAlta (8.7)0.61%—Grassroots GdcmAI26/3/202617/6/2026
A memory leak exists in the Grassroots DICOM library (GDCM). The bug occurs when parsing malformed DICOM files with non-standard VR types in file meta information. The vulnerability leads to vast memory allocations and resource depletion, triggering a denial-of-service condition. A maliciously crafted file can fill…
AplazadaMedia (6.9)0.40%—SpinwasmAIContainerd-shim-spinAISpinroot SpinAI26/2/202617/6/2026
Spin is an open source developer tool for building and running serverless applications powered by WebAssembly. When Spin is configured to allow connections to a database or web server which could return responses of unbounded size (e.g. tables with many rows or large content bodies), Spin may in some cases attempt to…
AplazadaAlta (8.7)0.29%—Abcz316 Skroot-linuxkernelrootAI27/1/202617/6/2026
NULL Pointer Dereference vulnerability in abcz316 SKRoot-linuxKernelRoot (testRoot/jni/utils modules). This vulnerability is associated with program files cJSON.Cpp. This issue affects SKRoot-linuxKernelRoot.
AplazadaCrítica (9.3)0.30%—Root Project RootAI27/1/202617/6/2026
Vulnerability in root-project root (builtins/zlib modules). This vulnerability is associated with program files inftrees.C. This issue affects root: through 6.36.00-rc1.
ModificadaCrítica (9.3)0.34%—Root27/1/202617/6/2026
Vulnerability in root-project root (builtins/zlib modules). This vulnerability is associated with program files inffast.C. This issue affects root.
AnalizadaCrítica (9.1)0.34%—Malaterre Grassroots Dicom16/12/202517/6/2026
An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to an information leak. An attacker can provide a malicious file to trigger this vulnerability.The function `null_convert` is called based of the value of the…
AnalizadaCrítica (9.1)0.32%—Malaterre Grassroots Dicom16/12/202517/6/2026
An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to an information leak. An attacker can provide a malicious file to trigger this vulnerability.The function `grayscale_convert` is called based of the value of…
AnalizadaAlta (7.5)0.41%—Malaterre Grassroots Dicom16/12/202517/6/2026
An out-of-bounds read vulnerability exists in the Overlay::GrabOverlayFromPixelData functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to an information leak. An attacker can provide a malicious file to trigger this vulnerability.
AnalizadaCrítica (9.1)0.43%—Malaterre Grassroots Dicom16/12/202517/6/2026
An out-of-bounds read vulnerability exists in the RLECodec::DecodeByStreams functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to leaking heap data. An attacker can provide a malicious file to trigger this vulnerability.
AplazadaMedia (6.8)0.15%—Grassroots GdcmAI12/12/202517/6/2026
An out-of-bounds write vulnerability exists in the Grassroots DICOM library (GDCM). The issue is triggered during parsing of a malformed DICOM file containing encapsulated PixelData fragments (compressed image data stored as multiple fragments). This vulnerability leads to a segmentation fault caused by an…
AplazadaAlta (7.8)0.14%—Kingosoft Technology LTD Kingo RootAI29/10/202517/6/2026
An unquoted service path in Kingosoft Technology Ltd Kingo ROOT v1.5.8.3353 allows attackers to escalate privileges via placing a crafted executable file into a parent folder.
AnalizadaBaja (2)0.38%—Roothub26/7/202517/6/2026
A vulnerability was found in Roothub up to 2.6. It has been declared as problematic. Affected by this vulnerability is the function Edit of the file src/main/java/cn/roothub/web/admin/SystemConfigAdminController.java. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has…
AplazadaMedia (5.3)0.26%—Ed4becky RootspersonaAI19/5/202517/6/2026
Missing Authorization vulnerability in ed4becky Rootspersona rootspersona allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rootspersona: from n/a through <= 3.7.5.
AplazadaMedia (5.4)0.14%—Ed4becky RootspersonaAI19/5/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ed4becky Rootspersona rootspersona allows Cross Site Request Forgery.This issue affects Rootspersona: from n/a through <= 3.7.5.