Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2727▼ 85 respecto a la semana anterior
Críticas / altas1416▲ 186 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)101▼ 398 respecto a la semana anterior
105 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.13% | — | Root Browser ClassicAI | 24/9/2026 | 25/9/2026 | Root Browser Classic 3.3.0 passes the path of a selected SQLite database to an operating-system shell without safely separating the filename from the command. | |
| Aplazada | Baja (2) | 0.30% | — | Rootcodeinc Roo-codeAI | 28/8/2026 | 28/8/2026 | A security vulnerability has been detected in RooCodeInc Roo-Code up to 3.51.1. This affects the function fetch_instructions of the file malicious_mcp_server.py of the component MCP Integration Trust Model. The manipulation leads to code injection. The attack is possible to be carried out remotely. The exploit has… | |
| Aplazada | Alta (7) | 0.27% | — | CorootAI | 25/8/2026 | 23/9/2026 | Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to register clients pointing to attacker-controlled hosts. Attackers can send authorization URLs to signed-in users, capture their authorization codes upon consent… | |
| Aplazada | Baja (2.4) | 0.15% | — | BrootAI | 20/8/2026 | 24/9/2026 | broot renders each file and directory name in its interactive tree view exactly as read from the filesystem. Names are converted with a plain to_string_lossy() call in src/tree_build/builder.rs and in TreeLine::unprune in src/tree/tree_line.rs, and no control-character filtering exists anywhere in the code, even… | |
| Aplazada | Media (5.4) | 0.24% | — | Cube-root Directory-serveAI | 10/8/2026 | 3/9/2026 | A stored cross-site scripting (XSS) vulnerability in cube-root/directory-serve through 1.3.7 allows an attacker to inject arbitrary JavaScript into the web interface by uploading a file with a crafted filename containing HTML attribute-breaking characters. | |
| Aplazada | Crítica (9.1) | 0.74% | — | Cube Root Directory ServeAI | 10/8/2026 | 28/8/2026 | A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to delete arbitrary files outside the intended served directory when the application is run with the --delete option. | |
| Aplazada | Alta (8.2) | 0.18% | — | Proot-distroAI | 29/7/2026 | 30/7/2026 | proot-distro is a utility for managing proot containers. Prior to version 5.1.6, proot-distro restore accepted hardlink entries whose linkname referenced another installed container and did not verify that the hardlink source container matched the destination container being restored, allowing a crafted restore… | |
| Aplazada | Alta (8.2) | 0.19% | — | Proot-distroAI | 29/7/2026 | 30/7/2026 | proot-distro is a utility for managing proot containers. Prior to version 5.1.5, proot-distro install extracted plain tarball root filesystems through _extract_plain_tar() in proot_distro/commands/install.py and Docker layers through _apply_layer() in proot_distro/helpers/docker.py without validating… | |
| Aplazada | Alta (8.5) | 0.22% | — | UprootAI | 18/7/2026 | 28/8/2026 | uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime. Some file-controlled streamer metadata fields (for example, streamer element names) are interpolated into the generated Python source without safe quoting via repr() or the !r format specifier.… | |
| Pendiente de análisis | Media (5.3) | 0.21% | — | Avast Windows Anti RootkitAIAVG Windows Anti RootkitAI | 8/5/2026 | 17/6/2026 | The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) due to a double fetch vulnerability at aswArPot+0xbb94. | |
| Pendiente de análisis | Alta (7.8) | 0.18% | — | Avast Windows Anti RootkitAIAVG Windows Anti RootkitAI | 8/5/2026 | 17/6/2026 | The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) due to a double fetch vulnerability at aswArPot+0xc4a3. | |
| Pendiente de análisis | Alta (8.7) | 0.61% | — | Grassroots GdcmAI | 26/3/2026 | 17/6/2026 | A memory leak exists in the Grassroots DICOM library (GDCM). The bug occurs when parsing malformed DICOM files with non-standard VR types in file meta information. The vulnerability leads to vast memory allocations and resource depletion, triggering a denial-of-service condition. A maliciously crafted file can fill… | |
| Aplazada | Media (6.9) | 0.40% | — | SpinwasmAIContainerd-shim-spinAISpinroot SpinAI | 26/2/2026 | 17/6/2026 | Spin is an open source developer tool for building and running serverless applications powered by WebAssembly. When Spin is configured to allow connections to a database or web server which could return responses of unbounded size (e.g. tables with many rows or large content bodies), Spin may in some cases attempt to… | |
| Aplazada | Alta (8.7) | 0.29% | — | Abcz316 Skroot-linuxkernelrootAI | 27/1/2026 | 17/6/2026 | NULL Pointer Dereference vulnerability in abcz316 SKRoot-linuxKernelRoot (testRoot/jni/utils modules). This vulnerability is associated with program files cJSON.Cpp. This issue affects SKRoot-linuxKernelRoot. | |
| Aplazada | Crítica (9.3) | 0.30% | — | Root Project RootAI | 27/1/2026 | 17/6/2026 | Vulnerability in root-project root (builtins/zlib modules). This vulnerability is associated with program files inftrees.C. This issue affects root: through 6.36.00-rc1. | |
| Modificada | Crítica (9.3) | 0.34% | — | Root | 27/1/2026 | 17/6/2026 | Vulnerability in root-project root (builtins/zlib modules). This vulnerability is associated with program files inffast.C. This issue affects root. | |
| Analizada | Crítica (9.1) | 0.34% | — | Malaterre Grassroots Dicom | 16/12/2025 | 17/6/2026 | An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to an information leak. An attacker can provide a malicious file to trigger this vulnerability.The function `null_convert` is called based of the value of the… | |
| Analizada | Crítica (9.1) | 0.32% | — | Malaterre Grassroots Dicom | 16/12/2025 | 17/6/2026 | An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to an information leak. An attacker can provide a malicious file to trigger this vulnerability.The function `grayscale_convert` is called based of the value of… | |
| Analizada | Alta (7.5) | 0.41% | — | Malaterre Grassroots Dicom | 16/12/2025 | 17/6/2026 | An out-of-bounds read vulnerability exists in the Overlay::GrabOverlayFromPixelData functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to an information leak. An attacker can provide a malicious file to trigger this vulnerability. | |
| Analizada | Crítica (9.1) | 0.43% | — | Malaterre Grassroots Dicom | 16/12/2025 | 17/6/2026 | An out-of-bounds read vulnerability exists in the RLECodec::DecodeByStreams functionality of Grassroot DICOM 3.024. A specially crafted DICOM file can lead to leaking heap data. An attacker can provide a malicious file to trigger this vulnerability. | |
| Aplazada | Media (6.8) | 0.15% | — | Grassroots GdcmAI | 12/12/2025 | 17/6/2026 | An out-of-bounds write vulnerability exists in the Grassroots DICOM library (GDCM). The issue is triggered during parsing of a malformed DICOM file containing encapsulated PixelData fragments (compressed image data stored as multiple fragments). This vulnerability leads to a segmentation fault caused by an… | |
| Aplazada | Alta (7.8) | 0.14% | — | Kingosoft Technology LTD Kingo RootAI | 29/10/2025 | 17/6/2026 | An unquoted service path in Kingosoft Technology Ltd Kingo ROOT v1.5.8.3353 allows attackers to escalate privileges via placing a crafted executable file into a parent folder. | |
| Analizada | Baja (2) | 0.38% | — | Roothub | 26/7/2025 | 17/6/2026 | A vulnerability was found in Roothub up to 2.6. It has been declared as problematic. Affected by this vulnerability is the function Edit of the file src/main/java/cn/roothub/web/admin/SystemConfigAdminController.java. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has… | |
| Aplazada | Media (5.3) | 0.26% | — | Ed4becky RootspersonaAI | 19/5/2025 | 17/6/2026 | Missing Authorization vulnerability in ed4becky Rootspersona rootspersona allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rootspersona: from n/a through <= 3.7.5. | |
| Aplazada | Media (5.4) | 0.14% | — | Ed4becky RootspersonaAI | 19/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ed4becky Rootspersona rootspersona allows Cross Site Request Forgery.This issue affects Rootspersona: from n/a through <= 3.7.5. |