Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3040▲ 560 respecto a la semana anterior
Críticas / altas1452▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
104 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.9) | — | — | Ansible-runnerAI | 1/10/2026 | 1/10/2026 | A flaw was found in ansible-runner. The unstream_dir() function, which receives and extracts a streamed zip archive on the worker side of the ansible-runner transmit/worker protocol, re-creates symbolic links from archive content without validating the link target and applies chmod() and utime() to an unsanitized… | |
| Aplazada | Crítica (9.4) | 0.44% | — | Gitea ACT RunnerAIACTAI | 28/6/2026 | 30/6/2026 | Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such as --pid=host, --cap-add, and --security-opt unchanged. A user… | |
| Aplazada | Alta (7.1) | 0.30% | — | Browserstack RunnerAI | 2/6/2026 | 22/7/2026 | BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the _default HTTP handler in lib/server.js that allows unauthenticated network-adjacent attackers to read arbitrary files. Attackers can exploit the unauthenticated HTTP server bound on all interfaces to traverse outside the project root and… | |
| Aplazada | Alta (8.7) | 0.67% | — | Browserstack RunnerAI | 2/6/2026 | 22/7/2026 | BrowserStack Runner through 0.9.5 contains a remote code execution vulnerability in the /_log HTTP handler that allows unauthenticated network-adjacent attackers to execute arbitrary code by submitting crafted JSON request bodies to the handler, which passes user-supplied data to vm.runInNewContext() combined with… | |
| Aplazada | Media (6.5) | 0.42% | — | Oinone PamirsAISupportsoft ScriptrunnerAI | 15/5/2026 | 17/6/2026 | Oinone Pamirs 7.0.0 contains a code execution vulnerability via ScriptRunner. The method ScriptRunner.run(String expression, String type, Map<String, Object> context) evaluates attacker-controlled script expressions through the underlying script engine without sandboxing or allowlist restrictions. | |
| Pendiente de análisis | Alta (8.7) | 0.44% | — | Code Runner MCP ServerAI | 12/5/2026 | 17/6/2026 | A remote code execution vulnerability exists in Code Runner MCP Server when run with the --transport http option, which exposes the /mcp JSON-RPC endpoint without authentication on port 3088. An unauthenticated remote attacker can invoke the run-code MCP tool to supply arbitrary source code and execute it via… | |
| Aplazada | Baja (2.1) | 1.8% | — | Privsim Mcp-test-runnerAI | 4/5/2026 | 17/6/2026 | A weakness has been identified in privsim mcp-test-runner 0.2.0. Impacted is the function child_process.spawn of the file src/index.ts of the component MCP Interface. Executing a manipulation of the argument command can lead to os command injection. The attack may be launched remotely. The exploit has been made… | |
| Aplazada | Media (6.9) | 0.15% | — | Asprunner ProfessionalAI | 5/4/2026 | 24/7/2026 | ASPRunner Professional 6.0.766 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by supplying an excessively long project name. Attackers can paste 180 or more characters into the Project name field during project creation to trigger an application crash. | |
| Analizada | Media (6.8) | 0.29% | — | Docker Model Runner | 1/4/2026 | 17/6/2026 | Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Prior to version 1.1.25, Docker Model Runner contains an SSRF vulnerability in its OCI registry token exchange flow. When pulling a model, Model Runner follows the realm URL from the registry's WWW-Authenticate header without… | |
| Aplazada | Media (6.9) | 0.13% | — | Asprunner.netAI | 22/3/2026 | 17/6/2026 | ASPRunner.NET 10.1 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the table name field. Attackers can input a buffer of 10000 characters in the table name parameter during database table creation to trigger an application crash. | |
| Aplazada | Media (6.9) | 0.16% | — | Xlinesoft PhprunnerAI | 22/3/2026 | 17/6/2026 | PHPRunner 10.1 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the dashboard name field. Attackers can paste a buffer of 10000 characters into the Name field during dashboard creation to trigger an application crash. | |
| Analizada | Media (4.6) | 0.48% | — | Stepsecurity Harden-runner | 20/3/2026 | 17/6/2026 | Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. In versions 2.15.1 and below, a DNS over HTTPS (DoH) vulnerability allows attackers to bypass egress-policy: block network restrictions by tunneling exfiltrated data through permitted HTTPS endpoints like dns.google. The attack… | |
| Analizada | Media (4.6) | 0.39% | — | Stepsecurity Harden-runner | 20/3/2026 | 17/6/2026 | Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. In versions 2.15.1 and below, the Harden-Runner that allows bypass of the egress-policy: block network restriction using DNS queries over TCP. Egress policies are enforced on GitHub runners by filtering outbound connections at… | |
| Aplazada | Alta (7.5) | 0.17% | — | Docker Model RunnerAIDocker DesktopAI | 27/2/2026 | 17/6/2026 | Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Versions prior to 1.0.16 expose a POST `/engines/_configure` endpoint that accepts arbitrary runtime flags without authentication. These flags are passed directly to the underlying inference server (llama.cpp). By injecting… | |
| Analizada | Alta (7.8) | 0.33% | — | Formulahendry Coderunner | 16/2/2026 | 17/6/2026 | An issue in the code-runner.executorMap setting of Visual Studio Code Extensions Code Runner v0.12.2 allows attackers to execute arbitrary code when opening a crafted workspace. | |
| Analizada | Media (6.3) | 0.36% | — | Stepsecurity Harden-runner | 9/2/2026 | 17/6/2026 | Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Prior to 2.14.2, a security vulnerability has been identified in the Harden-Runner GitHub Action (Community Tier) that allows outbound network connections to evade audit logging. Specifically, outbound traffic using the sendto,… | |
| Aplazada | Media (4.3) | 0.13% | — | Tmtraderunner Trade RunnerAI | 24/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in tmtraderunner Trade Runner traderunner allows Cross Site Request Forgery.This issue affects Trade Runner: from n/a through <= 3.14. | |
| Aplazada | Media (6.4) | 0.18% | — | Hotelrunner Booking WidgetAI | 21/11/2025 | 17/6/2026 | The HotelRunner Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hotelrunner' shortcode in all versions up to, and including, 5.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (4.3) | 0.25% | — | Jenkins Nexus Task Runner | 29/10/2025 | 17/6/2026 | A missing permission check in Jenkins Nexus Task Runner Plugin 0.9.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials. | |
| Modificada | Media (4.3) | 0.21% | — | Jenkins Nexus Task Runner | 29/10/2025 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Task Runner Plugin 0.9.2 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials. | |
| Analizada | Media (5.9) | 0.32% | — | Jenkins Eggplant Runner | 29/10/2025 | 17/6/2026 | Jenkins Eggplant Runner Plugin 0.0.1.301.v963cffe8ddb_8 and earlier sets the Java system property `jdk.http.auth.tunneling.disabledSchemes` to an empty value, disabling a protection mechanism of the Java runtime. | |
| Aplazada | Alta (7.1) | 0.13% | — | Integrationshotelrunner Hotelrunner Booking WidgetAI | 22/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in integrationshotelrunner HotelRunner Booking Widget hotelrunner allows Stored XSS.This issue affects HotelRunner Booking Widget: from n/a through <= 1.6. | |
| Aplazada | Media (4.7) | 0.20% | — | Hotelrunner B2BAI | 23/7/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in HotelRunner B2B allows Forceful Browsing. This issue affects B2B: before 04.06.2025. | |
| Aplazada | Media (4.6) | 0.10% | — | Hotelrunner B2BAI | 22/7/2025 | 17/6/2026 | Improper Validation of Certificate with Host Mismatch vulnerability in HotelRunner B2B allows HTTP Response Splitting. This issue affects B2B: before 04.06.2025. | |
| Aplazada | Media (4.8) | 0.18% | — | Hotelrunner B2BAI | 22/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HotelRunner B2B allows Cross-Site Scripting (XSS). This issue affects B2B: before 04.06.2025. |