Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2561▼ 314 respecto a la semana anterior
Críticas / altas1347▲ 83 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
8712 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Sin puntuar | 0.27% | — | Modelscope AgentscopeAI | 2/10/2026 | 2/10/2026 | agentscope v1.0.20 contains code injection in execute_shell_command (src/agentscope/tool/_coding/_shell.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution. | |
| Pendiente de análisis | Crítica (9.4) | 0.40% | — | Discord LibdaveAI | 2/10/2026 | 2/10/2026 | Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling messages to a client) could cause affected… | |
| Aplazada | Crítica (9.8) | 0.33% | — | Modelscope AgentscopeAI | 30/9/2026 | 1/10/2026 | In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to call that tool and run Python code in the service environment. In the validated path, RealtimeAgent._acting forwards the model-produced tool call to… | |
| Aplazada | Alta (8.1) | 0.30% | — | Modelscope AgentscopeAI | 30/9/2026 | 2/10/2026 | modelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert_text_file. | |
| Aplazada | Alta (8.1) | 0.32% | — | Modelscope AgentscopeAI | 30/9/2026 | 1/10/2026 | modelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write_text_file. | |
| Aplazada | Alta (7.6) | 0.28% | — | Quanticedgesolutions Category Discount WoocommerceAI | 30/9/2026 | 30/9/2026 | Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions. | |
| Analizada | Crítica (9.8) | 1.6% | ⚠ Explotación activa | Cisco Catalyst Sd-wan Manager | 30/9/2026 | 2/10/2026 | A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request… | |
| Aplazada | Media (5.3) | 0.18% | — | Openclaw DiscordAI | 26/9/2026 | 28/9/2026 | OpenClaw Discord versions before 2026.7.1 contain an authorization bypass vulnerability in guild metadata read actions that allows lower-trust senders to retrieve information excluded by channel allowlists. Attackers can bypass the configured Discord read-target policy to access guild metadata from servers or channels… | |
| Aplazada | Media (6) | 0.28% | — | Openclaw DiscordAI | 26/9/2026 | 28/9/2026 | OpenClaw's Discord integration (npm package @openclaw/discord) before version 2026.9.3 could lose the sender-scoped media policy in the emoji and sticker upload actions before loading a local file. A sender permitted to invoke those actions could cause OpenClaw to read a host path that the same sender's configured… | |
| Aplazada | Media (5) | 0.26% | — | DiscourseAI | 24/9/2026 | 24/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, attacker-controlled upload filenames used in chat message excerpts were rendered as unescaped HTML. A user able to upload a file and send chat content could place markup in a filename that was then interpreted by chat… | |
| Aplazada | Media (5.4) | 0.20% | — | DiscourseAI | 24/9/2026 | 24/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, provider-controlled video titles in lazy video embeds could be reparsed as HTML when Discourse generated notification emails or chat summaries. A user with standard posting privileges could create a post for an… | |
| Aplazada | Media (6.4) | 0.20% | — | DiscourseAI | 24/9/2026 | 28/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the topic small-action and nested-activity-log components interpolated the free-form action_code_who value into mention-link href attributes without URL encoding. A quote-bearing display name could terminate the… | |
| Aplazada | Media (5.4) | 0.22% | — | DiscourseAI | 24/9/2026 | 29/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the Discourse post sanitizer allowed a stored cross-origin iframe to bypass the allowed_iframes prefix policy when the iframe src contained encoded userinfo. The sanitizer validated a decoded form differently from the… | |
| Aplazada | Media (6.5) | 0.29% | — | DiscourseAI | 24/9/2026 | 24/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, authenticated users could supply unescaped SQL LIKE metacharacters to upload-resolution patterns, causing wildcard input to select unrelated upload records instead of matching a literal identifier. The affected upload… | |
| Aplazada | Media (4.3) | 0.14% | — | DiscourseAI | 24/9/2026 | 29/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, sites using wildcard patterns in the allowed_iframes setting could accept a crafted iframe URL whose allowlisted suffix appeared after a URL authority separator. The wildcard origin check matched the allowed domain… | |
| Aplazada | Alta (7.2) | 0.29% | — | DiscourseAI | 24/9/2026 | 24/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the iframe src traversal guard did not treat literal backslashes as path separators after decoded dot segments. A crafted source could therefore pass an allowed_iframes subpath check while browser URL normalization… | |
| Aplazada | Alta (8.7) | 0.26% | — | DiscourseAI | 24/9/2026 | 24/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the video placeholder component allowed crafted HTML to cause an attribute breakout and inject an attacker-controlled event handler. An authenticated user with default trust-level posting privileges could store the… | |
| Aplazada | Media (4.2) | 0.24% | — | Discourse AIAI | 24/9/2026 | 24/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Discourse AI reviewables associated with private messages could appear in the moderator review queue of a moderator who was not a participant in the message. Reviewable visibility filtering did not restrict… | |
| Pendiente de análisis | Media (5.3) | 0.41% | — | Projectdiscovery NucleiAI | 22/9/2026 | 23/9/2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST/fuzz payload path in pkg/fuzz/parts.go can evaluate substituted runtime data more than once, creating a second evaluation pass that allows response content captured by an internal: true extractor in one protocol step… | |
| Pendiente de análisis | Media (5.5) | 0.17% | — | Projectdiscovery NucleiAI | 22/9/2026 | 28/9/2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the workflow template loading path does not enforce the -file capability gate when resolving file: protocol templates referenced by a workflow. An untrusted unsigned workflow can therefore load a file-protocol template and… | |
| Pendiente de análisis | Media (5.3) | 0.40% | — | Projectdiscovery NucleiAI | 22/9/2026 | 25/9/2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the nuclei/mysql JavaScript library does not enforce the local-file sandbox when a JavaScript template supplies the allowAllFiles MySQL DSN option. An untrusted javascript: template scanning an attacker-controlled… | |
| Pendiente de análisis | Media (4.7) | 0.18% | — | Projectdiscovery NucleiAI | 22/9/2026 | 24/9/2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST template loading branch does not apply the unsigned code-template signature check before accepting a template that contains both a fuzzing: block and an unsigned code: block. When an operator enables -dast, an… | |
| Aplazada | Media (5.4) | 0.29% | — | DiscourseAI | 21/9/2026 | 23/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.7.0, the post action component failed to escape user-controlled display names before interpolating them into an HTML string passed to trustHTML. A user who could choose a crafted display name could persist markup in post action descriptions. Viewing the… | |
| Aplazada | Media (5.3) | 0.21% | — | Spatie ScottyAI | 18/9/2026 | 18/9/2026 | A vulnerability was identified in spatie Scotty up to 1.4.2. Affected is the function SelfUpdater::update of the file app/Updater/SelfUpdater.php of the component Self Update Handler. Such manipulation leads to download of code without integrity check. It is possible to launch the attack remotely. Upgrading to version… | |
| Aplazada | Media (5.3) | 1.4% | — | Spatie ScottyAI | 18/9/2026 | 23/9/2026 | A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivity/DoctorCommand::checkRemoteTools of the file app/Commands/DoctorCommand.php of the component Doctor Command Handler. This manipulation of the argument host causes os command injection. It is… |