Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2557▼ 320 respecto a la semana anterior
Críticas / altas1342▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
98 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.1) | 0.14% | — | Spice-space UsbredirAI | 21/9/2026 | 22/9/2026 | An out-of-bounds write flaw was found in usbredir. Starting an isochronous OUT stream with a transfer count of 1 leaves the stream's single transfer buffer permanently unsubmitted, defeating the bounds check in usbredirhost_iso_packet() and allowing a usbredir peer to write past the end of the packet descriptor array… | |
| Pendiente de análisis | Baja (3.7) | 0.34% | — | Authzed SpicedbAI | 14/9/2026 | 30/9/2026 | SpiceDB is an open source database system for creating and managing security-critical application permissions. From 1.34.0 until 1.54.0, SpiceDB can return PERMISSIONSHIP_HAS_PERMISSION instead of PERMISSIONSHIP_CONDITIONAL_PERMISSION or PERMISSIONSHIP_NO_PERMISSION because checkRequestToKey() and… | |
| Analizada | Media (4.4) | 0.13% | — | Redhat Enterprise LinuxSpice-space Spice-vdagent | 29/6/2026 | 8/7/2026 | A path traversal vulnerability was found in spice-vdagent. This flaw allows a malicious or compromised SPICE host to write arbitrary files to any location on the guest operating system. This occurs because the filename provided by the SPICE host during file transfers is not properly sanitized before being used. An… | |
| Analizada | Media (5.1) | 0.11% | — | Redhat Enterprise LinuxSpice-space Spice-vdagent | 29/6/2026 | 8/7/2026 | A flaw was found in spice-vdagent. A malicious or compromised SPICE host can trigger an integer overflow by sending a specially crafted message. This vulnerability can lead to a heap buffer overflow, causing the spice-vdagent daemon to crash and resulting in a Denial of Service (DoS) for the virtual machine. This… | |
| Aplazada | Baja (2.3) | 0.35% | — | Authzed SpicedbAI | 10/6/2026 | 23/7/2026 | SpiceDB is an open source database system for creating and managing security-critical application permissions. From version 1.15.0 to before version 1.52.0, caveat structures with nested lists can result in improper cache reuse. This issue has been patched in version 1.52.0. | |
| Aplazada | Crítica (9.3) | 0.43% | — | UserspiceAI | 23/5/2026 | 23/7/2026 | userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by sending POST requests to the existingUsernameCheck.php endpoint. Attackers can submit usernames and analyze response text for the 'taken' string to identify existing accounts in the… | |
| Aplazada | Media (5.1) | 0.15% | — | UserspiceAI | 23/5/2026 | 23/7/2026 | userSpice 4.3.24 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the X-Forwarded-For HTTP header. Attackers can send crafted requests to the backup.php endpoint with XSS payloads in the X-Forwarded-For header that execute when administrators visit the audit log… | |
| Aplazada | Alta (8.7) | 0.56% | — | SpicejetAI | 23/4/2026 | 17/6/2026 | A weakness in SpiceJet’s public booking retrieval page permits full passenger booking details to be accessed using only a PNR and last name, with no authentication or verification mechanisms. This results in exposure of extensive personal, travel, and booking metadata to any unauthenticated user who can obtain or… | |
| Aplazada | Alta (8.7) | 0.42% | — | Spicejet Booking APIAI | 23/4/2026 | 17/6/2026 | A vulnerability in SpiceJet’s booking API allows unauthenticated users to query passenger name records (PNRs) without any access controls. Because PNR identifiers follow a predictable pattern, an attacker could systematically enumerate valid records and obtain associated passenger names. This flaw stems from missing… | |
| Analizada | Media (4.4) | 0.18% | — | Authzed Spicedb | 15/4/2026 | 17/6/2026 | SpiceDB is an open source database system for creating and managing security-critical application permissions. In versions 1.49.0 through 1.51.0, when SpiceDB starts with log level info, the startup "configuration" log will include the full datastore DSN, including the plaintext password, inside DatastoreConfig.URI.… | |
| Aplazada | Alta (8.8) | 0.20% | — | Spicethemes SpicepressAI | 8/4/2026 | 24/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in spicethemes SpicePress spicepress allows Upload a Web Shell to a Web Server.This issue affects SpicePress: from n/a through <= 2.3.2.5. | |
| Aplazada | Media (6.6) | 0.28% | — | Hallo Welt Gmbh Extension NsfilerepoAIHallowelt BluespiceAI | 4/3/2026 | 17/6/2026 | Files or Directories Accessible to External Parties, Incorrect Permission Assignment for Critical Resource vulnerability in Hallo Welt! GmbH BlueSpice (Extension:NSFileRepo modules) allows Accessing Functionality Not Properly Constrained by ACLs, Bypassing Electronic Locks and Access Controls.This issue affects… | |
| Aplazada | Alta (8.8) | 0.35% | — | Spicethemes NewsbloggerAI | 19/2/2026 | 14/9/2026 | The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.5.9. This is due to missing or incorrect nonce validation on the newsblogger_install_and_activate_plugin() function. This makes it possible for unauthenticated attackers to upload arbitrary files and achieve… | |
| Aplazada | Media (6.4) | 0.21% | — | SpiceformsAI | 14/1/2026 | 17/6/2026 | The SpiceForms Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'spiceforms' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Baja (2.9) | 0.22% | — | Authzed Spicedb | 21/11/2025 | 17/6/2026 | SpiceDB is an open source database system for creating and managing security-critical application permissions. Prior to version 1.47.1, if a schema includes the following characteristics: permission defined in terms of a union (+) and that union references the same relation on both sides (but one side arrows to a… | |
| Analizada | Baja (2.7) | 0.25% | — | Authzed Spicedb | 10/11/2025 | 17/6/2026 | SpiceDB is an open source database system for creating and managing security-critical application permissions. In versions prior to 1.45.2, users who use the exclusion operator somewhere in their authorization schema; have configured their SpiceDB server such that `--write-relationships-max-updates-per-call` is bigger… | |
| Analizada | Media (5.9) | 0.18% | — | Hallowelt Bluespice | 19/9/2025 | 17/6/2026 | Improper Input Validation vulnerability in Hallo Welt! GmbH BlueSpice (Extension:CognitiveProcessDesigner) allows Cross-Site Scripting (XSS).This issue affects BlueSpice: from 5 through 5.1.1. | |
| Analizada | Media (5.9) | 0.18% | — | Hallowelt Bluespice | 19/9/2025 | 17/6/2026 | Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:BlueSpiceWhoIsOnline) allows Cross-Site Scripting (XSS). This issue affects BlueSpice: from 5 through 5.1.1. | |
| Analizada | Media (5.9) | 0.19% | — | Hallowelt Bluespice | 19/9/2025 | 17/6/2026 | Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:BlueSpiceAvatars) allows Cross-Site Scripting (XSS). This issue affects BlueSpice: from 5 through 5.1.1. | |
| Analizada | Media (5.9) | 0.19% | — | Hallowelt Bluespice | 19/9/2025 | 17/6/2026 | Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:AtMentions) allows Cross-Site Scripting (XSS). This issue affects BlueSpice: from 5 through 5.1.1. | |
| Aplazada | Alta (7.5) | 0.50% | — | Spicethemes Spice BlocksAI | 9/6/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spicethemes Spice Blocks spice-blocks allows Path Traversal.This issue affects Spice Blocks: from n/a through <= 2.0.7.4. | |
| Analizada | Media (5.3) | 0.32% | — | Authzed Spicedb | 6/6/2025 | 17/6/2026 | SpiceDB is an open source database for storing and querying fine-grained authorization data. Prior to version 1.44.2, on schemas involving arrows with caveats on the arrow’ed relation, when the path to resolve a CheckPermission request involves the evaluation of multiple caveated branches, requests may return a… | |
| Analizada | Alta (8.8) | 0.39% | — | Spicethemes Newsblogger | 1/5/2025 | 17/6/2026 | The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2.5.4. This is due to missing or incorrect nonce validation on the newsblogger_install_and_activate_plugin() function. This makes it possible for unauthenticated attackers to upload arbitrary files… | |
| Analizada | Alta (8.8) | 1.1% | — | Spicethemes Newsblogger | 1/5/2025 | 17/6/2026 | The NewsBlogger theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the newsblogger_install_and_activate_plugin() function in all versions up to, and including, 0.2.5.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload… | |
| Aplazada | Alta (7.5) | 0.38% | — | Spicethemes Spice BlocksAI | 17/4/2025 | 17/6/2026 | Missing Authorization vulnerability in spicethemes Spice Blocks spice-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spice Blocks: from n/a through <= 2.0.7.7. |