Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
170 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.6) | 0.22% | — | Tiger-gh-mcp-serverAI | 27/8/2026 | 23/9/2026 | tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host it named, making the locally reachable… | |
| Aplazada | Alta (7.6) | 0.22% | — | Tiger-slackAISlack MCPAI | 27/8/2026 | 23/9/2026 | tiger-slack started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. mcp/src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host it named, and a page in a browser could… | |
| Analizada | Alta (7.9) | 0.54% | — | Tigera Calico | 30/7/2026 | 8/8/2026 | Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a result, HTTP requests using path-traversal segments, encoded slashes, or repeated slashes are not correctly evaluated by Prefix path rules. Dikastes authorizes the request… | |
| Analizada | Media (6.2) | 0.39% | — | Tigera Calico | 30/7/2026 | 8/8/2026 | Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy, GlobalNetworkPolicy, and their staged variants is not invoked for DeleteCollection requests. A user holding the deletecollection verb or wildcard verbs on tier-scoped… | |
| Analizada | Media (6) | 0.67% | — | Tigera Calico | 30/7/2026 | 8/8/2026 | When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication. Any pod with network reachability to the listener can retrieve the process heap, goroutine stacks (including function arguments),… | |
| Aplazada | Media (5.3) | 0.29% | — | Presstigers Universal ClocksAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in PressTigers Universal Clocks universal-clocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Universal Clocks: from n/a through <= 1.2.0. | |
| Aplazada | Alta (8.6) | 1.2% | — | Vtiger CRMAI | 7/7/2026 | 8/7/2026 | Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-level attackers to upload arbitrary PHP files by submitting a crafted zip archive through the ModuleManager import function, which extracts contents directly into the… | |
| Aplazada | Alta (8.7) | 1.00% | — | Vtiger CRMAIApache Http ServerAI | 7/7/2026 | 8/7/2026 | Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uploading a .phar file containing arbitrary PHP code through the Documents module, bypassing the extension denylist in config.inc.php which omits the .phar extension. The… | |
| Analizada | Media (6) | 0.34% | — | Tigera Calico | 28/5/2026 | 17/6/2026 | When Calico is configured with the Azure IPAM plugin, the Calico CNI binary mutates the incoming CNI configuration to attach subnet information before delegating to the IPAM plugin. After mutating, the Azure IPAM helper logs the entire unmarshaled configuration map (stdinData) at INFO level to… | |
| Analizada | Media (6) | 0.53% | — | Tigera Calico | 28/5/2026 | 17/6/2026 | In Calico, the install-cni init container logs the rendered CNI configuration to standard output. When the configuration template uses the __SERVICEACCOUNT_TOKEN__ placeholder (Canal/Flannel-Calico deployments), the installer substitutes the live Kubernetes ServiceAccount bearer token before logging, exposing the… | |
| Aplazada | Media (6.1) | 0.26% | — | Vtiger CRMAI | 13/4/2026 | 17/6/2026 | A HTML Injection vulnerability exists in the Dashboard module of Vtiger CRM 8.4.0. The application fails to properly neutralize user-supplied input in the tabid parameter of the DashBoardTab view (getTabContents action), allowing an attacker to inject arbitrary HTML content into the dashboard interface. The injected… | |
| Aplazada | Media (5.4) | 0.14% | — | Vtiger CRMAI | 13/4/2026 | 17/6/2026 | Vtiger CRM 8.4.0 contains a reflected cross-site scripting (XSS) vulnerability in the MailManager module. Improper handling of user-controlled input in the _folder parameter allows a specially crafted, double URL-encoded payload to be reflected and executed in the context of an authenticated user s session. | |
| Modificada | Crítica (9.8) | 0.42% | — | Tigervnc | 26/3/2026 | 17/6/2026 | In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, because of incorrect permissions. | |
| Aplazada | Alta (8.1) | 0.58% | — | Themerex Tiger ClawAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Tiger Claw tiger-claw allows PHP Local File Inclusion.This issue affects Tiger Claw: from n/a through <= 1.1.14. | |
| Aplazada | Media (4.3) | 0.13% | — | Presstigers Simple FolioAI | 9/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PressTigers Simple Folio simple-folio allows Cross Site Request Forgery.This issue affects Simple Folio: from n/a through <= 1.1.0. | |
| Aplazada | Alta (8.8) | 0.28% | — | TigerAI | 27/11/2025 | 17/6/2026 | The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This is due to the plugin allowing a user to update the user role through the $user->set_role() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Crítica (9.8) | 0.35% | — | TigerAI | 27/11/2025 | 17/6/2026 | The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This is due to the 'paypal-submit.php' file not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during… | |
| Aplazada | Alta (7.5) | 0.39% | — | Presstigers Simple JOB BoardAI | 22/10/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in PressTigers Simple Job Board simple-job-board allows Retrieve Embedded Sensitive Data.This issue affects Simple Job Board: from n/a through <= 2.13.7. | |
| Aplazada | Media (5.9) | 0.15% | — | Logo Software INC Tigerwings ERPAI | 3/10/2025 | 17/6/2026 | Use of Hard-coded Credentials vulnerability in Logo Software Inc. TigerWings ERP allows Read Sensitive Constants Within an Executable. This issue affects TigerWings ERP: from 01.01.00 before 3.03.00. | |
| Aplazada | Alta (7.6) | 0.28% | — | Presstigers ZIP Code Based Content ProtectionAI | 9/9/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PressTigers ZIP Code Based Content Protection zip-code-based-content-protection allows SQL Injection.This issue affects ZIP Code Based Content Protection: from n/a through <= 1.0.0. | |
| Analizada | Alta (7.2) | 0.45% | — | Vtiger CRM | 21/5/2025 | 17/6/2026 | A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the ZIP import functionality in the Module Import feature. | |
| Analizada | Media (6.1) | 0.29% | — | Vtiger CRM | 21/5/2025 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Vtiger CRM Open Source Edition v8.3.0, exploitable via the Services Import feature. An attacker can craft a malicious CSV file containing an XSS payload, mapped to the Service Name field. When the file is uploaded, the application improperly sanitizes user… | |
| Modificada | Media (6.1) | 0.28% | — | Jocoxdesign Tiger | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jocoxdesign Tiger tiger allows Reflected XSS.This issue affects Tiger: from n/a through 2.0. | |
| Analizada | Baja (3.7) | 0.40% | — | Presstigers Simple JOB Board | 15/5/2025 | 17/6/2026 | The Simple Job Board WordPress plugin before 2.12.6 does not prevent uploaded files from being listed, allowing unauthenticated users to access and download uploaded resumes | |
| Analizada | Media (6.1) | 0.36% | — | Presstigers Simple JOB Board | 15/5/2025 | 17/6/2026 | In the process of testing the Simple Job Board WordPress plugin before 2.12.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor |