Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
–

142 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.49%—Yeger Turbo-graphAIYeger Turbo-graph-uiAI15/9/202630/9/2026
Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by default, while the GET handler for /api/run in…
AplazadaMedia (6.5)0.36%—Libjpeg-turboAI26/8/20269/9/2026
libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability in the PNG loader. When processing a valid indexed-color PNG image with a non-gray palette through tj3LoadImage12() or tj3LoadImage16() using the default pixel format, the application may trigger a division-by-zero in alloc_sarray(), causing a…
Pendiente de análisisAlta (7.5)0.60%—Facebook React-server-dom-webpackAIFacebook React-server-dom-parcelAIFacebook React-server-dom-turbopackAI21/7/202621/7/2026
A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.7, 19.1.0…
AnalizadaAlta (7.5)0.45%—Shopify React-routerTurbo-stream Turbo Stream2/6/202622/7/2026
React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications…
AnalizadaAlta (8.4)0.24%—Vercel Turborepo Language Server Protocol15/5/202617/6/2026
Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14000, the Turborepo LSP VS Code extension could execute shell commands derived from workspace-controlled values. The extension used string-based command execution for Turborepo daemon commands and task runs. A malicious…
AnalizadaMedia (5.1)0.18%—Vercel Turborepo15/5/202617/6/2026
Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14, Turborepo's self-hosted login and SSO browser flows did not validate a CSRF state value on the localhost callback. While the CLI was waiting for authentication, a malicious web page could send a request to the local…
AnalizadaNinguna (0)0.64%—Vercel Turborepo15/5/202617/6/2026
Turborepo is a high-performance build system for JavaScript and TypeScript codebases. From 1.1.0 to before 2.9.14, Turborepo can be vulnerable to arbitrary code execution when run in untrusted repositories that contain malicious Yarn configuration. In affected versions, package manager detection executed yarn…
AplazadaAlta (8.8)0.23%—E-kalite Software Turboard For-sAI12/5/202617/6/2026
Incorrect Authorization vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard FOR-S allows Privilege Escalation. This issue affects Turboard FOR-S: from 7.01.2026 before 18.02.2026.
AnalizadaAlta (7.5)1.5%—Facebook React-server-dom-parcelFacebook React-server-dom-turbopackFacebook React-server-dom-webpack6/5/202612/8/2026
A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel,…
AnalizadaAlta (7.8)0.15%—IBM Turbonomic Prometurbo Agent30/4/202617/6/2026
IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, including unrestricted read access to all secrets. An attacker that compromises the operator or its service account can exfiltrate sensitive credentials, escalate privileges,…
Pendiente de análisisAlta (7.5)1.6%—Facebook React-server-dom-parcelAIFacebook React-server-dom-turbopackAIFacebook React-server-dom-webpackAI8/4/202625/7/2026
A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, and 19.2.0 through 19.2.4). The vulnerability is triggered by sending specially…
AplazadaAlta (7.5)0.51%—Redqteam Turbo ManagerAIPHPAI13/3/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in redqteam Turbo Manager turbo-manager allows PHP Local File Inclusion.This issue affects Turbo Manager: from n/a through < 4.0.8.
AplazadaMedia (6.7)0.32%—Hotwired TurboAI11/2/202617/6/2026
BOOTP Turbo 2.0 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the Structured Exception Handler (SEH). Attackers can generate a malicious payload of 2196 bytes with specific byte patterns to trigger an application crash and corrupt the SEH chain.
AplazadaCrítica (9.4)0.39%—E-kalite Software Hardware Engineering Design AND Internet Services Industry AND Trade LTD CO TurboardAI11/2/202617/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard allows Reflected XSS. This issue affects Turboard: from 2025.07 before 2026.02. NOTE: This CVE record…
AplazadaAlta (8.5)0.14%—Tftp TurboAI1/2/202617/6/2026
TFTP Turbo 4.6.1273 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be launched with LocalSystem permissions.
AplazadaAlta (8.5)0.17%—Dhcp TurboAI1/2/202617/6/2026
DHCP Turbo 4.61298 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code by exploiting the service binary path. Attackers can place malicious executables in the service path to gain elevated privileges when the service starts.
AplazadaAlta (8.5)0.14%—Hotwired TurboAI1/2/202617/6/2026
BOOTP Turbo 2.0.1214 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted executable path to inject malicious code that will be executed when the service starts with LocalSystem permissions.
AplazadaMedia (6.9)0.36%—Libjpeg-turboAINeka-nat CupochAI27/1/202617/6/2026
Out-of-bounds Write vulnerability in neka-nat cupoch (third_party/libjpeg-turbo/libjpeg-turbo modules). This vulnerability is associated with program files tjbench.C. This issue affects cupoch.
AnalizadaMedia (4.8)0.28%—Hotwired Turbo20/1/202617/6/2026
Race condition in the turbo-frame element handler in Hotwired Turbo before 8.0.x causes logout operations to fail when delayed frame responses reapply session cookies after logout. This can be exploited by remote attackers via selective network delays (e.g. delaying requests based on sequence or timing) or by…
AplazadaAlta (8.5)0.16%—Bootp TurboAI16/1/202617/6/2026
BOOTP Turbo 2.0.0.1253 contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path to execute arbitrary code with elevated LocalSystem privileges during system startup or reboot.
AnalizadaAlta (7.5)0.63%—Turbopuffer Logrus4/12/202517/6/2026
A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with "token too long" and the writer pipe is closed, leaving Writer() unusable and…
ModificadaBaja (2.1)0.45%—Harry0703 Moneyprinterturbo11/10/202517/6/2026
A weakness has been identified in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function upload_music of the file app/controllers/v1/music.py of the component API Endpoint. Executing a manipulation of the argument File can lead to path traversal. The attack may be performed from remote. The…
AnalizadaMedia (5.5)0.84%—Harry0703 Moneyprinterturbo15/9/202517/6/2026
A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function download_video/stream_video of the file app/controllers/v1/video.py of the component URL Handler. The manipulation of the argument file_path leads to path traversal. The attack can be initiated remotely. The…
AnalizadaMedia (6.3)0.31%—Harry0703 Moneyprinterturbo15/9/202517/6/2026
wangxutech MoneyPrinterTurbo 1.2.6 allows path traversal via /api/v1/download/ URIs such as /api/v1/download//etc/passwd.
AplazadaMedia (4.1)0.27%—TurbovncAINovncAIOSC Open OndemandAI9/9/202517/6/2026
Open OnDemand is an open-source HPC portal. Prior to versions 3.1.15 and 4.0.7, noVNC interactive applications did not correctly rotate the password when TurboVNC was higher than version 3.1.2. The likelihood of exploitation is low as a user would need to share their link to an active desktop session and the other…