Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
142 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.49% | — | Yeger Turbo-graphAIYeger Turbo-graph-uiAI | 15/9/2026 | 30/9/2026 | Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by default, while the GET handler for /api/run in… | |
| Aplazada | Media (6.5) | 0.36% | — | Libjpeg-turboAI | 26/8/2026 | 9/9/2026 | libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability in the PNG loader. When processing a valid indexed-color PNG image with a non-gray palette through tj3LoadImage12() or tj3LoadImage16() using the default pixel format, the application may trigger a division-by-zero in alloc_sarray(), causing a… | |
| Pendiente de análisis | Alta (7.5) | 0.60% | — | Facebook React-server-dom-webpackAIFacebook React-server-dom-parcelAIFacebook React-server-dom-turbopackAI | 21/7/2026 | 21/7/2026 | A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.7, 19.1.0… | |
| Analizada | Alta (7.5) | 0.45% | — | Shopify React-routerTurbo-stream Turbo Stream | 2/6/2026 | 22/7/2026 | React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications… | |
| Analizada | Alta (8.4) | 0.24% | — | Vercel Turborepo Language Server Protocol | 15/5/2026 | 17/6/2026 | Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14000, the Turborepo LSP VS Code extension could execute shell commands derived from workspace-controlled values. The extension used string-based command execution for Turborepo daemon commands and task runs. A malicious… | |
| Analizada | Media (5.1) | 0.18% | — | Vercel Turborepo | 15/5/2026 | 17/6/2026 | Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14, Turborepo's self-hosted login and SSO browser flows did not validate a CSRF state value on the localhost callback. While the CLI was waiting for authentication, a malicious web page could send a request to the local… | |
| Analizada | Ninguna (0) | 0.64% | — | Vercel Turborepo | 15/5/2026 | 17/6/2026 | Turborepo is a high-performance build system for JavaScript and TypeScript codebases. From 1.1.0 to before 2.9.14, Turborepo can be vulnerable to arbitrary code execution when run in untrusted repositories that contain malicious Yarn configuration. In affected versions, package manager detection executed yarn… | |
| Aplazada | Alta (8.8) | 0.23% | — | E-kalite Software Turboard For-sAI | 12/5/2026 | 17/6/2026 | Incorrect Authorization vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard FOR-S allows Privilege Escalation. This issue affects Turboard FOR-S: from 7.01.2026 before 18.02.2026. | |
| Analizada | Alta (7.5) | 1.5% | — | Facebook React-server-dom-parcelFacebook React-server-dom-turbopackFacebook React-server-dom-webpack | 6/5/2026 | 12/8/2026 | A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel,… | |
| Analizada | Alta (7.8) | 0.15% | — | IBM Turbonomic Prometurbo Agent | 30/4/2026 | 17/6/2026 | IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, including unrestricted read access to all secrets. An attacker that compromises the operator or its service account can exfiltrate sensitive credentials, escalate privileges,… | |
| Pendiente de análisis | Alta (7.5) | 1.6% | — | Facebook React-server-dom-parcelAIFacebook React-server-dom-turbopackAIFacebook React-server-dom-webpackAI | 8/4/2026 | 25/7/2026 | A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, and 19.2.0 through 19.2.4). The vulnerability is triggered by sending specially… | |
| Aplazada | Alta (7.5) | 0.51% | — | Redqteam Turbo ManagerAIPHPAI | 13/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in redqteam Turbo Manager turbo-manager allows PHP Local File Inclusion.This issue affects Turbo Manager: from n/a through < 4.0.8. | |
| Aplazada | Media (6.7) | 0.32% | — | Hotwired TurboAI | 11/2/2026 | 17/6/2026 | BOOTP Turbo 2.0 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the Structured Exception Handler (SEH). Attackers can generate a malicious payload of 2196 bytes with specific byte patterns to trigger an application crash and corrupt the SEH chain. | |
| Aplazada | Crítica (9.4) | 0.39% | — | E-kalite Software Hardware Engineering Design AND Internet Services Industry AND Trade LTD CO TurboardAI | 11/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard allows Reflected XSS. This issue affects Turboard: from 2025.07 before 2026.02. NOTE: This CVE record… | |
| Aplazada | Alta (8.5) | 0.14% | — | Tftp TurboAI | 1/2/2026 | 17/6/2026 | TFTP Turbo 4.6.1273 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be launched with LocalSystem permissions. | |
| Aplazada | Alta (8.5) | 0.17% | — | Dhcp TurboAI | 1/2/2026 | 17/6/2026 | DHCP Turbo 4.61298 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code by exploiting the service binary path. Attackers can place malicious executables in the service path to gain elevated privileges when the service starts. | |
| Aplazada | Alta (8.5) | 0.14% | — | Hotwired TurboAI | 1/2/2026 | 17/6/2026 | BOOTP Turbo 2.0.1214 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted executable path to inject malicious code that will be executed when the service starts with LocalSystem permissions. | |
| Aplazada | Media (6.9) | 0.36% | — | Libjpeg-turboAINeka-nat CupochAI | 27/1/2026 | 17/6/2026 | Out-of-bounds Write vulnerability in neka-nat cupoch (third_party/libjpeg-turbo/libjpeg-turbo modules). This vulnerability is associated with program files tjbench.C. This issue affects cupoch. | |
| Analizada | Media (4.8) | 0.28% | — | Hotwired Turbo | 20/1/2026 | 17/6/2026 | Race condition in the turbo-frame element handler in Hotwired Turbo before 8.0.x causes logout operations to fail when delayed frame responses reapply session cookies after logout. This can be exploited by remote attackers via selective network delays (e.g. delaying requests based on sequence or timing) or by… | |
| Aplazada | Alta (8.5) | 0.16% | — | Bootp TurboAI | 16/1/2026 | 17/6/2026 | BOOTP Turbo 2.0.0.1253 contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path to execute arbitrary code with elevated LocalSystem privileges during system startup or reboot. | |
| Analizada | Alta (7.5) | 0.63% | — | Turbopuffer Logrus | 4/12/2025 | 17/6/2026 | A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB without newline characters. Due to limitations in the internal bufio.Scanner, the read fails with "token too long" and the writer pipe is closed, leaving Writer() unusable and… | |
| Modificada | Baja (2.1) | 0.45% | — | Harry0703 Moneyprinterturbo | 11/10/2025 | 17/6/2026 | A weakness has been identified in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function upload_music of the file app/controllers/v1/music.py of the component API Endpoint. Executing a manipulation of the argument File can lead to path traversal. The attack may be performed from remote. The… | |
| Analizada | Media (5.5) | 0.84% | — | Harry0703 Moneyprinterturbo | 15/9/2025 | 17/6/2026 | A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function download_video/stream_video of the file app/controllers/v1/video.py of the component URL Handler. The manipulation of the argument file_path leads to path traversal. The attack can be initiated remotely. The… | |
| Analizada | Media (6.3) | 0.31% | — | Harry0703 Moneyprinterturbo | 15/9/2025 | 17/6/2026 | wangxutech MoneyPrinterTurbo 1.2.6 allows path traversal via /api/v1/download/ URIs such as /api/v1/download//etc/passwd. | |
| Aplazada | Media (4.1) | 0.27% | — | TurbovncAINovncAIOSC Open OndemandAI | 9/9/2025 | 17/6/2026 | Open OnDemand is an open-source HPC portal. Prior to versions 3.1.15 and 4.0.7, noVNC interactive applications did not correctly rotate the password when TurboVNC was higher than version 3.1.2. The likelihood of exploitation is low as a user would need to share their link to an active desktop session and the other… |