Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 1.4% | — | Marcopiovanello Yt-dlp-web-uiAI | 18/9/2026 | 22/9/2026 | A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function NewGenericDownload of the file server/internal/downloaders/generic.go. Such manipulation of the argument params leads to command injection. It is possible to launch the attack remotely. The exploit has… | |
| Aplazada | Media (5.1) | 0.40% | — | Elenavanengelenmaslova Mocknest-serverlessAI | 8/9/2026 | 23/9/2026 | A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-role.yaml of the component AWS GitHub OIDC Deployment Helper Script. Performing a manipulation results in improper privilege management. It is… | |
| Aplazada | Alta (8.3) | 0.43% | — | Datavane TISAI | 14/8/2026 | 24/9/2026 | Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perform server-side request forgery and out-of-band file exfiltration by supplying a crafted taskScript payload to the doEditWorkflow endpoint, which processes XML through an unhardened… | |
| Aplazada | Baja (3.7) | 0.40% | — | GNU SavaneAI | 20/6/2026 | 22/6/2026 | GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization. | |
| Aplazada | Alta (7.5) | 0.33% | — | VanetzaAI | 26/5/2026 | 24/7/2026 | Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vulnerability was identified in the cryptographic verification pipeline of Vanetza. When processing incoming V2X messages, the ASN.1 decoder accepts the structure as syntactically valid. However, this… | |
| Aplazada | Alta (7.5) | 0.31% | — | VanetzaAI | 26/5/2026 | 24/7/2026 | Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vulnerability was identified in the ASN.1/OER parsing pipeline of Vanetza. When processing malformed network packets containing corrupted ASN.1/OER structures (e.g., invalid length fields or malformed… | |
| Aplazada | Media (5.5) | 0.47% | — | Itzcrazy KNS VaneAI | 24/5/2026 | 23/7/2026 | A flaw has been found in ItzCrazyKns Vane up to 1.12.1. This vulnerability affects unknown code of the file src/app/api/providers/route.ts of the component Model Provider API. This manipulation of the argument baseURL causes server-side request forgery. Remote exploitation of the attack is possible. The exploit has… | |
| Aplazada | Baja (2.9) | 0.54% | — | Itzcrazy KNS VaneAI | 24/5/2026 | 23/7/2026 | A security vulnerability has been detected in ItzCrazyKns Vane up to 1.12.1. Affected by this issue is some unknown functionality of the file route.ts of the component API. The manipulation leads to missing authentication. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitation… | |
| Aplazada | Alta (7.5) | 0.63% | — | Vanetza V2XAIOpensslAI | 1/5/2026 | 17/6/2026 | An issue was discovered in Vanetza V2X v26.02 allowing remote unauthorized attackers to cause a denial of service. The vulnerability exists in the GeoNetworking packet processing pipeline where OpenSSL exceptions from ECC point validation (invalid compressed point, point not on curve) are not properly caught by the… | |
| Aplazada | Baja (2.9) | 0.43% | — | Datavane DatavinesAI | 26/4/2026 | 17/6/2026 | A vulnerability was determined in Datavane Datavines up to 13607645e14a4982468cfdbcf75c85cde63bae71. The affected element is an unknown function of the file datavines-core/src/main/java/io/datavines/core/utils/TokenManager.java of the component JWT Token Handler. Executing a manipulation of the argument tokenSecret… | |
| Aplazada | Crítica (10) | 0.29% | — | Datavane TISAI | 27/1/2026 | 17/6/2026 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in datavane tis (tis-console/src/main/java/com/qlangtech/tis/runtime/module/action modules). This vulnerability is associated with program files ChangeDomainAction.Java. This issue affects tis: before v4.3.0. | |
| Aplazada | Crítica (10) | 0.35% | — | Datavane TISAI | 27/1/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type, Deserialization of Untrusted Data vulnerability in datavane tis (tis-plugin/src/main/java/com/qlangtech/tis/extension/impl modules). This vulnerability is associated with program files XmlFile.Java. This issue affects tis: before v4.3.0. | |
| Aplazada | Media (4.3) | 0.22% | — | Michielvaneerd Private Google CalendarsAI | 11/11/2025 | 17/6/2026 | The Private Google Calendars plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pgc_remove' action in all versions up to, and including, 20250811. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset the… | |
| Aplazada | Media (6.5) | 0.39% | — | Giovanebribeiro WP Pagseguro PaymentsAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in giovanebribeiro WP PagSeguro Payments wp-pagseguro-payments allows Stored XSS.This issue affects WP PagSeguro Payments: from n/a through <= 1.0. | |
| Analizada | Alta (7.6) | 0.95% | — | GNU Savane | 11/4/2024 | 17/6/2026 | An issue was discovered in GNU Savane v.3.13 and before, allows a remote attacker to execute arbitrary code and escalate privileges via a crafted file to the upload.php component. | |
| Analizada | Alta (8.8) | 1.3% | — | GNU Savane | 8/4/2024 | 17/6/2026 | An issue in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via the form_id in the form_header() function. | |
| Analizada | Media (6) | 0.42% | — | GNU Savane | 8/4/2024 | 17/6/2026 | Cross Site Request Forgery vulnerability in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via siteadmin/usergroup.php | |
| Analizada | Alta (7.5) | 0.82% | — | GNU Savane | 8/4/2024 | 17/6/2026 | Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arbitrary files via crafted input to the trackers_data_delete_file function. | |
| Modificada | Media (5.4) | 0.31% | — | Michielvaneerd Private Google Calendars | 8/1/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michiel van Eerd Private Google Calendars allows Stored XSS.This issue affects Private Google Calendars: from n/a through 20231125. | |
| Modificada | Alta (7.5) | 17% | — | Novastor Novanet | 9/3/2009 | 16/6/2026 | Stack-based buffer overflow in the DtbClsLogin function in NovaStor NovaNET 12 allows remote attackers to (1) execute arbitrary code on Linux platforms via a long username field during backup domain authentication, related to libnnlindtb.so; or (2) cause a denial of service (daemon crash) on Windows platforms via a… | |
| Modificada | Alta (7.5) | 2.2% | — | Tolvanen Eraser | 31/12/2002 | 16/6/2026 | Eraser 5.3 does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be deleted. | |
| Modificada | Alta (7.5) | 2.8% | — | Vanessa LoggerVerge Perdition | 31/12/2001 | 16/6/2026 | Format string vulnerability in libvanessa_logger 0.0.1 in Perdition 0.1.8 allows remote attackers to execute arbitrary code via format string specifiers in the __vanessa_logger_log function. |