Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3070▲ 562 respecto a la semana anterior
Críticas / altas1457▲ 278 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
155 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (8.8) | — | — | PgvectorAI | 1/10/2026 | 1/10/2026 | IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, which can lead to arbitrary code execution. | |
| Pendiente de análisis | Alta (8.8) | 0.20% | — | NeuvectorAI | 28/9/2026 | 29/9/2026 | Improper parameter handling in NeuVector allows any authenticated user who holds the namespaced Runtime Policies (write) permission or anyone with access to NeuVector’s internal gRPC certificate key pair the ability to inject OS commands in the privileged enforcer container, which can lead to the complete compromise… | |
| Aplazada | Media (5.3) | 0.16% | — | Gvectors WpforoAI | 25/9/2026 | 25/9/2026 | The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does not verify the source of client-supplied IP address headers before using them to key its per-visitor rate limit on paid AI requests, allowing unauthenticated attackers to bypass the limit by spoofing the header and exhaust the site owner's metered AI… | |
| Aplazada | Media (6.4) | 0.20% | — | Gvectors WpforoAI | 25/9/2026 | 25/9/2026 | The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'telegram' profile field in versions up to, and including, 3.1.6. This is due to insufficient input sanitization and output escaping in the profile_update action — the raw $_POST['data'] array is copied into a $custom_fields… | |
| Aplazada | Alta (7.5) | 0.31% | — | Gvectors Wpforo ForumAI | 24/9/2026 | 24/9/2026 | The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes a user-supplied profile field value, allowing authenticated users with Subscriber-level access and above to inject a PHP Object. No POP chain is present in the wpForo Forum WordPress plugin before… | |
| Aplazada | Media (6.5) | 0.22% | — | Gvectors Wpforo ForumAI | 23/9/2026 | 23/9/2026 | Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 versions. | |
| Pendiente de análisis | Crítica (9.3) | 1.1% | — | VectorAI | 22/9/2026 | 26/9/2026 | Vector is a high-performance observability data pipeline. From 0.10.0 until 0.57.0, the file sink renders its templated path from event fields and opens the result without confining it to an intended directory. When an untrusted source supplies an event field used by the path template, the value can contain an… | |
| Pendiente de análisis | Alta (8.7) | 0.52% | — | VectorAI | 22/9/2026 | 24/9/2026 | Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source feeds each decompressed frame back into its decoder without limiting nested compression depth. An unauthenticated remote peer that can reach the default 0.0.0.0:5044 listener can send many nested compressed frames,… | |
| Pendiente de análisis | Alta (8.7) | 0.52% | — | VectorAI | 22/9/2026 | 24/9/2026 | Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source reads a 32-bit compressed-frame length from the network and uses it to size an in-memory buffer without an upper bound. An unauthenticated remote peer that can reach the default 0.0.0.0:5044 listener can send a… | |
| Aplazada | Media (4.3) | 0.39% | — | Gvectors WpforoAI | 22/9/2026 | 23/9/2026 | The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to take… | |
| Pendiente de análisis | Media (5.3) | 0.24% | — | NeuvectorAI | 17/9/2026 | 28/9/2026 | The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images. Since the image path is entirely controlled by the workload author, any user capable of deploying workloads can evade admission deny rules simply by… | |
| Pendiente de análisis | Baja (2) | 0.19% | — | NeuvectorAI | 17/9/2026 | 28/9/2026 | The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires. | |
| Pendiente de análisis | Alta (7.6) | 0.36% | — | NeuvectorAI | 17/9/2026 | 28/9/2026 | Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticketing system, an expenses tool, or anything they legitimately hold an account on can log into their system via SAML SSO. The IdP issues an assertion to them. If that assertion is presented to… | |
| Pendiente de análisis | Media (6.8) | 0.20% | — | Suse NeuvectorAI | 9/9/2026 | 10/9/2026 | An Insertion of Sensitive Information into Log File vulnerability in SUSE neuvector manager exposes sensitive information into the manager container’s log This issue affects neuvector: before 5.4.5. | |
| Aplazada | Alta (7.5) | 0.55% | — | Gvectors WpforoAI | 28/8/2026 | 28/8/2026 | The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'referer' parameter in all versions up to, and including, 2.4.17. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… | |
| Pendiente de análisis | Alta (7.3) | 0.80% | — | NeuvectorAI | 5/8/2026 | 1/9/2026 | NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing sensitive information. | |
| Aplazada | Baja (1.9) | 0.16% | — | Epsilla Cloud VectordbAI | 5/8/2026 | 12/8/2026 | A vulnerability has been found in epsilla-cloud vectordb up to 0.3.18/df5a5f5afb85a2376a0f2f316c79dea9b2c6ac7a. This impacts the function SplitTokens/ShuntingYard of the file engine/query/expr/expr.cpp of the component Filter Parser. Such manipulation leads to improper check for unusual conditions. The attack needs to… | |
| Aplazada | Media (4.3) | 0.25% | — | Gvectors WpforoAI | 4/8/2026 | 26/8/2026 | The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-level account to write administrator-controlled account-state and reputation fields on their own profile, including self-activating a pending or banned… | |
| Aplazada | Media (5.4) | 0.23% | — | Gvectors WpforoAI | 1/8/2026 | 26/8/2026 | The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it inside an HTML attribute on the public participant profile page, allowing users with a subscriber-level account to inject JavaScript that executes in the browser of any visitor who views the profile,… | |
| Aplazada | Media (5.4) | 0.29% | — | Gvectors Wpforo ForumAI | 31/7/2026 | 26/8/2026 | The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messages, allowing users with a subscriber-level account to permanently delete the stored AI chat message history of any other user. | |
| Analizada | Alta (8.8) | 0.60% | — | Pgvector Project Pgvector | 29/7/2026 | 20/8/2026 | Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, which could lead to arbitrary code execution. Only 32-bit systems are affected. | |
| Aplazada | Media (6.4) | 0.36% | — | Gvectors WpforoAI | 16/7/2026 | 16/7/2026 | The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Profile Field in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject… | |
| Aplazada | Crítica (9.3) | 0.70% | — | PgvectorAIApache CassandraAIPraisonaiAI | 11/7/2026 | 14/7/2026 | PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. Although schema, keyspace, and collection-name identifiers are validated, the dimension value (declared as int but not enforced at runtime) is interpolated… | |
| Pendiente de análisis | Alta (7.6) | 0.47% | — | Langchain4jAILangchain4j-mariadbAILangchain4j-pgvectorAI | 10/7/2026 | 13/7/2026 | LangChain4j is a Java library for building LLM-powered applications on the JVM. Prior to 1.2.1-beta8, 1.5.1-beta11, 1.11.8-beta19, and 1.16.3-beta26, the MariaDB and pgvector embedding stores build metadata-filter SQL by string-concatenating filter keys, and in MariaDB string values, directly into the query without… | |
| Aplazada | Alta (8.5) | 0.36% | — | Gvectors WpforoAI | 26/6/2026 | 26/6/2026 | Contributor SQL Injection in wpForo Forum <= 3.0.9 versions. |