Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3070▲ 562 respecto a la semana anterior
Críticas / altas1457▲ 278 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
–

155 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaAlta (8.8)——PgvectorAI1/10/20261/10/2026
IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, which can lead to arbitrary code execution.
Pendiente de análisisAlta (8.8)0.20%—NeuvectorAI28/9/202629/9/2026
Improper parameter handling in NeuVector allows any authenticated user who holds the namespaced Runtime Policies (write) permission or anyone with access to NeuVector’s internal gRPC certificate key pair the ability to inject OS commands in the privileged enforcer container, which can lead to the complete compromise…
AplazadaMedia (5.3)0.16%—Gvectors WpforoAI25/9/202625/9/2026
The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does not verify the source of client-supplied IP address headers before using them to key its per-visitor rate limit on paid AI requests, allowing unauthenticated attackers to bypass the limit by spoofing the header and exhaust the site owner's metered AI…
AplazadaMedia (6.4)0.20%—Gvectors WpforoAI25/9/202625/9/2026
The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'telegram' profile field in versions up to, and including, 3.1.6. This is due to insufficient input sanitization and output escaping in the profile_update action — the raw $_POST['data'] array is copied into a $custom_fields…
AplazadaAlta (7.5)0.31%—Gvectors Wpforo ForumAI24/9/202624/9/2026
The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes a user-supplied profile field value, allowing authenticated users with Subscriber-level access and above to inject a PHP Object. No POP chain is present in the wpForo Forum WordPress plugin before…
AplazadaMedia (6.5)0.22%—Gvectors Wpforo ForumAI23/9/202623/9/2026
Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 versions.
Pendiente de análisisCrítica (9.3)1.1%—VectorAI22/9/202626/9/2026
Vector is a high-performance observability data pipeline. From 0.10.0 until 0.57.0, the file sink renders its templated path from event fields and opens the result without confining it to an intended directory. When an untrusted source supplies an event field used by the path template, the value can contain an…
Pendiente de análisisAlta (8.7)0.52%—VectorAI22/9/202624/9/2026
Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source feeds each decompressed frame back into its decoder without limiting nested compression depth. An unauthenticated remote peer that can reach the default 0.0.0.0:5044 listener can send many nested compressed frames,…
Pendiente de análisisAlta (8.7)0.52%—VectorAI22/9/202624/9/2026
Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source reads a 32-bit compressed-frame length from the network and uses it to size an in-memory buffer without an upper bound. An unauthenticated remote peer that can reach the default 0.0.0.0:5044 listener can send a…
AplazadaMedia (4.3)0.39%—Gvectors WpforoAI22/9/202623/9/2026
The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to take…
Pendiente de análisisMedia (5.3)0.24%—NeuvectorAI17/9/202628/9/2026
The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images. Since the image path is entirely controlled by the workload author, any user capable of deploying workloads can evade admission deny rules simply by…
Pendiente de análisisBaja (2)0.19%—NeuvectorAI17/9/202628/9/2026
The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires.
Pendiente de análisisAlta (7.6)0.36%—NeuvectorAI17/9/202628/9/2026
Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticketing system, an expenses tool, or anything they legitimately hold an account on can log into their system via SAML SSO. The IdP issues an assertion to them. If that assertion is presented to…
Pendiente de análisisMedia (6.8)0.20%—Suse NeuvectorAI9/9/202610/9/2026
An Insertion of Sensitive Information into Log File vulnerability in SUSE neuvector manager exposes sensitive information into the manager container’s log This issue affects neuvector: before 5.4.5.
AplazadaAlta (7.5)0.55%—Gvectors WpforoAI28/8/202628/8/2026
The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'referer' parameter in all versions up to, and including, 2.4.17. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated…
Pendiente de análisisAlta (7.3)0.80%—NeuvectorAI5/8/20261/9/2026
NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing sensitive information.
AplazadaBaja (1.9)0.16%—Epsilla Cloud VectordbAI5/8/202612/8/2026
A vulnerability has been found in epsilla-cloud vectordb up to 0.3.18/df5a5f5afb85a2376a0f2f316c79dea9b2c6ac7a. This impacts the function SplitTokens/ShuntingYard of the file engine/query/expr/expr.cpp of the component Filter Parser. Such manipulation leads to improper check for unusual conditions. The attack needs to…
AplazadaMedia (4.3)0.25%—Gvectors WpforoAI4/8/202626/8/2026
The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-level account to write administrator-controlled account-state and reputation fields on their own profile, including self-activating a pending or banned…
AplazadaMedia (5.4)0.23%—Gvectors WpforoAI1/8/202626/8/2026
The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it inside an HTML attribute on the public participant profile page, allowing users with a subscriber-level account to inject JavaScript that executes in the browser of any visitor who views the profile,…
AplazadaMedia (5.4)0.29%—Gvectors Wpforo ForumAI31/7/202626/8/2026
The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messages, allowing users with a subscriber-level account to permanently delete the stored AI chat message history of any other user.
AnalizadaAlta (8.8)0.60%—Pgvector Project Pgvector29/7/202620/8/2026
Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, which could lead to arbitrary code execution. Only 32-bit systems are affected.
AplazadaMedia (6.4)0.36%—Gvectors WpforoAI16/7/202616/7/2026
The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Profile Field in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject…
AplazadaCrítica (9.3)0.70%—PgvectorAIApache CassandraAIPraisonaiAI11/7/202614/7/2026
PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. Although schema, keyspace, and collection-name identifiers are validated, the dimension value (declared as int but not enforced at runtime) is interpolated…
Pendiente de análisisAlta (7.6)0.47%—Langchain4jAILangchain4j-mariadbAILangchain4j-pgvectorAI10/7/202613/7/2026
LangChain4j is a Java library for building LLM-powered applications on the JVM. Prior to 1.2.1-beta8, 1.5.1-beta11, 1.11.8-beta19, and 1.16.3-beta26, the MariaDB and pgvector embedding stores build metadata-filter SQL by string-concatenating filter keys, and in MariaDB string values, directly into the query without…
AplazadaAlta (8.5)0.36%—Gvectors WpforoAI26/6/202626/6/2026
Contributor SQL Injection in wpForo Forum <= 3.0.9 versions.