Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
91 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.77% | — | Mistral VibeAI | 19/9/2026 | 22/9/2026 | Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary shell commands with the privileges of the user running Vibe. | |
| Aplazada | Crítica (10) | 0.43% | — | Mistral VibeAI | 11/9/2026 | 11/9/2026 | An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through commands classified as unconditionally allowed. Missing path validation for these commands enables access to files outside the active workspace without user approval. | |
| Aplazada | Crítica (10) | 0.56% | — | Mistral VibeAI | 11/9/2026 | 11/9/2026 | An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable assignments preceding allowlisted commands. These assignments are excluded from inspection, enabling attacker-controlled environment variables to cause arbitrary code execution… | |
| Aplazada | Crítica (10) | 0.56% | — | Mistral VibeAI | 11/9/2026 | 11/9/2026 | An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using shell constructs it's parser cannot interpret. Unparsed portions are omitted from inspection, enabling embedded commands to execute on the user's system without approval. | |
| Aplazada | Crítica (10) | 0.56% | — | Mistral VibeAI | 11/9/2026 | 11/9/2026 | An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using ANSI-C quoted arguments. These arguments are not properly inspected, enabling a crafted allowlisted command to execute arbitrary code on the user's system without approval. | |
| Aplazada | Crítica (9.3) | 0.50% | — | Mistral VibeAI | 11/9/2026 | 11/9/2026 | An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or overwrite files outside the active workspace without user approval. Shell redirection destinations are omitted from permission checks, enabling otherwise allowlisted commands to write to arbitrary paths… | |
| Aplazada | Crítica (9.2) | 0.62% | — | Mistral VibeAI | 11/9/2026 | 11/9/2026 | An arbitrary file read vulnerability in Mistral Vibe, introduced in version 2.6.0, allows an attacker to bypass workspace restrictions using quoted absolute paths in allowlisted shell commands. Improper handling of quotation marks during path validation enables files outside the active workspace to be read without… | |
| Aplazada | Alta (8.6) | 1.1% | — | Mistral VibeAI | 5/8/2026 | 24/9/2026 | Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a repository's .git/config file, which is triggered when vibe invokes git status --porcelain without suppressing hook execution. Attackers can… | |
| Aplazada | Media (5.5) | 0.52% | — | Vibesurf-ai VibesurfAI | 4/8/2026 | 12/8/2026 | A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an unknown function of the file /code of the component Python Validation Handler. The manipulation leads to code injection. Remote exploitation of the attack is possible. This product follows a rolling… | |
| Aplazada | Alta (7.1) | 0.25% | — | Form Vibes Database Manager FOR FormsAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions. | |
| Aplazada | Alta (7.2) | 0.40% | — | Wpvibes Form VibesAI | 11/7/2026 | 13/7/2026 | The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 Form Field in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Media (6) | 0.45% | — | Vibe-tradingAI | 30/6/2026 | 14/7/2026 | Vibe-Trading before 0.1.10 contains a path traversal vulnerability that allows attackers to write files outside the intended memory root directory by supplying a malicious memory_type value containing path traversal sequences through the remember tool. Attackers can manipulate the memory_type parameter in the… | |
| Aplazada | Baja (2.3) | 0.34% | — | Vibe-tradingAI | 30/6/2026 | 14/7/2026 | Vibe-Trading before 0.1.10 constructs the swarm run directory by joining a caller-supplied run identifier onto the runs base directory without validation in run_dir (agent/src/swarm/store.py). A crafted run identifier supplied through the MCP swarm tools causes the application to read arbitrary run.json files outside… | |
| Aplazada | Alta (7.2) | 0.55% | — | Vibe-tradingAI | 30/6/2026 | 14/7/2026 | Vibe-Trading before 0.1.10 builds the proposal file path by joining a caller-supplied proposal identifier onto the broker proposals directory without sanitization (agent/src/live/mandate/commit.py). A proposal identifier containing path traversal sequences causes the application to load an attacker-controlled JSON… | |
| Aplazada | Alta (7.7) | 0.42% | — | Vibe-tradingAI | 30/6/2026 | 14/7/2026 | Vibe-Trading before 0.1.10 contains a DNS rebinding authentication bypass vulnerability that allows remote attackers to bypass bearer-token authentication by exploiting the server's trust of TCP peer addresses for loopback clients combined with missing Host header validation while binding to 0.0.0.0 with credentialed… | |
| Aplazada | Alta (7.1) | 0.27% | — | Wpvibes WP Mail LOGAI | 11/6/2026 | 23/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP Mail Log allows DOM-Based XSS. This issue affects WP Mail Log: from n/a through 1.0.2. | |
| Analizada | Crítica (9.8) | 0.36% | — | Rakuten Viber | 5/3/2026 | 17/6/2026 | Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 uses a static and predictable TLS ClientHello fingerprint lacking extension diversity, allowing Deep Packet Inspection (DPI) systems to trivially identify and block proxy traffic, undermining censorship circumvention. (CWE-327) | |
| Aplazada | Media (6.5) | 0.39% | — | Wpvibes Elementor Addon ElementsAI | 26/2/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in WPVibes Elementor Addon Elements addon-elements-for-elementor-page-builder allows Retrieve Embedded Sensitive Data.This issue affects Elementor Addon Elements: from n/a through <= 1.14.4. | |
| Aplazada | Alta (8.6) | 0.54% | — | Vibethemes WplmsAI | 22/1/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through <= 1.9.9.5.4. | |
| Aplazada | Media (4.9) | 0.32% | — | Wpvibes Form VibesAI | 6/1/2026 | 17/6/2026 | The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to SQL Injection via the 'params' parameter in all versions up to, and including, 1.4.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.18% | — | Wpvibes Anywhere Elementor PROAI | 5/1/2026 | 30/9/2026 | Missing Authorization vulnerability in WPvibes AnyWhere Elementor Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AnyWhere Elementor Pro: from n/a through 2.29. | |
| Modificada | Media (6.5) | 0.20% | — | Vibethemes Wordpress Learning Management System | 9/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VibeThemes WPLMS wplms_plugin allows DOM-Based XSS.This issue affects WPLMS: from n/a through <= 1.9.9.5.4. | |
| Analizada | Media (5.3) | 0.22% | — | Salesforce Agentforce Vibes | 4/11/2025 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable Configuration Files.This issue affects Agentforce Vibes Extension: before 3.3.0. | |
| Analizada | Media (5.3) | 0.24% | — | Salesforce Agentforce Vibes | 4/11/2025 | 17/6/2026 | Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable Configuration Files.This issue affects Agentforce Vibes Extension: before 3.3.0. | |
| Analizada | Media (6.5) | 0.21% | — | Salesforce Agentforce Vibes | 4/11/2025 | 17/6/2026 | Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Code Injection.This issue affects Agentforce Vibes Extension: before 3.2.0. |