Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
148 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.4) | 0.40% | — | Rattadan CosmowarpAI | 25/9/2026 | 30/9/2026 | The Rattadan Cosmowarp smart contract before 56c6147 can have a comparison to an unintended value of current_admin. | |
| Aplazada | Media (6) | 0.41% | — | WarpgateAI | 21/9/2026 | 24/9/2026 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.28.4, PUT /@warpgate/admin/api/users/:id/roles/:role_id reaches api_update_user_role in warpgate-admin/src/api/users.rs through AdminContext but does not require AdminPermission::AccessRolesAssign. A limited administrator with any… | |
| Aplazada | Media (5.7) | 0.22% | — | WarpgateAI | 21/9/2026 | 24/9/2026 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.25.0 until 0.27.6, the browser SSH path in warpgate-web-ssh/src/manager.rs handles RCEvent::HostKeyUnknown without the presenting hop identity and instead passes ssh_options.host and ssh_options.port for the final target to… | |
| Aplazada | Baja (2.4) | 0.40% | — | WarpgateAI | 21/9/2026 | 24/9/2026 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.27.6, the response_mode=form_post SSO return path in warpgate-protocol-http/src/api/sso_provider_list.rs uses serde_json::to_string inside ReturnToSsoPostResponse without neutralizing a script-closing sequence. The vulnerable value can… | |
| Aplazada | Media (4.3) | 0.42% | — | WarpgateAI | 21/9/2026 | 24/9/2026 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.23.0 until 0.27.3, HTTP API token authentication resolves ConfigProvider::validate_api_token into RequestAuthorization::UserToken without enforcing the owning user's allowed_ip_ranges against the trusted client address in… | |
| Aplazada | Alta (7.7) | 0.45% | — | WarpgateAI | 21/9/2026 | 30/9/2026 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, api_get_recording_stream in warpgate-admin/src/api/recordings_detail.rs protects /@warpgate/admin/api/recordings/{uuid}/stream only with session authentication and omits require_admin_permission for… | |
| Aplazada | Media (4.9) | 0.31% | — | WarpgateAI | 21/9/2026 | 24/9/2026 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, copy_server_request in warpgate-protocol-http/src/proxy.rs forwards a client-supplied x-warpgate-username header before inject_own_headers appends the authenticated username. Because the request builder preserves repeated values,… | |
| Aplazada | Crítica (9.3) | 0.46% | — | WarpgateAI | 21/9/2026 | 24/9/2026 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.5, the /@warpgate/api/sso/providers/:name/start endpoint stores an attacker-controlled next parameter that the POST /@warpgate/api/sso/return handler inserts without HTML escaping into the response generated by… | |
| Aplazada | Crítica (9.8) | 0.68% | — | Fatpipe MpvpnAIFatpipe IpvpnAICloudflare WarpAI | 17/9/2026 | 18/9/2026 | FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based buffer overflow in /usr/sbin/auth_user_pass. An unauthenticated remote attacker with access to the affected management interface can submit a crafted authentication request that reaches an unchecked… | |
| Aplazada | Crítica (9.8) | 1.4% | — | Fatpipe MpvpnAIFatpipe IpvpnAICloudflare WarpAI | 17/9/2026 | 18/9/2026 | FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command injection vulnerability in the xtremed daemon. An unauthenticated remote attacker with access to the affected management interface can submit crafted input to the AuthFormServlet endpoint, causing… | |
| Aplazada | Baja (2) | 0.35% | — | Liaoxuefeng ItranswarpAI | 14/9/2026 | 15/9/2026 | A flaw has been found in michaelliao itranswarp up to 2.19. The impacted element is the function Markdown.toHtml of the file Markdown.java of the component Page Content Rendering. This manipulation causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. The… | |
| Aplazada | Baja (2.1) | 0.38% | — | Vvbbnn00 Warp-clash-apiAI | 13/9/2026 | 14/9/2026 | A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. Affected is the function get_surge_subscription of the file services/subscription.py of the component Subscription Handler. Such manipulation of the argument key leads to improper access controls. The attack may… | |
| Aplazada | Baja (1.3) | 0.25% | — | Vvbbnn00 Warp-clash-apiAI | 13/9/2026 | 16/9/2026 | A vulnerability was determined in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This impacts an unknown function of the component Save Account Job. This manipulation causes race condition. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitability is… | |
| Aplazada | Baja (1.3) | 0.25% | — | Vvbbnn00 Warp-clash-apiAI | 13/9/2026 | 14/9/2026 | A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This affects the function doUpdateLicenseKey. The manipulation results in race condition. The attack can be launched remotely. The attack requires a high level of complexity. The exploitability is reported as… | |
| Aplazada | Media (5.5) | 0.65% | — | Vvbbnn00 Warp-clash-apiAI | 13/9/2026 | 21/9/2026 | A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted element is the function authorized. The manipulation of the argument SECRET_KEY leads to missing authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and… | |
| Aplazada | Alta (7.7) | 0.74% | — | Cloudflare WarpAI | 24/6/2026 | 25/6/2026 | Warp is an agentic development environment. From 0.2024.03.12.08.02.stable_01 until 0.2026.05.06.15.42.stable_01, Warp contains an OS command injection vulnerability in the WSL URL-opening fallback. When Warp is running under WSL and cannot open a URL through wslview, it falls back to a Windows command processor path.… | |
| Aplazada | Media (4.3) | 0.40% | — | Cloudflare WarpAI | 24/6/2026 | 25/6/2026 | Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp accepted certain state-mutating terminal lifecycle hooks from the PTY stream without verifying that the hooks were emitted by Warp's shell integration for the active session. An attacker who could… | |
| Aplazada | Alta (8.8) | 1.4% | — | Cloudflare WarpAI | 24/6/2026 | 25/6/2026 | Warp is an agentic development environment. From 0.2023.03.21.08.02.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection issue in the legacy SSH background command path. Warp used the remote working directory reported by the session when building helper commands for SSH-backed metadata… | |
| Aplazada | Alta (7.8) | 0.89% | — | Cloudflare WarpAI | 24/6/2026 | 25/6/2026 | Warp is an agentic development environment. From 0.2024.02.20.08.01.stable_01 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection issue in the Linux external editor launcher. Warp expanded freedesktop .desktop Exec templates for affected editor integrations and executed the expanded command through a… | |
| Aplazada | Alta (8.1) | 0.38% | — | Cloudflare WarpAI | 24/6/2026 | 25/6/2026 | Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp allows terminal output to request access to the local system clipboard. A malicious remote host, remote program, or other attacker-controlled terminal output source can trigger clipboard reads or… | |
| Aplazada | Alta (8.6) | 0.22% | — | Cloudflare WarpAI | 24/6/2026 | 25/6/2026 | Warp is an agentic development environment. From 0.2025.10.08.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command execution permission-check bypass in the default unsandboxed CLI agent profile. The CLI profile is non-interactive and relies on a command denylist as a safety boundary for commands… | |
| Aplazada | Alta (8.8) | 0.44% | — | Cloudflare WarpAI | 24/6/2026 | 25/6/2026 | Warp is an agentic development environment. From 0.2025.03.05.08.02.stable_00 until 0.2026.05.06.15.42.stable_01, Warp accepts non-inline `OSC 1337;File` payloads from terminal output and materialize the decoded payload as a local file without an additional confirmation step. This vulnerability is fixed in… | |
| Aplazada | Alta (8) | 1.3% | — | Cloudflare WarpAI | 24/6/2026 | 25/6/2026 | Warp is an agentic development environment. From 0.2025.08.06.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection in the prompt branch selector. A user who can publish a branch to a Git repository opened in Warp can cause a crafted branch name to be interpreted by the victim's shell… | |
| Aplazada | Alta (8.8) | 0.44% | — | Cloudflare WarpAI | 24/6/2026 | 25/6/2026 | Warp is an agentic development environment. From 0.2023.10.24.08.03.stable_00 until 0.2026.05.06.15.42.stable_01, Warp may open executable local files through the operating system default file handler. A malicious Markdown document or project can contain a local-file link that appears as normal rendered content. If a… | |
| Aplazada | Alta (7.8) | 0.25% | — | Cloudflare WarpAI | 24/6/2026 | 25/6/2026 | Warp is an agentic development environment. From 0.2025.04.09.08.11.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command execution policy bypass in Agent code search tools. The affected Grep and FileGlob actions are authorized as read/search operations, but their implementations build shell command… |