Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3060▲ 560 respecto a la semana anterior
Críticas / altas1458▲ 280 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

88 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)0.84%—Punchin-emailAICloudflare WorkersAI17/9/202630/9/2026
punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. Prior to 1.5.0, handleInbound delivers inbound alias mail with message.forward(), which silently drops the added Reply-To header intended to route responses through the relay. When a correspondent…
AplazadaCrítica (9.8)1.2%—Powerjob WorkerAI4/9/20268/9/2026
PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code.
AplazadaAlta (8.1)0.37%—Managewp WorkerAI22/8/202626/8/2026
The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who obtain such a link to gain a session as any user on the site, including an administrator.
Pendiente de análisisMedia (6.8)0.15%—RenovateAIMend Renovate-ceAIRenovate-ee-serverAIRenovate-ee-workerAI19/8/202629/9/2026
Renovate versions from 42.68.1 before 42.96.3 and from 43.0.0 before 43.4.4, including the renovate/renovate Docker images, and Mend Renovate CE/EE images (renovate-ce, renovate-ee-server, renovate-ee-worker) from 13.3.0 before 13.6.0, fail to restrict environment variables to an allowlist when spawning child…
Pendiente de análisisAlta (7.8)0.36%—Yggdrasil Worker-package-managerAI31/7/20263/8/2026
A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen, to be misinterpreted as command options by apt-get. Successful…
AplazadaMedia (5.3)0.37%—Cloudflare WorkerdAICapgo Cap-goAI20/6/202622/6/2026
Cap-go before 12.128.12 contains a broken cursor pagination vulnerability in the /private/devices endpoint on the Cloudflare/workerd path that allows authenticated attackers to cause duplicate-page loops and make later rows unreachable. Attackers with app.read_devices access can exploit non-advancing cursor filters to…
AplazadaAlta (7.1)0.25%—Managewp WorkerAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in ManageWP Worker <= 4.9.31 versions.
AplazadaAlta (7.2)0.32%—Managewp WorkerAI14/5/202617/6/2026
The ManageWP Worker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'MWP-Key-Name' HTTP request header in all versions up to, and including, 4.9.31. This is due to insufficient input sanitization and output escaping of attacker-controlled header values. This makes it possible for…
AnalizadaAlta (7.8)0.30%—Microsoft Azure Automation Hybrid Worker Windows Extension10/3/202617/6/2026
Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.
AplazadaMedia (5.4)0.20%—Merkulove Worker FOR WpbakeryAI31/12/202523/9/2026
Missing Authorization vulnerability in merkulove Worker for WPBakery worker-wpbakery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Worker for WPBakery: from n/a through <= 1.1.1.
AplazadaMedia (5.4)0.20%—Merkulove Worker FOR ElementorAI31/12/202523/9/2026
Missing Authorization vulnerability in merkulove Worker for Elementor worker-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Worker for Elementor: from n/a through <= 1.0.10.
AplazadaCrítica (9.3)0.37%—Rekinddns Serverless-dnsAICloudflare WorkersAIDeno DeployAIFastlyAI+130/9/202517/6/2026
serverless-dns is a RethinkDNS resolver that deploys to Cloudflare Workers, Deno Deploy, Fastly, and Fly.io. Versions through abd including 0.1.30 have a vulnerability where the pr.yml GitHub Action interpolates in an unsafe manner untrusted input, specifically the github.event.pull_request.head.repo.clone_url and…
AplazadaMedia (5.3)0.39%—OAKAIDenoAIDeno DeployAINodejsAI+29/8/202517/6/2026
oak is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. In versions 17.1.5 and below, it's possible to significantly slow down an oak server with specially crafted values of the x-forwarded-proto or x-forwarded-for headers.
AnalizadaAlta (7.5)0.24%—Dell Networker1/7/202517/6/2026
Dell NetWorker, versions 19.12.0.1 and prior, contains a Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
AplazadaAlta (8.1)0.58%—Codesupplyco NetworkerAI27/6/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in codesupplyco Networker networker allows PHP Local File Inclusion.This issue affects Networker: from n/a through <= 1.2.0.
AplazadaAlta (8.6)0.54%—Cisco Anyconnect VPN ServerAICisco Meraki MXAICisco Meraki Z Series Teleworker GatewayAI18/6/202517/6/2026
A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition in the Cisco AnyConnect service on an affected device. This vulnerability is due to&nbsp;variable…
AnalizadaMedia (5.3)0.57%—Cloudflare Workers-oauth-provider1/5/202517/6/2026
PKCE was implemented in the OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp . However, it was found that an attacker could cause the check to be skipped. Fixed in: https://github.com/cloudflare/workers-oauth-provider/pull/27…
AnalizadaMedia (6)0.32%—Cloudflare Workers-oauth-provider1/5/202517/6/2026
The OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp , did not correctly validate that redirect_uri was on the allowed list of redirect URIs for the given client registration. Fixed in: https://github.com/cloudflare/workers-oauth-provider/pull/26…
ModificadaMedia (6.5)0.30%—Dell Networker13/3/202517/6/2026
Dell NetWorker, versions prior to 19.11.0.4 and version 19.12, contains an URL Redirection to Untrusted Site ('Open Redirect') Vulnerability in NetWorker Management Console. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to a targeted application user being…
AnalizadaAlta (7.8)0.22%—Dell Networker17/2/202517/6/2026
Dell NetWorker Management Console, version(s) 19.11 through 19.11.0.3 & Versions prior to 19.10.0.7 contain(s) an improper neutralization of server-side vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability and run arbitrary code on the server.
AnalizadaAlta (7.8)0.20%—Dell Networker30/1/202517/6/2026
Dell NetWorker, version(s) prior to 19.11.0.3, all versions of 19.10 & prior versions contain(s) an Unquoted Search Path or Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
AplazadaMedia (6.5)0.35%—Octopus Kubernetes WorkerAIOctopus Kubernetes AgentAI16/1/202517/6/2026
In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes script pod log in clear-text. This was identified in Version 2 however it was determined that this could also be achieved in Version 1 and the fix was applied to both versions accordingly.
AnalizadaAlta (7.5)0.29%—Dell Networker3/12/202417/6/2026
Dell NetWorker, version(s) 19.10, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
AnalizadaAlta (7.8)0.13%—Dell Networker Management Console3/12/202417/6/2026
Dell NetWorker Management Console, version(s) 19.11, contain(s) an Improper Verification of Cryptographic Signature vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Code execution.
AplazadaMedia (5.3)0.50%—THE NetworkerAI27/3/202417/6/2026
The Networker - Tech News WordPress Theme with Dark Mode theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_reload_nav_menu() function in all versions up to, and including, 1.1.9. This makes it possible for unauthenticated attackers to modify the…