Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.9) | 0.79% | — | Daggerheart Query WranglerAI | 20/8/2026 | 20/8/2026 | Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions. | |
| Aplazada | Alta (8.8) | 1.0% | — | Daggerheart Query WranglerAI | 16/8/2026 | 20/8/2026 | The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_ajax_qw_form_ajax handler, combined with unsanitized attacker-controlled options… | |
| Pendiente de análisis | Alta (8.8) | 0.68% | — | Cloudflare Pages-actionAICloudflare Wrangler-actionAI | 12/8/2026 | 28/8/2026 | Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execution issue in `src/index.ts` reachable from certain GitHub Actions workflow configurations. Successful exploitation may expose workflow secrets such as CLOUDFLARE_API_TOKEN… | |
| Aplazada | Media (4.3) | 0.27% | — | Daggerheart Query WranglerAI | 23/7/2026 | 23/7/2026 | Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions. | |
| Aplazada | Crítica (9.1) | 0.54% | — | Jonathan Daggerhart Widget WranglerAI | 25/3/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Jonathan Daggerhart Widget Wrangler widget-wrangler allows Code Injection.This issue affects Widget Wrangler: from n/a through <= 2.3.9. | |
| Analizada | Alta (7.7) | 1.5% | — | Cloudflare Wrangler | 20/1/2026 | 17/6/2026 | SummaryA command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The issue occurs because the `--commit-hash` parameter is passed directly to a shell command without proper validation or sanitization, allowing an attacker with control of `--commit-hash` to execute… | |
| Aplazada | Alta (8.5) | 0.34% | — | FilewranglerAI | 20/8/2025 | 16/6/2026 | FileWrangler <= 5.30 suffers from a stack-based buffer overflow vulnerability when parsing directory listings from an FTP server. A malicious server can send an overlong folder name in response to a LIST command, triggering memory corruption during client-side rendering. Exploitation requires passive user… | |
| Aplazada | Media (5.4) | 0.20% | — | Daggerheart Query WranglerAI | 1/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jonathan Daggerhart Query Wrangler query-wrangler allows Cross Site Request Forgery.This issue affects Query Wrangler: from n/a through <= 1.5.54. | |
| Modificada | Alta (8) | 0.63% | — | Cloudflare Wrangler | 29/12/2023 | 17/6/2026 | The V8 inspector intentionally allows arbitrary code execution within the Workers sandbox for debugging. wrangler dev would previously start an inspector server listening on all network interfaces. This would allow an attacker on the local network to connect to the inspector and run arbitrary code. Additionally, the… | |
| Modificada | Media (5.7) | 0.70% | — | Cloudflare Wrangler | 29/12/2023 | 17/6/2026 | Sending specially crafted HTTP requests and inspector messages to Wrangler's dev server could result in any file on the user's computer being accessible over the local network. An attacker that could trick any user on the local network into opening a malicious website could also read any file. | |
| Modificada | Media (6.1) | 0.38% | — | Daggerheart Query Wrangler | 16/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jonathan Daggerhart Query Wrangler plugin <= 1.5.51 versions. | |
| Modificada | Media (5.7) | 0.82% | — | Cloudflare Wrangler | 3/8/2023 | 17/6/2026 | The Wrangler command line tool (<=wrangler@3.1.0 or <=wrangler@2.20.1) was affected by a directory traversal vulnerability when running a local development server for Pages (wrangler pages dev command). This vulnerability enabled an attacker in the same network as the victim to connect to the local development server… | |
| Modificada | Alta (7.5) | 0.68% | — | Suse Wrangler | 7/2/2023 | 17/6/2026 | A Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in SUSE Rancher allows remote attackers to cause denial of service by supplying specially crafted git credentials. This issue affects: SUSE Rancher wrangler version 0.7.3 and prior versions; wrangler… | |
| Modificada | Crítica (9.8) | 3.8% | — | Suse Wrangler | 7/2/2023 | 17/6/2026 | A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in wrangler of SUSE Rancher allows remote attackers to inject commands in the underlying host via crafted commands passed to Wrangler. This issue affects: SUSE Rancher wrangler version 0.7.3 and prior versions;… | |
| Modificada | Media (6.4) | 1.8% | — | Barebones TextwranglerBarebones BbeditBarebones Yojimbo | 31/12/2013 | 16/6/2026 | The software update mechanism as used in Bare Bones Software Yojimbo before 4.0, TextWrangler before 4.5.3, and BBEdit before 10.5.5 does not properly download and verify updates before installation, which allows attackers to perform "tampering or corruption" of the updates. | |
| Modificada | Alta (9.3) | 8.6% | — | Cursorarts Zipwrangler | 4/5/2010 | 16/6/2026 | Stack-based buffer overflow in CursorArts ZipWrangler 1.20 allows user-assisted remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename. |