Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2577▼ 311 respecto a la semana anterior
Críticas / altas1352▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.7) | 0.27% | — | Vaxilu X-uiAI | 22/9/2026 | 22/9/2026 | A reflected cross-site scripting vulnerability exists in x-ui 0.3.2. The management interface reflects the raw request URI into a client-side template binding expression used for sidebar menu highlighting. Server-side HTML entity escaping is ineffective in this context: the browser decodes the entities before the… | |
| Aplazada | Alta (8.8) | 0.30% | — | Vaxilu X-uiAI | 22/9/2026 | 25/9/2026 | A horizontal privilege escalation vulnerability exists in x-ui 0.3.2. An authenticated user can modify the inbound proxy configurations of other users, including remark, port, protocol, settings, enabled state, expiry time and traffic quota, by submitting a request referencing the target resource identifier. The… | |
| Aplazada | Media (4.8) | 0.29% | — | Vaxilu X-uiAI | 21/9/2026 | 22/9/2026 | A session invalidation flaw exists in x-ui 0.3.2. The full user object is stored in a client-side signed cookie, and authentication only checks that a user object can be retrieved from the cookie without re-validating against the database or any session version. When an administrator changes the username or password,… | |
| Aplazada | Alta (7.6) | 0.32% | — | Vaxilu X-uiAI | 21/9/2026 | 22/9/2026 | An improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can modify the xray configuration template through the settings interface and trigger a panel restart, causing the xray management gRPC service, which is bound to loopback by default, to be regenerated and bound to non-loopback… | |
| Aplazada | Media (5.4) | 0.24% | — | BharatmlstackAITrufflebox-uiAI | 15/9/2026 | 22/9/2026 | BharatMLStack up to and including 1.3.0 is vulnerable to Cross Site Scripting (XSS) via the component Trufflebox UI (trufflebox-ui) in ExpressionViewModal.jsx. | |
| Aplazada | Media (6.1) | 0.25% | — | BharatmlstackAIBharatmlstack Trufflebox-uiAI | 15/9/2026 | 22/9/2026 | BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site Scripting (XSS) in the component Trufflebox UI (trufflebox-ui) in GenericNumerixTable.jsx. | |
| Aplazada | Alta (7.2) | 0.61% | — | Xray-coreAIMhsanaei 3x-uiAI | 25/6/2026 | 25/6/2026 | 3X-UI is a web control panel for managing Xray-core servers. Prior to 3.3.1, an authenticated administrator can abuse the database import functionality to achieve arbitrary file write on the host by modifying Xray configuration values stored in the database. This can be leveraged to obtain code execution and… | |
| Analizada | Crítica (9.8) | 0.46% | — | Mhsanaei 3x-ui | 26/6/2025 | 17/6/2026 | An issue in MHSanaei 3x-ui before v.2.5.3 and before allows a remote attacker to execute arbitrary code via the management script x-ui passes the no check certificate option to wget when downloading updates | |
| Modificada | Alta (7.5) | 0.55% | — | Vaxilu X-ui | 18/9/2023 | 9/7/2026 | An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password. | |
| Modificada | Crítica (10) | 0.35% | — | Edex-ui Project Edex-ui | 28/4/2023 | 17/6/2026 | eDEX-UI is a science fiction terminal emulator. Versions 2.2.8 and prior are vulnerable to cross-site websocket hijacking. When running eDEX-UI and browsing the web, a malicious website can connect to eDEX's internal terminal control websocket, and send arbitrary commands to the shell. The project has been archived… |