Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2577▼ 311 respecto a la semana anterior
Críticas / altas1352▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

10 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.7)0.27%—Vaxilu X-uiAI22/9/202622/9/2026
A reflected cross-site scripting vulnerability exists in x-ui 0.3.2. The management interface reflects the raw request URI into a client-side template binding expression used for sidebar menu highlighting. Server-side HTML entity escaping is ineffective in this context: the browser decodes the entities before the…
AplazadaAlta (8.8)0.30%—Vaxilu X-uiAI22/9/202625/9/2026
A horizontal privilege escalation vulnerability exists in x-ui 0.3.2. An authenticated user can modify the inbound proxy configurations of other users, including remark, port, protocol, settings, enabled state, expiry time and traffic quota, by submitting a request referencing the target resource identifier. The…
AplazadaMedia (4.8)0.29%—Vaxilu X-uiAI21/9/202622/9/2026
A session invalidation flaw exists in x-ui 0.3.2. The full user object is stored in a client-side signed cookie, and authentication only checks that a user object can be retrieved from the cookie without re-validating against the database or any session version. When an administrator changes the username or password,…
AplazadaAlta (7.6)0.32%—Vaxilu X-uiAI21/9/202622/9/2026
An improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can modify the xray configuration template through the settings interface and trigger a panel restart, causing the xray management gRPC service, which is bound to loopback by default, to be regenerated and bound to non-loopback…
AplazadaMedia (5.4)0.24%—BharatmlstackAITrufflebox-uiAI15/9/202622/9/2026
BharatMLStack up to and including 1.3.0 is vulnerable to Cross Site Scripting (XSS) via the component Trufflebox UI (trufflebox-ui) in ExpressionViewModal.jsx.
AplazadaMedia (6.1)0.25%—BharatmlstackAIBharatmlstack Trufflebox-uiAI15/9/202622/9/2026
BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site Scripting (XSS) in the component Trufflebox UI (trufflebox-ui) in GenericNumerixTable.jsx.
AplazadaAlta (7.2)0.61%—Xray-coreAIMhsanaei 3x-uiAI25/6/202625/6/2026
3X-UI is a web control panel for managing Xray-core servers. Prior to 3.3.1, an authenticated administrator can abuse the database import functionality to achieve arbitrary file write on the host by modifying Xray configuration values stored in the database. This can be leveraged to obtain code execution and…
AnalizadaCrítica (9.8)0.46%—Mhsanaei 3x-ui26/6/202517/6/2026
An issue in MHSanaei 3x-ui before v.2.5.3 and before allows a remote attacker to execute arbitrary code via the management script x-ui passes the no check certificate option to wget when downloading updates
ModificadaAlta (7.5)0.55%—Vaxilu X-ui18/9/20239/7/2026
An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password.
ModificadaCrítica (10)0.35%—Edex-ui Project Edex-ui28/4/202317/6/2026
eDEX-UI is a science fiction terminal emulator. Versions 2.2.8 and prior are vulnerable to cross-site websocket hijacking. When running eDEX-UI and browsing the web, a malicious website can connect to eDEX's internal terminal control websocket, and send arbitrary commands to the shell. The project has been archived…