Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
1318 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.42% | — | Frappe ErpnextAI | 20/9/2026 | 21/9/2026 | Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authenticated attackers can call get_projectwise_timesheet_data, get_timesheet_detail_rate, and get_timesheet endpoints to… | |
| Aplazada | Media (4.3) | 0.27% | — | Nextcloud DeckAI | 18/9/2026 | 18/9/2026 | The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission to manage the referenced board. | |
| Aplazada | Media (6.5) | 0.47% | — | Nextcloud Team FoldersAINextcloud WorkspaceAI | 18/9/2026 | 18/9/2026 | A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization controls. The workspace app enables organizations to delegate limited administrative privileges for team folder management… | |
| Aplazada | Media (6.2) | 0.19% | — | Nextcloud CirclesAI | 18/9/2026 | 18/9/2026 | Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this request, bypassing Nextcloud's core SSRF protections. The public, unauthenticated endpoints POST /apps/circles/event/ and… | |
| Pendiente de análisis | Alta (7.5) | 0.76% | — | Quarkus-websockets-nextAI | 17/9/2026 | 22/9/2026 | A flaw was found in quarkus-websockets-next. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by streaming messages over a single connection faster than the application can process them. Due to unbounded message buffering and a lack of read backpressure, this rapidly exhausts heap space,… | |
| Aplazada | Alta (8.8) | 0.52% | — | Next-tinacms-azureAISupabase AuthAI | 16/9/2026 | 30/9/2026 | Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled clientID and asks isUserAuthorized to validate the bearer token against that selected TinaCloud app instead of the self-hosted site's configured app. An attacker with any… | |
| Pendiente de análisis | Media (5.5) | 0.14% | — | NextflowAI | 15/9/2026 | 30/9/2026 | Nextflow is a DSL for data-driven computational pipelines. From 25.09.2-edge until 25.10.6 and 26.04.3, nextflow auth login writes Seqera Platform OIDC bearer tokens to ${NXF_HOME:-~/.nextflow}/seqera-auth.config through AuthCommandImpl.writeConfig in… | |
| Aplazada | Media (6.9) | 0.42% | — | Next-videoAI | 14/9/2026 | 30/9/2026 | next-video is a library for adding video to Next.js applications. Prior to 2.8.1, the GET endpoint exported by next-video/request-handler and commonly mounted at /api/video accepts an unauthenticated url query parameter, while src/utils/utils.ts isRemote() treats any value without an HTTP or HTTPS prefix as a local… | |
| Pendiente de análisis | Alta (7.2) | 0.45% | — | Nextgen Mirth ConnectAI | 11/9/2026 | 18/9/2026 | NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in disclosure of stored credentials for connected systems, arbitrary file write, and a denial-of-service condition. | |
| Aplazada | Alta (8.1) | 0.90% | — | Next Cart Store TO Woocommerce MigrationAI | 9/9/2026 | 9/9/2026 | The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.9.8 via the `NCWM_Kitconnect::run()` function. This is due to the plugin registering the `/wp-json/next_cart/v1/migration` REST route with `permission_callback` set to… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Next4biz Information Technologies INC CSMAI | 7/9/2026 | 9/9/2026 | Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (Customer Service Management): before 8.0.3. | |
| Aplazada | Alta (7.5) | 0.50% | — | Next4biz Information Technologies INC CSMAI | 7/9/2026 | 8/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Path Traversal. This issue affects CSM (Customer Service Management): from 6.8.9 before 8.0.3. | |
| Aplazada | Crítica (9) | 2.3% | — | Vercel Next.jsAI | 1/9/2026 | 9/9/2026 | Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently escape backslashes in route segments before constructing incremental-cache paths. In… | |
| Aplazada | Alta (8.7) | 0.51% | — | NextchatAI | 30/8/2026 | 10/9/2026 | NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key. The x-base-url header is validated using substring matching instead of hostname parsing, allowing any URL containing 'api.openai.com' to pass… | |
| Aplazada | Media (6.4) | 0.32% | — | Nextendweb Smart Slider 3AI | 28/8/2026 | 28/8/2026 | The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'slider' Block Attribute in all versions up to, and including, 3.5.1.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Aplazada | Crítica (9.1) | 0.73% | — | Nextcloud MCP ServerAI | 25/8/2026 | 9/9/2026 | Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nextcloud instance. Prior to 0.117.2, the POST /webhooks/nextcloud endpoint in nextcloud_mcp_server/vector/webhook_receiver.py has no authentication by default because WEBHOOK_SECRET defaults to None and startup validation does not… | |
| Aplazada | Media (6.9) | 0.58% | — | Alibaba Fusion NextAI | 24/8/2026 | 24/8/2026 | A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the function ConfigProvider.getContextProps of the file components/dialog/index.tsx of the component deepMerge. Performing a manipulation of the argument locale results in improperly controlled modification of object prototype… | |
| Aplazada | Media (5.4) | 0.38% | — | Next-tinacms-s3AINext-tinacms-dosAINext-tinacms-azureAINext-tinacms-cloudinaryAI | 19/8/2026 | 18/9/2026 | Tina is a headless content management system. Prior to next-tinacms-s3 23.0.4, next-tinacms-dos 23.0.4, next-tinacms-azure 14.0.4, and next-tinacms-cloudinary 26.0.4, the first-party production media adapters pass attacker-controlled object keys to storage SDK upload and delete operations without enforcing the… | |
| Aplazada | Alta (7.1) | 0.25% | — | Nextscripts Social Networks Auto PosterAI | 19/8/2026 | 26/8/2026 | The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string parameters it reflects back on one of its admin pages, allowing attackers to perform Reflected Cross-Site Scripting attacks against logged-in users such as administrators who are tricked into opening a… | |
| Aplazada | Crítica (9.9) | 1.0% | — | FrappeAIFrappe ErpnextAI | 17/8/2026 | 9/9/2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe execution because frappe.render_template is exposed without forcing restrict_globals, allowing server-side template injection and remote code… | |
| Aplazada | Alta (7.6) | 0.46% | — | Frappe ErpnextAI | 17/8/2026 | 9/9/2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.116.0 and 16.23.0, erpnext/selling/report/inactive_customers/inactive_customers.py accepts an unvalidated doctype filter and interpolates it into raw SQL in get_sales_details and get_last_sales_amt, allowing an authenticated user to… | |
| Aplazada | Media (5.3) | 0.29% | — | Next TerminalAI | 17/8/2026 | 24/9/2026 | Next Terminal fails to enforce per-asset authorization checks on the portal ping and wake-on-LAN endpoints, allowing any authenticated user to probe and wake assets they are not granted access to. Attackers can call these endpoints with arbitrary asset identifiers to retrieve asset information including display names,… | |
| Pendiente de análisis | Crítica (9.1) | 0.64% | — | Nextauth.js Next-authAI | 13/8/2026 | 18/9/2026 | NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, applications that gate access by checking only for the existence of the auth object returned by the auth() wrapper can fail open when Auth.js has a server configuration error. In middleware, Route Handlers, React Server… | |
| Pendiente de análisis | Crítica (9.1) | 0.73% | — | Nextauth.js Next-authAICoreAI | 13/8/2026 | 18/9/2026 | NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the defaultNormalizer used by the email and magic-link sign-in flow validates an address before applying Unicode normalization. An address can contain a Unicode character such as U+FF20 FULLWIDTH… | |
| Aplazada | Media (5.1) | 0.26% | — | Next AI Draw.ioAI | 13/8/2026 | 9/9/2026 | Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site scripting vulnerability in the mcp query parameter that is interpolated without escaping into HTML and JavaScript. Attackers can craft malicious URLs to execute arbitrary JavaScript in the localhost origin, enabling exfiltration of diagram sessions… |