Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2744▼ 71 respecto a la semana anterior
Críticas / altas1416▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)106▼ 394 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.38% | — | Vvbbnn00 Warp-clash-apiAI | 13/9/2026 | 14/9/2026 | A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. Affected is the function get_surge_subscription of the file services/subscription.py of the component Subscription Handler. Such manipulation of the argument key leads to improper access controls. The attack may… | |
| Aplazada | Baja (1.3) | 0.25% | — | Vvbbnn00 Warp-clash-apiAI | 13/9/2026 | 16/9/2026 | A vulnerability was determined in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This impacts an unknown function of the component Save Account Job. This manipulation causes race condition. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitability is… | |
| Aplazada | Baja (1.3) | 0.25% | — | Vvbbnn00 Warp-clash-apiAI | 13/9/2026 | 14/9/2026 | A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This affects the function doUpdateLicenseKey. The manipulation results in race condition. The attack can be launched remotely. The attack requires a high level of complexity. The exploitability is reported as… | |
| Aplazada | Media (5.5) | 0.65% | — | Vvbbnn00 Warp-clash-apiAI | 13/9/2026 | 21/9/2026 | A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted element is the function authorized. The manipulation of the argument SECRET_KEY leads to missing authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and… | |
| Aplazada | Alta (8.4) | 0.17% | — | Clash-verge-service-ipcAI | 6/6/2026 | 23/7/2026 | clash-verge-service-ipc before 2.3.0 has a world-reachable IPC endpoint, leading to local privilege escalation. | |
| Aplazada | Alta (7.8) | 0.23% | — | Clash Verge REVAI | 7/10/2025 | 17/6/2026 | Clash Verge Rev thru 2.2.3 (fixed in 2.3.0) forces the installation of system services(clash-verge-service) by default and exposes key functions through the unauthorized HTTP API `/start_clash`, allowing local users to submit arbitrary bin_path parameters and pass them directly to the service process for execution,… | |
| Modificada | Media (6.9) | 0.89% | — | Clashforwindows Clash | 7/6/2024 | 17/6/2026 | A vulnerability was found in Clash up to 0.20.1 on Windows. It has been declared as critical. This vulnerability affects unknown code of the component Proxy Port. The manipulation leads to improper authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is… | |
| Modificada | Crítica (9.8) | 1.3% | — | Clash Project Clash | 23/2/2023 | 17/6/2026 | Clash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via overwriting the configuration file (cfw-setting.yaml). | |
| Modificada | Alta (7.8) | 0.32% | — | Clash Project Clash | 29/9/2022 | 17/6/2026 | A misconfiguration in the Service Mode profile directory of Clash for Windows v0.19.9 allows attackers to escalate privileges and execute arbitrary commands when Service Mode is activated. | |
| Modificada | Crítica (9.8) | 1.8% | — | Clash Project Clash | 28/3/2022 | 17/6/2026 | Clash for Windows v0.19.8 was discovered to allow arbitrary code execution via a crafted payload injected into the Proxies name column. | |
| Modificada | Alta (8.8) | 0.68% | — | Clash Project Clash | 21/3/2022 | 17/6/2026 | In Dreamacro Clash for Windows v0.11.4, an attacker could embed a malicious iframe in a website with a crafted URL that would launch the Clash Windows client and force it to open a remote SMB share. Windows will perform NTLM authentication when opening the SMB share and that request can be relayed (using a tool like… |