Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
227 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.11% | — | Fabasoft Folio ClientAIFabasoft Egov-suiteAI | 24/9/2026 | 26/9/2026 | Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension via web messaging, does not restrict which web origins may invoke its functions by default. The registry value VALIDDOMAINS, which limits permitted origins, was optional and empty by default,… | |
| Aplazada | Media (5.3) | 0.45% | — | Governikus AusweisappAI | 15/9/2026 | 16/9/2026 | A weakness has been identified in Governikus AusweisApp up to 2.5.4. Affected is an unknown function of the component StartPAOSResponse Handler. Executing a manipulation of the argument ResultMessage can lead to cross site scripting. The attack can be launched remotely. Upgrading to version 2.5.5 is able to address… | |
| Aplazada | Alta (7.5) | 0.63% | — | Govcert.lu EML ParserAI | 25/8/2026 | 9/9/2026 | eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.2, eml_parser.routing.noparenthesis in eml_parser/routing.py removes parenthesized CFWS comments from Received: headers with a regex-based fix-point loop whose… | |
| Aplazada | Media (5.3) | 0.52% | — | Govcert.lu EML ParserAI | 25/8/2026 | 9/9/2026 | eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.2, eml_parser.parser.HeaderParser.header_fetch_parse in eml_parser/parser.py uses email.utils.getaddresses() to parse address-bearing e-mail headers. A deeply… | |
| Aplazada | Media (6.5) | 0.52% | — | Govcert.lu EML ParserAI | 25/8/2026 | 9/9/2026 | eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.2, the clean_found_uri function in eml_parser/parser.py validates potential URL strings before unescaping HTML entities used for colon, slash, or period… | |
| Pendiente de análisis | Alta (8.8) | 0.81% | — | Redhat Advanced Cluster Management FOR KubernetesAIRedhat Governance Policy Addon ControllerAI | 18/8/2026 | 27/8/2026 | A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container image. This allows an attacker to run a controlled image with… | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Purview Data Governance | 24/7/2026 | 29/7/2026 | Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 2.1% | — | Localgovdrupal Localgov Workflows | 10/7/2026 | 6/8/2026 | Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0. | |
| Pendiente de análisis | Media (5.1) | 0.49% | — | U.s. Government Accountability Office Electronic Protest Docketing SystemAICivilian Board OF Contract Appeals Electronic Docketing SystemAI | 18/6/2026 | 24/6/2026 | The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) do not validate X-Forwarded-For HTTP headers, allowing a remote attacker with compromised administrator credentials to bypass network access… | |
| Pendiente de análisis | Alta (8.7) | 0.72% | — | U.s. Government Accountability Office Electronic Protest Docketing SystemAICivilian Board OF Contract Appeals Electronic Docketing SystemAI | 18/6/2026 | 22/6/2026 | The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the 'epds_role_id' parameter without verification, allowing a remote, authenticated attacker to escalate their own… | |
| Aplazada | Alta (8.1) | 0.47% | — | Thegov CoreAI | 17/6/2026 | 17/6/2026 | Unauthenticated Local File Inclusion in Thegov Core < 2.0.23 versions. | |
| Pendiente de análisis | Media (4.3) | 0.26% | — | SAP Master Data GovernanceAI | 9/6/2026 | 23/7/2026 | SAP MDG (Review Match Groups Application) does not perform the necessary authorization checks for authenticated users. This could allow a low-privileged user to perform actions that would otherwise be restricted, resulting in escalation of privileges. This has a low impact on integrity, while confidentiality and… | |
| Aplazada | Media (6.3) | 0.43% | — | Govcert.lu EML ParserAI | 26/5/2026 | 24/7/2026 | eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.1, EmlParser.get_raw_body_text() recurses unconditionally for every nested message/rfc822 attachment without any depth limit. An attacker who can supply a badly… | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Pendiente de análisis | Media (5.1) | 0.59% | — | Cisa Manage.get.govAI | 7/5/2026 | 25/6/2026 | manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assign domain manager privileges for domains not already in another organization. Fixed in 1.176.0 on or around 2026-04-30. | |
| Aplazada | Media (5.5) | 0.50% | — | Algovate Xhs-mcpAI | 29/4/2026 | 17/6/2026 | A vulnerability was found in Algovate xhs-mcp 0.8.11. This affects the function xhs_publish_content of the file src/server/mcp.server.ts of the component MCP Interface. Performing a manipulation of the argument media_paths results in server-side request forgery. The attack may be initiated remotely. The exploit has… | |
| Analizada | Crítica (9.3) | 0.80% | — | Dragonsoft Gcb/fcb Government Financial Cybersecurity Configuration Audit Software | 17/3/2026 | 17/6/2026 | GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access certain APIs to create a new administrative account. | |
| Analizada | Media (5.5) | 0.18% | — | Govcert.lu EML Parser | 7/3/2026 | 17/6/2026 | eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to version 2.0.1, the official example script examples/recursively_extract_attachments.py contains a path traversal vulnerability that allows arbitrary file write… | |
| Aplazada | Crítica (9.3) | 0.39% | — | Govee H6056AIGovee HomeAI | 18/12/2025 | 30/9/2026 | A flaw in the binding process of Govee’s cloud platform and devices allows a remote attacker to bind an existing, online Govee device to the attacker’s account, resulting in full control of the device and removal of the device from its legitimate owner’s account. The server‑side API allows device association using a… | |
| Analizada | Media (5.1) | 0.19% | — | Idieikon Governalia | 2/12/2025 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) in IDI Eikon's Governalia. The vulnerability allows an attacker to execute JavaScript code in the victim's browser when a malicious URL with the 'q' parameter in '/search' is sent to them. This vulnerability can be exploited to steal sensitive information such as session cookies or… | |
| Aplazada | Media (6.8) | 0.24% | — | Wickr GOVAIWickr EnterpriseAIAmazon WickrAI | 21/11/2025 | 17/6/2026 | Improper resource release in the call termination process in AWS Wickr before version 6.62.13 on Windows, macOS and Linux may allow a call participant to continue receiving audio input from another user after they close their call window. This issue occurs under certain conditions, which require the affected user to… | |
| Aplazada | Alta (8.7) | 0.27% | — | Egovframe-common-componentsAI | 19/11/2025 | 14/7/2026 | eGovFramework/egovframe-common-components versions up to and including 4.3.1 includes Web Editor image upload and related file delivery functionality that uses symmetric encryption to protect URL parameters, but exposes an encryption oracle that allows attackers to generate valid ciphertext for chosen values. The… | |
| Aplazada | Media (6.9) | 0.56% | — | Egovframework Egovframe-common-componentsAI | 19/11/2025 | 14/7/2026 | eGovFramework/egovframe-common-components versions up to and including 4.3.1 contain an unauthenticated file upload vulnerability via the /utl/wed/insertImage.do and /utl/wed/insertImageCk.do image upload endpoints. These controllers accept multipart requests without authentication, pass the uploaded content to a… | |
| Aplazada | Crítica (9.3) | 0.45% | — | GOV CMSAI | 4/9/2025 | 17/6/2026 | Input from search query parameter in GOV CMS is not sanitized properly, leading to a Blind SQL injection vulnerability, which might be exploited by an unauthenticated remote attacker. Versions 4.0 and above are not affected. | |
| Analizada | Media (5.3) | 0.34% | — | IBM Security Verify Governance | 28/8/2025 | 17/6/2026 | IBM Security Verify Governance Identity Manager 10.0.2 could allow a remote attacker to obtain sensitive information when detailed technical error messages are returned. This information could be used in further attacks against the system. |