Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 76 respecto a la semana anterior
Críticas / altas1446▲ 304 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 0.42% | — | PgvectorAI | 1/10/2026 | 2/10/2026 | IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, which can lead to arbitrary code execution. | |
| En análisis | Crítica (9.2) | 0.27% | — | Simple-gitAISimple-git Argv-parserAI | 29/9/2026 | 30/9/2026 | simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 2.0.1 of the argv-parser package, parseEnv omits VISUAL from GitEnvKeys, so prepareEnv drops the value before vulnerabilityCheck can classify it as allowUnsafeEditor. A… | |
| Pendiente de análisis | Alta (8.8) | 0.10% | — | Google GvisorAI | 25/9/2026 | 25/9/2026 | Improper Exposure of Resource to Wrong Sphere in the host file helper (gofer) in Google gVisor prior to commit 573a9e73cf844f on Linux platforms with CUSE enabled allows a local attacker with container image deployment privileges to achieve root code execution on the host system. By including a /dev/cuse character… | |
| Aplazada | Media (5.3) | 0.16% | — | Gvectors WpforoAI | 25/9/2026 | 25/9/2026 | The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does not verify the source of client-supplied IP address headers before using them to key its per-visitor rate limit on paid AI requests, allowing unauthenticated attackers to bypass the limit by spoofing the header and exhaust the site owner's metered AI… | |
| Aplazada | Media (6.4) | 0.20% | — | Gvectors WpforoAI | 25/9/2026 | 25/9/2026 | The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'telegram' profile field in versions up to, and including, 3.1.6. This is due to insufficient input sanitization and output escaping in the profile_update action — the raw $_POST['data'] array is copied into a $custom_fields… | |
| Aplazada | Alta (7.5) | 0.31% | — | Gvectors Wpforo ForumAI | 24/9/2026 | 24/9/2026 | The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes a user-supplied profile field value, allowing authenticated users with Subscriber-level access and above to inject a PHP Object. No POP chain is present in the wpForo Forum WordPress plugin before… | |
| Aplazada | Media (6.5) | 0.22% | — | Gvectors Wpforo ForumAI | 23/9/2026 | 23/9/2026 | Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 versions. | |
| Aplazada | Media (4.3) | 0.39% | — | Gvectors WpforoAI | 22/9/2026 | 23/9/2026 | The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to take… | |
| Aplazada | Alta (7.8) | 0.20% | — | Geovision Gv-remote E-mapAI | 17/9/2026 | 18/9/2026 | A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location. If successfully… | |
| Pendiente de análisis | Alta (7) | 0.17% | — | Gnome GvfsAI | 10/9/2026 | 1/10/2026 | A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race… | |
| Aplazada | Alta (7.5) | 0.46% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated clients to declare unbounded VLSVR frame lengths and indefinitely delay blocking receives, allowing remote exhaustion of memory, connection, and worker resources. | |
| Aplazada | Alta (7.5) | 0.57% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.14 (260903) fails to validate attacker-controlled variable-length fields before copying them into fixed-size stack buffers in multiple VLSVR request handlers, allowing an unauthenticated remote attacker to crash the VLSVR service. | |
| Aplazada | Media (6.5) | 0.55% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 fails to restrict the filename supplied to BKDownloadLink.cgi, allowing a remote user with valid web credentials to read arbitrary files accessible to the root-run web service. | |
| Aplazada | Alta (7.5) | 0.55% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 fails to bound the number of Scopes tokens in unauthenticated ONVIF WS-Discovery Probe requests, allowing a remote attacker to corrupt stack control state and crash the discovery process. | |
| Aplazada | Alta (7.5) | 0.46% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 improperly manages PTZ connection state, allowing an unauthenticated remote client to block the accept loop and prevent new PTZ connections. | |
| Aplazada | Crítica (9.4) | 0.51% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clients to retrieve PTZ information and issue PTZ or raw serial commands. | |
| Aplazada | Media (4.9) | 0.44% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF SetUser requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker. | |
| Aplazada | Media (4.9) | 0.44% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF CreateUsers requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker. | |
| Aplazada | Alta (7.2) | 0.54% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 allows an administrator-controlled FTP username containing shell metacharacters to be executed as arbitrary root commands during a subsequent FTP-account update. | |
| Aplazada | Media (4.9) | 0.44% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 fails to limit repeated Username elements in ONVIF DeleteUsers requests, allowing an authenticated administrator to overflow a stack array and crash the ONVIF worker. | |
| Aplazada | Media (4.9) | 0.44% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 copies an oversized ONVIF SetUser password into a fixed stack field, allowing an authenticated administrator to crash the ONVIF worker. | |
| Aplazada | Media (4.9) | 0.44% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 copies oversized ONVIF CreateUsers username or password values into fixed stack fields, allowing an authenticated administrator to crash the ONVIF worker. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations. | |
| Aplazada | Alta (8.8) | 0.65% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 allows an authenticated ONVIF user to inject shell commands through ConsumerReference.Address and execute arbitrary commands as root. | |
| Aplazada | Alta (7.2) | 0.70% | — | Geovision Gv-lpc2211AI | 10/9/2026 | 10/9/2026 | GeoVision GV-LPC2211 V1.13 allows administrator-controlled WEP key values containing shell syntax to execute arbitrary commands as root. |