Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3037▲ 502 respecto a la semana anterior
Críticas / altas1448▲ 249 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 158 respecto a la semana anterior
772 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 1.4% | — | MonkeyAI | 16/9/2026 | 22/9/2026 | A Null Pointer Dereference in the mk_sched_event_close function (mk_server/mk_scheduler.c) of Monkey through commit 4fb0c16 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server. | |
| Aplazada | Alta (7.5) | 0.48% | — | MonkeytypeAI | 20/8/2026 | 18/9/2026 | Monkeytype is a minimalistic and customizable typing test. In 26.26.0 and earlier, the backend rate-limit key generator in backend/src/middlewares/rate-limit.ts uses client-controlled cf-connecting-ip and x-forwarded-for headers before the trust-proxy-derived req.ip value. An unauthenticated attacker can rotate either… | |
| Aplazada | Media (6.4) | 0.33% | — | Snow Monkey BlocksAI | 13/5/2026 | 17/6/2026 | The Snow Monkey Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-slick' attribute in all versions up to, and including, 24.1.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Aplazada | Media (5.5) | 2.1% | — | Eyal-gor P 69 Branch Monkey MCPAI | 1/5/2026 | 17/6/2026 | A vulnerability was identified in eyal-gor p_69_branch_monkey_mcp up to 69bc71874ce40050ef45fde5a435855f18af3373. The affected element is an unknown function of the file branch_monkey_mcp/bridge_and_local_actions/routes/advanced.py of the component Preview Endpoint. Such manipulation of the argument dev_script leads… | |
| Analizada | Media (6.9) | 0.18% | — | Ventismedia Mediamonkey | 21/3/2026 | 17/6/2026 | MediaMonkey 4.1.23 contains a denial of service vulnerability that allows local attackers to crash the application by opening a specially crafted MP3 file containing an excessively long URL string. Attackers can create a malicious MP3 file with a buffer containing 4000 bytes of data appended to a URL, which causes the… | |
| Aplazada | Alta (7.5) | 0.33% | — | Monkeybread Software MBS Dynapdf PluginAI | 12/2/2026 | 17/6/2026 | A stack overflow in the ZBarcode_Encode function of Monkeybread Software MBS DynaPDF Plugin v21.3.1.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Analizada | Alta (7.5) | 1.3% | — | Monkey-project Monkey | 29/1/2026 | 17/6/2026 | A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server. | |
| Analizada | Alta (7.5) | 1.2% | — | Monkey-project Monkey | 29/1/2026 | 17/6/2026 | An out-of-bounds read in the mk_mimetype_find function (mk_server/mk_mimetype.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server. | |
| Analizada | Alta (7.5) | 1.2% | — | Monkey-project Monkey | 29/1/2026 | 17/6/2026 | An out-of-bounds read in the header_cmp function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server. | |
| Analizada | Alta (7.5) | 8.6% | — | Monkey-project Monkey | 29/1/2026 | 17/6/2026 | A NULL pointer dereference in the mk_http_range_parse function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server. | |
| Analizada | Alta (7.5) | 1.2% | — | Monkey-project Monkey | 29/1/2026 | 17/6/2026 | An out-of-bounds read in the mk_vhost_fdt_close function (mk_server/mk_vhost.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server. | |
| Analizada | Alta (7.5) | 1.2% | — | Monkey-project Monkey | 29/1/2026 | 17/6/2026 | A use-after-free in the mk_http_request_end function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server. | |
| Analizada | Alta (7.5) | 1.1% | — | Monkey-project Monkey | 29/1/2026 | 17/6/2026 | A use-after-free in the mk_string_char_search function (mk_core/mk_string.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server. | |
| Analizada | Alta (7.5) | 1.2% | — | Monkey-project Monkey | 29/1/2026 | 17/6/2026 | An out-of-bounds read in the mk_ptr_to_buf in mk_core function (mk_memory.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server. | |
| Analizada | Alta (7.5) | 1.1% | — | Monkey-project Monkey | 29/1/2026 | 17/6/2026 | An out-of-bounds read in the http_parser_transfer_encoding_chunked function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted POST request to the server. | |
| Aplazada | Crítica (9.8) | 13% | — | Snow Monkey FormsAI | 28/1/2026 | 17/6/2026 | The Snow Monkey Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'generate_user_dirpath' function in all versions up to, and including, 12.0.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can… | |
| Analizada | Alta (7.1) | 0.24% | — | Monkeytype | 4/12/2025 | 17/6/2026 | Monkeytype is a minimalistic and customizable typing test. In 25.49.0 and earlier, there is improper handling of user input which allows an attacker to execute malicious javascript on anyone viewing a malicious quote submission. quote.text and quote.source are user input, and they're inserted straight into the DOM. If… | |
| Aplazada | Crítica (9.1) | 0.46% | — | Monkeysaudio Monkey S AudioAI | 28/10/2025 | 17/6/2026 | An out-of-bounds read vulnerability has been discovered in Monkey's Audio 11.31, specifically in the CAPECharacterHelper::GetUTF16FromUTF8 function. The issue arises from improper handling of the length of the input UTF-8 string, causing the function to read past the memory boundary. This vulnerability may result in a… | |
| Aplazada | Media (5.4) | 0.28% | — | Snow MonkeyAI | 26/9/2025 | 17/6/2026 | The Snow Monkey theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 29.1.5 via the request() function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and… | |
| Modificada | Baja (2.4) | 0.23% | — | Monkeytype | 25/9/2025 | 17/6/2026 | Monkeytype is a minimalistic and customizable typing test. In versions 25.36.0 and prior, improper handling of user input when loading a saved custom text results in XSS. This issue has been fixed in version 25.44.0. | |
| Analizada | Media (4.3) | 0.15% | — | Drunkenmonkey Search API Solr | 23/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Search API Solr allows Cross Site Request Forgery.This issue affects Search API Solr: from 0.0.0 before 4.3.9. | |
| Aplazada | Alta (7.1) | 0.21% | — | Pushmonkey Push Monkey PROAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in pushmonkey Push Monkey Pro – Web Push Notifications and WooCommerce Abandoned Cart push-monkey-desktop-push-notifications allows Cross Site Request Forgery.This issue affects Push Monkey Pro – Web Push Notifications and WooCommerce Abandoned Cart: from n/a through <=… | |
| Aplazada | Media (5.4) | 0.60% | — | Mobilemonkey Wp-chatbot FOR MessengerAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in MobileMonkey WP-Chatbot for Messenger allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-Chatbot for Messenger: from n/a through 4.7. | |
| Analizada | Crítica (9.6) | 0.88% | — | Monkeytype | 2/8/2024 | 17/6/2026 | Monkeytype is a minimalistic and customizable typing test. Monkeytype is vulnerable to Poisoned Pipeline Execution through Code Injection in its ci-failure-comment.yml GitHub Workflow, enabling attackers to gain pull-requests write access. The ci-failure-comment.yml workflow is triggered when the Monkey CI workflow… | |
| Modificada | Crítica (9.1) | 1.5% | — | 2inc Snow Monkey Forms | 28/6/2023 | 17/6/2026 | Directory traversal vulnerability in Snow Monkey Forms v5.1.1 and earlier allows a remote unauthenticated attacker to delete arbitrary files on the server. |