Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.3) | 0.12% | — | Johnsoncontrols Easyio NEOAI | 1/10/2026 | 2/10/2026 | - Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack. This issue affects EasyIO NEO: before 3.3b25. | |
| Aplazada | Media (6.3) | 0.24% | — | Johnsoncontrols Easy IO NEOAI | 1/10/2026 | 2/10/2026 | - Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations. This issue affects Easy IO Neo: before 3.3b63. | |
| Aplazada | Alta (7.2) | 0.24% | — | Johnsoncontrols NEO Series Mvp2AI | 1/10/2026 | 2/10/2026 | - On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations. This issue affects Neo Series MVP2: before 3.3b63. | |
| Aplazada | Alta (7.2) | 0.49% | — | KaneoAI | 22/9/2026 | 22/9/2026 | Kaneo versions 2.3.12 before 2.12.2 contain a missing authorization vulnerability that allows authenticated workspace members with viewer or member roles to delete and modify tasks beyond their assigned permissions by exploiting the bulk task endpoint that omits workspace permission checks. Attackers can send requests… | |
| Aplazada | Media (6.8) | 0.21% | — | Oracle HelidonAIOracle Helidon-integrations-neo4jAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-integrations-neo4j). Supported versions that are affected are 3.0.0-3.2.20 and 4.0.0-4.5.4. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware… | |
| Aplazada | Crítica (9.8) | 0.60% | — | Apache SyncopeAINeo4jAI | 14/9/2026 | 14/9/2026 | Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue. | |
| Aplazada | Crítica (9.3) | 0.41% | — | DJI NEOAIDJI NEO 2AIDJI FlipAIDJI AIR 3AI+12 | 27/8/2026 | 28/8/2026 | DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticated users to upload files without limits on file size, file count, or total storage consumed in **/blackbox/upgrade/**, as well as overwrite existing files in that directory. An attacker with access to… | |
| Aplazada | Alta (7) | 0.17% | — | ARM Trusted Firmware-mAIInfineon Psoc64AIRaspberrypi Rp2350AI | 26/8/2026 | 9/9/2026 | On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer. | |
| Aplazada | Media (6) | 0.24% | — | DJI NEOAIDJI NEO 2AIDJI FlipAIDJI AIR 3AI+12 | 24/8/2026 | 26/8/2026 | The HTTP media server on DJI drones does not enforce sufficient limits on incoming connections or request rates. An attacker with access to the drone's internal network can exhaust the server's connection pool by repeatedly requesting a stored media file, preventing the server from handling legitimate requests and… | |
| Aplazada | Alta (8.5) | 0.23% | — | DJI NEOAIDJI NEO 2AIDJI FlipAIDJI AIR 3AI+12 | 24/8/2026 | 26/8/2026 | DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, including the SSID, PSK, MAC address, regulatory country code, and wireless channel. An attacker can overwrite the Wi-Fi PSK with a known value and connect… | |
| Aplazada | Alta (8.7) | 0.41% | — | DJI NEOAIDJI NEO 2AIDJI FlipAIDJI AIR 3AI+12 | 24/8/2026 | 26/8/2026 | The HTTP media server running on DJI drones serves stored photos and videos through the `/v2` endpoint without authenticating the requesting client. Filenames follow a predictable pattern, allowing an attacker who joins the drone's internal network to enumerate valid filenames and exfiltrate stored photos and videos.… | |
| Pendiente de análisis | Media (5.3) | 0.25% | — | Infineon Airoc Wifi DriverAI | 22/8/2026 | 26/8/2026 | The Infineon Airoc Wi-Fi driver's transmit callback airoc_mgmt_send() in drivers/wifi/infineon/airoc_wifi.c allocates a net_buf from the fixed airoc_pool for every outbound packet. When whd_network_send_ethernet_data() returns a synchronous failure, the underlying WHD library does not take ownership of the buffer, but… | |
| Aplazada | Crítica (9.4) | 0.09% | — | DJI NEOAIDJI NEO 2AIDJI FlipAIDJI AIR 3AI+12 | 21/8/2026 | 26/8/2026 | DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encryption. When a client attempts to connect to the drone over Wi-Fi, or when the drone is switched to QuickTransfer mode, the DJI Fly application exchanges DUML messages with the drone over BLE,… | |
| Pendiente de análisis | Crítica (9.8) | 1.7% | — | NEO MJSAIAI MCPAI | 20/8/2026 | 3/9/2026 | Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server, where the checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled absolutePath values into shell commands, enabling arbitrary OS command execution… | |
| Pendiente de análisis | Alta (7.6) | 0.49% | — | Neo4j GraphqlAI | 18/8/2026 | 9/9/2026 | @neo4j/graphql from 5.2.0 until the patched versions fails to enforce field-level @authentication rules on root custom-resolver fields when a type-level @authentication rule is also present on the same operation type. When both a type-level @authentication (on Query/Mutation) and a field-level @authentication (on a… | |
| Pendiente de análisis | Alta (7.5) | 0.74% | — | Parisneo LollmsAI | 9/8/2026 | 3/9/2026 | A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises from the improper handling of user-controlled path input, which is directly joined into a filesystem path without sanitization or containment… | |
| Pendiente de análisis | Alta (8.2) | 0.59% | — | Neo4j GraphqlAI | 6/8/2026 | 18/8/2026 | @neo4j/graphql library versions prior to 7.5.6 fail to verify the authenticity of a client-supplied, pre-decoded JWT object passed through GraphQL subscription connectionParams. As a result, any unauthenticated remote client that can open a GraphQL-over-WebSocket connection can forge arbitrary JWT claims (e.g. sub,… | |
| Analizada | Media (5.5) | 0.54% | — | Neo4j | 5/8/2026 | 28/8/2026 | Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask. When an unauthenticated client sends a selected protocol version followed by 32 continuation bytes in the capability mask, the decoder resets the reader index and waits for more bytes instead of… | |
| Aplazada | Alta (8.6) | 0.46% | — | QTI NeonAI | 28/7/2026 | 30/7/2026 | QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets to the host without bounding them, so an unauthenticated client can drive relay-to-host amplification and cause a denial of service on the host. No… | |
| Aplazada | Alta (7.2) | 0.46% | — | Getgrav GravAINeos FormAI | 15/7/2026 | 15/7/2026 | Grav before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename parameter, which is validated against path traversal before Twig processing but never re-validated after rendering. Attackers can submit form data containing path traversal sequences that are processed through… | |
| Aplazada | Crítica (9.2) | 0.46% | — | LangroidAINeo4jAI | 10/7/2026 | 10/7/2026 | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.5, Neo4jChatAgent passes LLM-generated Cypher queries straight to the Neo4j driver with no validation, no statement-type allowlist, and no opt-out gate. The query text is influenceable by prompt injection (direct user… | |
| Aplazada | Alta (8.1) | 0.44% | — | NeobeatAI | 17/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in NeoBeat <= 1.7 versions. | |
| Aplazada | Alta (8.1) | 0.47% | — | RoneousAI | 17/6/2026 | 30/9/2026 | Unauthenticated Local File Inclusion in Roneous <= 2.1.5 versions. | |
| Pendiente de análisis | Crítica (9.1) | 0.54% | — | ARM C1-ultraAIARM C1-premiumAIARM Neoverse V3AIARM Neoverse V3aeAI+17 | 9/6/2026 | 4/9/2026 | Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher exception level. | |
| Aplazada | Baja (1.9) | 0.92% | — | NeovimAI | 8/6/2026 | 23/7/2026 | A flaw has been found in Neovim up to 0.12.2. Affected by this issue is the function M.read of the file runtime/lua/vim/secure.lua of the component View Branch. Executing a manipulation of the argument path can lead to command injection. It is possible to launch the attack on the local host. The exploit has been… |