Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2727▼ 85 respecto a la semana anterior
Críticas / altas1416▲ 186 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)101▼ 398 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Sin puntuar | 0.21% | — | Algorithm Ahocorasick XSAI | 30/9/2026 | 30/9/2026 | Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length before the scalar is stringified. The matches, first_match and match_details methods use the T_STD_STRING typemap to translate Perl scalars (SVs) into strings via the std::string constructor, using the SvPV macro to stringify the… | |
| Aplazada | Media (4.7) | 0.35% | — | Oras GOAI | 16/9/2026 | 16/9/2026 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/utils.go accepts an absolute URL from a registry-controlled Link response header without validating its scheme, host, or port. Tags, Referrers, and Repositories pagination operations then issue a GET request… | |
| Aplazada | Alta (8.8) | 0.63% | — | Oras-goAI | 16/9/2026 | 16/9/2026 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked with io.deis.oras.content.unpack=true can write outside the store working directory. The pushDir path through extractTarDirectory and ensureLinkPath validates symlink targets lexically,… | |
| Aplazada | Media (6.5) | 0.54% | — | OrasAI | 25/8/2026 | 9/9/2026 | ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries. In ORAS CLI versions up to and including 1.3.2, the recursive referrer traversal does not track visited descriptors, so a malicious OCI registry that returns a cyclic referrer graph causes unbounded recursion and memory… | |
| Aplazada | Alta (7.1) | 0.43% | — | Oras-goAI | 17/7/2026 | 23/7/2026 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 validates a hardlink target relative to the extract base but returns the unresolved target, causing os.Link("victim.secret", "<extract_base>/payload.tar.gz/evil_cwd_link") to resolve header.Linkname… | |
| Aplazada | Media (6.9) | 0.51% | — | Oras-goAI | 17/7/2026 | 23/7/2026 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, resolveWritePath() in content/file/file.go uses a lexical filepath.Rel check for workingDir and does not account for symlink traversal, so when AllowPathTraversalOnWrite=false an attacker-controlled blob title through ocispec.AnnotationTitle such as… | |
| Analizada | Alta (7.5) | 0.49% | — | Linuxfoundation Oras | 17/7/2026 | 26/8/2026 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST request for the subsequent PUT request,… | |
| Aplazada | Baja (2.1) | 0.26% | — | Oras-goAI | 17/7/2026 | 23/7/2026 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's WWW-Authenticate: Bearer challenge without validating the scheme or host, allowing a malicious or compromised registry to cause SSRF to internal networks such as http://169.254.169.254/,… | |
| Aplazada | Media (5.3) | 0.37% | — | Kasuganosoras PigeonAI | 19/2/2025 | 17/6/2026 | A vulnerability was found in kasuganosoras Pigeon 1.0.177. It has been declared as critical. This vulnerability affects unknown code of the file /pigeon/imgproxy/index.php. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. Upgrading to version 1.0.181 is… | |
| Aplazada | Media (6.4) | 0.78% | — | Control HorasAI | 22/11/2024 | 17/6/2026 | The Control horas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ch_registro' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Alta (7.7) | 1.4% | — | Deislabs Oras | 25/1/2021 | 17/6/2026 | ORAS is open source software which enables a way to push OCI Artifacts to OCI Conformant registries. ORAS is both a CLI for initial testing and a Go Module. In ORAS from version 0.4.0 and before version 0.9.0, there is a "zip-slip" vulnerability. The directory support feature allows the downloaded gzipped tarballs to… | |
| Modificada | Alta (7.5) | 5.2% | — | Uclouvain OpenjpegFedoraproject FedoraDebian LinuxRedhat Enterprise Linux+8 | 13/1/2020 | 22/9/2026 | OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation. | |
| Modificada | Media (5.5) | 1.7% | — | Uclouvain OpenjpegDebian LinuxCanonical Ubuntu LinuxOracle Georaster | 4/2/2018 | 17/6/2026 | In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. | |
| Modificada | Media (4.3) | 1.1% | — | Denorastats Phpdenora | 10/3/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in phpDenora before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via an IRC channel name. NOTE: some of these details are obtained from third party information. |