Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3043▲ 582 respecto a la semana anterior
Críticas / altas1452▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.40% | — | Maalfer PentestifyAI | 19/8/2026 | 1/9/2026 | Incorrect Behavior Order: Validate Before Canonicalize in the report theme CSS sanitizer in maalfer Pentestify 1.2.0 through 2.3.2 allows an authenticated user to force outbound HTTP requests from other users' browsers, disclosing their IP address and User-Agent, via CSS hex escapes that reconstruct the url() function… | |
| Aplazada | Media (5.1) | 0.47% | — | Maalfer PentestifyAI | 13/8/2026 | 1/9/2026 | Cross-site Scripting in the Markdown renderer in maalfer Pentestify before 2.3.2 allows authenticated users to execute arbitrary JavaScript in the application origin via a Markdown link whose URL contains a double quote, which closes the anchor's href attribute because the renderer's sanitization step does not escape… | |
| Aplazada | Media (5.1) | 0.47% | — | Maalfer PentestifyAI | 13/8/2026 | 1/9/2026 | Stored Cross-site Scripting (CWE-79) in the user management component in maalfer Pentestify before 1.1.1 allows an authenticated attacker to execute arbitrary JavaScript in the browser of another authenticated user via a crafted username, because the frontend escapes the username with escapeHTML() before interpolating… | |
| Aplazada | Media (5.1) | 0.47% | — | Maalfer PentestifyAI | 11/8/2026 | 1/9/2026 | Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute arbitrary JavaScript in the application origin via HTML markup stored in a finding's severity field, which the frontend interpolates unescaped into class and style attributes when rendering the report. | |
| Aplazada | Media (5.3) | 0.45% | — | Maalfer PentestifyAI | 31/7/2026 | 1/9/2026 | Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to cause outbound HTTP GET requests from the server to arbitrary attacker-chosen destinations via unvalidated URLs stored in the finding images field or the report client_logo field, which the… | |
| Pendiente de análisis | Media (6.9) | 0.56% | — | Maalfer PentestifyAI | 20/7/2026 | 23/7/2026 | Stored Cross-site Scripting (CWE-79) in the client-side report rendering functions (renderPreview, renderEditor, renderAuditData in js/app.js) in maalfer Pentestify before 1.1.0 allows a remote, authenticated attacker to execute arbitrary JavaScript in the browser of any user who views an affected report via a payload… | |
| Aplazada | Media (6.9) | 0.49% | — | Ccyl13 PentestifyAI | 24/6/2026 | 25/6/2026 | Server-Side Request Forgery (SSRF) (CWE-918) in the PDF generation endpoint GET /api/reports/{id}/pdf (backend/main.py) in ccyl13 Pentestify 1.0.0 and lower allows remote attackers to make the server issue requests to arbitrary internal or external URLs, including cloud metadata services, and return the rendered… |