Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.28% | — | Songxinjianqwe ChatAI | 24/9/2026 | 25/9/2026 | A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4ba7e88d3b7a032637150d. Affected by this issue is some unknown functionality of the file chat-server/src/main/java/cn/sinjinsong/chat/server/ChatServer.java of the component chat-server. This manipulation causes server-side request forgery.… | |
| Aplazada | Media (5.6) | 0.24% | — | Tauri Http PluginAIReqwestAI | 22/9/2026 | 22/9/2026 | The Tauri HTTP plugin validates requested URLs against the application's configured scope allowlist only once, on the initial request. When the remote server responds with an HTTP 3xx redirect, reqwest follows the redirect internally without re-checking the new target URL against the scope. This allows an attacker who… | |
| Aplazada | Alta (8.7) | 0.46% | — | Qwen-agentAIGradioAI | 28/8/2026 | 23/9/2026 | Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the document parser that fails to restrict file access to intended directories. Attackers can supply absolute file paths to the unauthenticated Gradio interface to read arbitrary files accessible by the server process. | |
| Aplazada | Alta (8.7) | 0.35% | — | Alibaba Qwen-agentAIGradioAI | 28/8/2026 | 23/9/2026 | Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats caller-supplied paths as URLs without scheme restriction or host validation. Attackers can reach the unauthenticated Gradio interface to make the server issue HTTP requests to arbitrary internal… | |
| Aplazada | Alta (8.8) | 0.78% | — | QwedAI | 25/8/2026 | 9/9/2026 | QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, tool calls, code, schemas, and agent state before production execution. Prior to 5.1.2, the qwed package passes caller-controlled math expressions directly to SymPy parse_expr() without restricted global_dict and… | |
| Aplazada | Crítica (9.8) | 0.73% | — | Qwed MCPAISympyAI | 25/8/2026 | 9/9/2026 | QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2.1, verify_math_expression() in src/qwed_mcp/engines/math_engine.py passes attacker-controlled expression and claimed_result strings directly to SymPy's parse_expr() after only normalizing caret syntax to Python exponent syntax, without restricting… | |
| Pendiente de análisis | Alta (7.1) | 0.46% | — | Huggingface TransformersAIHuggingface IdeficsAIHuggingface FlorenceAIHuggingface GemmaAI+2 | 2/8/2026 | 3/9/2026 | A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMixin`, where keys from the `chat_template` dictionary are used directly as filenames… | |
| Aplazada | Media (5.1) | 0.34% | — | QWE DLAI | 1/2/2026 | 17/6/2026 | QWE DL 2.0.1 mobile web application contains a persistent input validation vulnerability allowing remote attackers to inject malicious script code through path parameter manipulation. Attackers can exploit the vulnerability to execute persistent cross-site scripting attacks, potentially leading to session hijacking… | |
| Analizada | Crítica (9.1) | 0.24% | — | Qwer Crypt\ | 30/9/2025 | 17/6/2026 | Crypt::RandomEncryption for Perl version 0.01 uses insecure rand() function during encryption. | |
| Modificada | Media (5.4) | 0.42% | — | Asdqwedev Ajax Domain Checker | 22/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Asdqwe Dev Ajax Domain Checker plugin <= 1.3.0 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Qwerty23 Rocket Font | 21/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Qwerty23 Rocket Font plugin <= 1.2.3 versions. | |
| Modificada | Alta (10) | 1.4% | — | Goforandroid GO Qqweibowidget | 7/3/2012 | 16/6/2026 | Unspecified vulnerability in the GO QQWeiboWidget (com.gau.go.launcherex.gowidget.qqweibowidget) application 1.2 for Android has unknown impact and attack vectors. | |
| Modificada | Media (4.3) | 2.2% | — | Inter7 Sqwebmail | 7/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows remote attackers to inject arbitrary web script or HTML via an e-mail message containing Internet Explorer "Conditional Comments" such as "[if]" and "[endif]". | |
| Modificada | Media (4.3) | 2.7% | — | Inter7 Sqwebmail | 2/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 and possibly other versions allows remote attackers to inject arbitrary web script or HTML via an HTML e-mail containing tags with strings that contain ">" or other special characters, which is not properly sanitized by SqWebMail. | |
| Modificada | Media (4.3) | 1.8% | — | Inter7 Sqwebmail | 30/8/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows remote attackers to inject arbitrary web script or HTML via a file attachment that is processed by the Display feature. NOTE: the severity of this issue has been disputed by the developer. | |
| Modificada | Alta (7.5) | 2.3% | — | Inter7 Sqwebmail | 15/4/2005 | 16/6/2026 | SqWebMail allows remote attackers to inject arbitrary web script or HTML via CRLF sequences in the redirect parameter followed by the desired script or HTML. | |
| Modificada | Media (5) | 1.6% | — | Inter7 Sqwebmail | 31/12/2004 | 16/6/2026 | Inter7 SqWebMail 3.4.1 through 3.6.1 generates different error messages for incorrect passwords versus correct passwords on non-mail-enabled accounts (such as root), which allows remote attackers to guess the root password via brute force attacks. | |
| Modificada | Media (6.8) | 5.0% | — | Inter7 Sqwebmail | 6/8/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the print_header_uc function for SqWebMail 4.0.4 and earlier, and possibly 3.x, allows remote attackers to inject arbitrary web script or HRML via (1) e-mail headers or (2) a message with a "message/delivery-status" MIME Content-Type. | |
| Modificada | Alta (7.5) | 3.3% | — | Double Precision Incorporated Courier MTADouble Precision Incorporated SqwebmailInter7 Courier-imapGentoo Linux | 15/4/2004 | 16/6/2026 | Multiple buffer overflows in (1) iso2022jp.c or (2) shiftjis.c for Courier-IMAP before 3.0.0, Courier before 0.45, and SqWebMail before 4.0.0 may allow remote attackers to execute arbitrary code "when Unicode character is out of BMP range." |