Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2573▼ 324 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 435 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)——Sciphi-ai R2RAI4/10/20264/10/2026
A vulnerability was identified in SciPhi-AI R2R up to 3.6.6. This vulnerability affects unknown code of the file py/shared/abstractions/llm.py of the component Retrieval Completion API Endpoint. Such manipulation of the argument generation_config.api_base leads to server-side request forgery. The attack can be…
AplazadaMedia (5.5)——Sciphi-ai R2RAI4/10/20264/10/2026
A vulnerability was determined in SciPhi-AI R2R up to 3.6.6. This affects an unknown part of the component JWT Secret Handler. This manipulation of the argument DEFAULT_BCRYPT_SECRET_KEY/DEFAULT_NACL_SECRET_KEY causes hard-coded credentials. The attack can be initiated remotely. The exploit has been publicly disclosed…
AplazadaMedia (4.8)0.19%—Scipopt ScipAI28/4/202517/6/2026
A vulnerability has been found in scipopt scip up to 9.2.1 and classified as problematic. Affected by this vulnerability is the function main of the file examples/LOP/src/genRandomLOPInstance.c of the component File Descriptor Handler. The manipulation of the argument File leads to uncontrolled file descriptor…
ModificadaCrítica (9.8)0.53%—Gmbilisim Multi-disciplinary Design Optimization29/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GM Information Technologies MDO allows SQL Injection. This issue affects MDO: through 20231229. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
ModificadaCrítica (9.8)1.3%—Scipy6/7/202317/6/2026
A use-after-free issue was discovered in Py_FindObjects() function in SciPy versions prior to 1.8.0. NOTE: the vendor and discoverer indicate that this is not a security issue.
ModificadaMedia (5.5)0.38%—Scipy5/7/202317/6/2026
A refcounting issue which leads to potential memory leak was discovered in scipy commit 8627df31ab in Py_FindObjects() function. Note: This is disputed as a bug and not a vulnerability. SciPy is not designed to be exposed to untrusted users or data directly.
ModificadaCrítica (9.8)2.1%—Amazon AWS SDK FOR JavasciptAmazon AWS Shared Configuration File Loader19/1/202117/6/2026
This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0. If an attacker submits a malicious INI file to an application that parses it with loadSharedConfigFiles , they will pollute the prototype on the application. This can be exploited further depending on the…
ModificadaAlta (7.8)0.43%—ScipyFedoraproject FedoraRedhat Enterprise LinuxDebian Linux4/11/201916/6/2026
The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories.
ModificadaAlta (7.5)2.7%—Scipter.ch Gastebuch27/2/200716/6/2026
PHP remote file inclusion vulnerability in sinagb.php in Sinapis Gastebuch 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the fuss parameter.