Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2744▼ 71 respecto a la semana anterior
Críticas / altas1416▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)106▼ 394 respecto a la semana anterior
90 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.39% | — | Modsetter SurfsenseAI | 29/9/2026 | 1/10/2026 | A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknown function of the file surfsense_backend/app/routes/circleback_webhook_route.py of the component circleback Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The… | |
| Aplazada | Baja (2.1) | 0.23% | — | Modsetter SurfsenseAI | 29/9/2026 | 29/9/2026 | A security flaw has been discovered in MODSetter SurfSense up to 0.0.36. Impacted is an unknown function of the file surfsense_backend/app/routes/editor_routes.py of the component Document Export Feature. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The… | |
| Aplazada | Baja (2.1) | 1.2% | — | Modsetter SurfsenseAI | 29/9/2026 | 29/9/2026 | A vulnerability was identified in MODSetter SurfSense up to 2.0.3. This issue affects some unknown processing of the file /api/search-source/connectors/mcp/test of the component MCP Connector Integration. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit is… | |
| Aplazada | Crítica (9.8) | 0.74% | — | SurfioAI | 15/9/2026 | 30/9/2026 | Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fields in IRAP files, leading to a buffer overflow when untrusted files are parsed. The severity assumes surfio is used to parse untrusted files in a networking context such as a web service. This issue… | |
| Aplazada | Media (6.7) | 0.11% | — | Android SurfaceflingerAI | 7/9/2026 | 8/9/2026 | In SurfaceFlinger, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11123860; Issue ID: MSV-8890. | |
| Aplazada | Baja (1.9) | 0.17% | — | Incomestreamsurfer ROO Code Memory Bank MCP ServerAI | 9/8/2026 | 14/8/2026 | A security vulnerability has been detected in IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35ac1983885a6d4e5621a0081e. This affects the function readMemoryBankFile/appendMemoryBankEntry of the file src/index.ts of the component read_memory_bank_file/append_memory_bank_entry. Such manipulation… | |
| Aplazada | Media (5.5) | 0.52% | — | Vibesurf-ai VibesurfAI | 4/8/2026 | 12/8/2026 | A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an unknown function of the file /code of the component Python Validation Handler. The manipulation leads to code injection. Remote exploitation of the attack is possible. This product follows a rolling… | |
| Analizada | Alta (8.8) | 0.96% | — | Microsoft Surface Management Services | 24/7/2026 | 6/8/2026 | Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.30% | — | Microsoft Surface GO 2 1901 FirmwareMicrosoft Surface GO 2 1926 FirmwareMicrosoft Surface GO 2 1927 FirmwareMicrosoft Surface GO 3 1901 Firmware+23 | 14/7/2026 | 24/7/2026 | Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Media (4.3) | 0.37% | — | SurflinkAI | 11/7/2026 | 13/7/2026 | The SurfLink - Ultimate Link Manager plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the ajax_import_410() function in all versions up to 2.6.0. This is due to a missing capability check (current_user_can()) and missing nonce verification (check_ajax_referer())… | |
| Aplazada | Alta (8) | 0.33% | — | Codeium WindsurfAI | 15/4/2026 | 17/6/2026 | A prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim system. When Windsurf processes attacker-controlled HTML content, malicious instructions can cause unauthorized modification of the local MCP configuration and automatic registration of a malicious… | |
| Analizada | Alta (8.6) | 0.24% | — | Surf Pinfo | 28/3/2026 | 17/6/2026 | PInfo 0.6.9-5.1 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized argument to the -m parameter. Attackers can craft a malicious input string with 564 bytes of padding followed by a return address to overwrite the instruction pointer and… | |
| Aplazada | Media (6.7) | 0.33% | — | Surfoffline ProfessionalAI | 12/2/2026 | 17/6/2026 | SurfOffline Professional 2.2.0.103 contains a structured exception handler (SEH) overflow vulnerability that allows attackers to crash the application by manipulating the project name input. Attackers can generate a malicious payload of 382 'A' characters followed by specific byte sequences to trigger a denial of… | |
| Aplazada | Media (6.4) | 0.25% | — | Wavesurfer WPAI | 6/2/2026 | 17/6/2026 | The WaveSurfer-WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's audio shortcode in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping on the 'src' attribute. This makes it possible for authenticated attackers, with Contributor-level… | |
| Analizada | Media (6.5) | 0.34% | — | Netsurf-browser Netsurf | 3/11/2025 | 17/6/2026 | An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure. | |
| Analizada | Media (6.5) | 0.30% | — | Netsurf-browser Netsurf | 3/11/2025 | 17/6/2026 | NetSurf 3.11 is vulnerable to Use After Free in dom_node_set_text_content function. | |
| Analizada | Media (6.5) | 0.41% | — | Netsurf-browser Netsurf | 3/11/2025 | 17/6/2026 | An issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize function | |
| Aplazada | Crítica (9.8) | 0.65% | — | Codeium WindsurfAI | 17/10/2025 | 17/6/2026 | A path traversal vulnerability in all versions of the Windsurf IDE enables a threat actor to read and write arbitrary local files in and outside of current projects on an end user’s system. The vulnerability can be reached directly and through indirect prompt injection. | |
| Aplazada | Media (4.6) | 0.19% | — | Codeium WindsurfAI | 14/10/2025 | 17/6/2026 | A prompt injection vulnerability exists in Windsurft version 1.10.7 in Write mode using SWE-1 model. It is possible to create a file name that will be appended to the user prompt causing Windsurf to follow its instructions. | |
| Aplazada | Media (5.3) | 0.27% | — | SurferseoAI | 3/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Surfer Surfer surferseo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Surfer: from n/a through <= 1.6.4.574. | |
| Analizada | Media (6) | 0.23% | — | Nosurf Project Nosurf | 13/5/2025 | 17/6/2026 | nosurf is cross-site request forgery (CSRF) protection middleware for Go. A vulnerability in versions prior to 1.2.0 allows an attacker who controls content on the target site, or on a subdomain of the target site (either via XSS, or otherwise) to bypass CSRF checks and issue requests on user's behalf. Due to misuse… | |
| Analizada | Alta (7.1) | 0.85% | — | Microsoft Surface HUB 2S FirmwareMicrosoft Surface PRO 8 FOR Business 1983 FirmwareMicrosoft Surface Laptop GO FirmwareMicrosoft Surface Laptop GO 2 Firmware+23 | 11/2/2025 | 17/6/2026 | Microsoft Surface Security Feature Bypass Vulnerability | |
| Aplazada | Alta (7.6) | 0.60% | — | SurferseoAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Surfer Surfer surferseo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Surfer: from n/a through <= 1.3.2.357. | |
| Aplazada | Alta (7.6) | 0.42% | — | SurferseoAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Surfer Surfer surferseo allows SQL Injection.This issue affects Surfer: from n/a through <= 1.5.0.502. | |
| Aplazada | Media (6.5) | 0.41% | — | Wpsurface BloglentorAI | 14/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsurface BlogLentor allows Stored XSS.This issue affects BlogLentor: from n/a through 1.0.8. |