Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
88 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.76% | — | Plone APP DexterityAIPlone APP ContenttypesAI | 22/9/2026 | 25/9/2026 | plone.app.dexterity is a content-type system for the Plone content management system, and plone.app.contenttypes provides Plone’s Dexterity-based content types. Plone.app.dexterity versions through 3.2.2, 4.0.0 through 4.1.2, and 5.0.0, and plone.app.contenttypes versions through 3.0.11, 4.0.0 through 4.0.9, and 5.0.0… | |
| Aplazada | Media (6.3) | 0.55% | — | Ash-project ASH TypescriptAI | 1/9/2026 | 1/9/2026 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to read internal application data from an HTTP 500 response body. When a typed-controller route handler returns anything other than a %Plug.Conn{}, dispatch/3 in… | |
| Aplazada | Media (6.3) | 0.68% | — | Ash-project ASH TypescriptAI | 1/9/2026 | 1/9/2026 | Improper Input Validation vulnerability in ash-project ash_typescript allows a remote attacker to submit argument values outside a declared allowlist or bound on typed-controller routes. AshTypescript.TypedController.RequestHandler in lib/ash_typescript/typed_controller/request_handler.ex calls Ash.Type.cast_input/3… | |
| Aplazada | Baja (2.3) | 0.50% | — | Ash-project ASH TypescriptAI | 1/9/2026 | 1/9/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ash-project ash_typescript allows an attacker who controls a path-parameter value to redirect a generated client's request, and the credentials attached to it, to an unintended route or an external origin. The URL builders in… | |
| Aplazada | Alta (8.2) | 0.50% | — | Ash-project ASH TypescriptAI | 1/9/2026 | 1/9/2026 | Incorrect Authorization vulnerability in ash-project ash_typescript allows an unauthorized RPC caller to read attribute values that Ash field policies denied. When a field policy denies an attribute, Ash substitutes %Ash.ForbiddenField{}, which retains the real value in original_value because embedded resources must… | |
| Aplazada | Media (6.3) | 0.55% | — | Ash-project ASH TypescriptAI | 1/9/2026 | 1/9/2026 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to receive unredacted internal error data by provoking an error shape the configured error handler does not match. apply_error_handler/3 in lib/ash_typescript/rpc/errors.ex is the… | |
| Aplazada | Alta (8.2) | 0.55% | — | Ash-project ASH TypescriptAI | 1/9/2026 | 1/9/2026 | Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort the node via client-supplied typed struct field names. resolve_typed_struct_field/2 in lib/ash_typescript/rpc/field_processing/field_selector.ex… | |
| Aplazada | Alta (8.7) | 0.55% | — | Ash-project ASH TypescriptAI | 1/9/2026 | 1/9/2026 | Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort the node via client-supplied RPC field names. AshTypescript.FieldFormatter.convert_to_field_atom/2 in lib/ash_typescript/field_formatter.ex… | |
| Aplazada | Alta (8.3) | 0.48% | — | Swagger-typescript-apiAI | 29/7/2026 | 30/7/2026 | swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-routes/schema-routes.ts passes OpenAPI path keys through parseRouteName to templates/default/procedure-call.ejs and templates/modular/procedure-call.ejs without escaping JavaScript template… | |
| Aplazada | Alta (8.3) | 0.48% | — | Swagger-typescript-apiAI | 29/7/2026 | 30/7/2026 | swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-parser/base-schema-parsers/enum.ts passes components.schemas.*.enum[i] values to Ts.StringValue in src/configuration.ts without escaping before templates/base/enum-data-contract.ejs renders… | |
| Aplazada | Media (6.1) | 0.32% | — | Swagger-typescript-api Swagger Typescript APIAI | 29/7/2026 | 30/7/2026 | swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts warmUpRemoteSchemasCache resolves external $ref URLs and fetchRemoteSchemaDocument uses isHttpUrl to fetch any http or https target without private IP, redirect, DNS rebinding,… | |
| Aplazada | Alta (8.3) | 0.48% | — | Swagger-typescript-apiAI | 29/7/2026 | 30/7/2026 | swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-gen-process.ts createApiConfig copies servers[0].url into apiConfig.baseUrl, and templates/base/http-clients/fetch-http-client.ejs interpolates apiConfig.baseUrl into the generated HttpClient baseUrl… | |
| Aplazada | Alta (8.3) | 0.48% | — | Swagger-typescript-apiAI | 29/7/2026 | 30/7/2026 | swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templates/base/http-clients/axios-http-client.ejs interpolates servers[0].url from src/code-gen-process.ts into the HttpClient constructor without escaping, allowing an attacker-controlled OpenAPI spec to… | |
| Aplazada | Alta (7.4) | 0.44% | — | Swagger-typescript-api Swagger Typescript APIAI | 29/7/2026 | 30/7/2026 | swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts getRemoteRequestHeaders forwards --authorizationToken to every URL fetched by fetchRemoteSchemaDocument while warmUpRemoteSchemasCache resolves external $ref URLs, allowing an… | |
| Aplazada | Media (6.9) | 0.20% | — | RattlerAIRattler Conda TypesAIConda PixiAIConda MambaAI+1 | 21/7/2026 | 23/7/2026 | Rattler is a library that provides common functionality used within the conda ecosystem. Prior to version 0.43.2, `EntryPoint::FromStr` in `rattler_conda_types` performs only `.trim()` on the `command` field before the linker joins it onto the install prefix and writes an executable Python script. A malicious… | |
| Aplazada | Media (6) | 0.38% | — | TypesenseAI | 12/6/2026 | 17/6/2026 | Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is a cache isolation issue affecting search requests that use both server-side search result caching and Scoped Search API Keys. Under specific request ordering, cached search results could be reused across requests with different… | |
| Aplazada | Alta (8.7) | 0.54% | — | TypesenseAI | 12/6/2026 | 17/6/2026 | Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is an unauthenticated denial-of-service vulnerability in the /multi_search endpoint. A specially crafted request can trigger an unhandled exception during request processing, causing the server process to terminate. This issue can… | |
| Aplazada | Media (4.7) | 0.20% | — | Utcp HttpAITypescript UtcpAI | 28/5/2026 | 21/7/2026 | typescript-utcp is a typescript implementation of UTCP. Prior to 1.1.2, the @utcp/http package is vulnerable to a blind Server-Side Request Forgery (SSRF) caused by a trust-boundary inconsistency between manual discovery and tool invocation. registerManual() validates the discovery URL against an HTTPS / loopback… | |
| Aplazada | Alta (7.1) | 0.44% | — | Themeisle Disable Comments FOR ANY Post TypesAI | 27/5/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeisle Disable Comments for Any Post Types (Remove comments) comments-plus allows Password Recovery Exploitation.This issue affects Disable Comments for Any Post Types (Remove comments): from n/a through <= 1.3.0. | |
| Aplazada | Media (4.3) | 0.40% | — | Typesquare Webfonts FOR ConahaAI | 20/5/2026 | 23/7/2026 | The TypeSquare Webfonts for ConoHa plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access… | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Analizada | Media (4.8) | 0.13% | — | Anthropic Claude SDK FOR Typescript | 4/5/2026 | 17/6/2026 | Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From version 0.79.0 to before version 0.91.1, the BetaLocalFilesystemMemoryTool in the Anthropic TypeScript SDK created memory files and directories using the Node.js default modes (0o666 for files,… | |
| Analizada | Media (6.3) | 0.39% | — | Anthropic Claude SDK FOR Typescript | 31/3/2026 | 24/7/2026 | Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From version 0.79.0 to before version 0.81.0, the local filesystem memory tool in the Anthropic TypeScript SDK validated model-supplied paths using a string prefix check that did not append a trailing… | |
| Aplazada | Alta (8.3) | 0.32% | — | Mimetypes Link IconsAI | 21/3/2026 | 17/6/2026 | The MimeTypes Link Icons plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.2.20. This is due to the plugin making outbound HTTP requests to user-controlled URLs without proper validation when the "Show file size" option is enabled. This makes it possible for… | |
| Aplazada | Media (5.4) | 0.30% | — | BSV Blockchain Typescript SDKAI | 18/2/2026 | 17/6/2026 | The BSV Blockchain SDK is a unified TypeScript SDK for developing scalable apps on the BSV Blockchain. Prior to version 2.0.0, a cryptographic vulnerability in the TypeScript SDK's BRC-104 authentication implementation caused incorrect signature data preparation, resulting in signature incompatibility between SDK… |