Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
88 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.3) | — | — | Vercel Next.jsAI | 2/10/2026 | 2/10/2026 | Next.js is a React framework for building full-stack web applications. From 16.3.0 until 16.3.8, pending use cache fills for the same key are shared without separating Draft Mode requests from regular requests. An overlapping regular request can receive unauthenticated unpublished content from an editor's Draft Mode… | |
| Pendiente de análisis | Media (6.3) | — | — | Vercel Next.jsAI | 2/10/2026 | 2/10/2026 | Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated or Incremental Static Regeneration pages can key a response cache entry without sufficiently binding it to the source route. A request… | |
| Pendiente de análisis | Baja (2.3) | — | — | Vercel Next.jsAI | 2/10/2026 | 2/10/2026 | Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the next dev development server exposes a Model Context Protocol endpoint without reliably restricting cross-site requests. A malicious website visited by a developer can reach the endpoint and read the project's disk… | |
| Pendiente de análisis | Media (6.3) | — | — | Vercel Next.jsAI | 2/10/2026 | 2/10/2026 | Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the `next dev` development server exposes a Model Context Protocol endpoint without reliably restricting cross-site requests. A malicious website visited by a developer can reach the endpoint and read the project's disk… | |
| Pendiente de análisis | Media (6.3) | — | — | Vercel Next.jsAI | 2/10/2026 | 2/10/2026 | Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, applications with a root-level catch-all page and statically generated or Incremental Static Regeneration routes can use a shared response cache key that is insufficiently scoped to the source route. A single… | |
| Pendiente de análisis | Alta (8.3) | — | — | Vercel Next.jsAI | 2/10/2026 | 2/10/2026 | Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, Image Optimization can follow attacker-controlled DNS resolution for a remote URL that matches images.remotePatterns, allowing the optimized image fetch to reach private IP addresses after the URL passes the allow-list… | |
| Pendiente de análisis | Media (6.3) | 0.32% | — | Vercel Next.jsAI | 1/10/2026 | 2/10/2026 | Next.js versions from 16.3.0 to 16.3.7 warm `use cache` handlers using `next/root-params` and can leak their return value to pages with different root params. With Cache Components enabled (cacheComponents: true), a 'use cache' function that calls another 'use cache' function that reads a root param can be keyed… | |
| Pendiente de análisis | Media (5.3) | 0.18% | — | Payloadcms Storage-vercel-blobAI | 25/9/2026 | 30/9/2026 | The @payloadcms/storage-vercel-blob storage adapter for Payload contains an improper access control vulnerability that allows authenticated users to bypass collection-level permissions by accessing the client-upload route directly. Attackers can upload files through the client-upload endpoint without possessing the… | |
| Aplazada | Crítica (9) | 2.3% | — | Vercel Next.jsAI | 1/9/2026 | 9/9/2026 | Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently escape backslashes in route segments before constructing incremental-cache paths. In… | |
| Aplazada | Media (6.5) | 0.38% | — | Astro Vercel AdapterAI | 17/8/2026 | 9/9/2026 | Astro is a web framework for content-driven websites. From 10.0.3 until 11.0.3, the Astro Vercel adapter in packages/integrations/vercel/src/serverless/entrypoint.ts accepts x_astro_path for the public /_isr function based only on the x-vercel-isr header, allowing unauthenticated GET requests to render routes… | |
| Analizada | Alta (8.3) | 0.46% | — | Vercel Next.js | 27/7/2026 | 29/7/2026 | Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the… | |
| Analizada | Media (6) | 0.34% | — | Vercel Next.js | 27/7/2026 | 29/7/2026 | Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. Confidential data in the POST's response body… | |
| Analizada | Media (6.3) | 0.32% | — | Vercel Next.js | 27/7/2026 | 29/7/2026 | Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. Confidential data in the POST's response body… | |
| Analizada | Media (6.3) | 0.52% | — | Vercel Next.js | 27/7/2026 | 29/7/2026 | Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge runtime. This… | |
| Analizada | Alta (8.3) | 0.41% | — | Vercel Next.js | 27/7/2026 | 29/7/2026 | Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's hostname… | |
| Analizada | Media (6.3) | 0.67% | — | Vercel Next.js | 27/7/2026 | 29/7/2026 | Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 through 16.2.10, when self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain… | |
| Analizada | Media (6.3) | 0.51% | — | Vercel Next.js | 27/7/2026 | 29/7/2026 | Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, Next.js applications using App Router, Server Actions (use server) or use cache endpoints can be disclosed bypassing any authentication on the pages where these endpoints are usually… | |
| Analizada | Alta (8.3) | 0.64% | — | Vercel Next.js | 27/7/2026 | 29/7/2026 | Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router built with Turbopack and a single entry in config.i18n.locales can bypass middleware/proxy based authentication. This issue has been fixed in… | |
| Analizada | Alta (8.2) | 0.86% | — | Vercel Next.js | 27/7/2026 | 29/7/2026 | Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same… | |
| Aplazada | Crítica (10) | 1.4% | — | Vercel Next.jsAICalcom Cal.diyAI | 23/7/2026 | 29/9/2026 | Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attacker can send a crafted RSC request to the server and cause arbitrary code to be… | |
| Analizada | Baja (2.1) | 0.73% | — | Vercel AI | 17/5/2026 | 17/6/2026 | A vulnerability was determined in vercel ai up to 3.0.97. The impacted element is the function createJsonResponseHandler/createJsonErrorResponseHandler of the file packages/provider-utils/src/response-handler.ts of the component provider-utils. This manipulation causes resource consumption. The attack may be initiated… | |
| Analizada | Media (5.5) | 0.69% | — | Vercel AI | 17/5/2026 | 17/6/2026 | A vulnerability was found in vercel ai up to 3.0.97. The affected element is the function validateDownloadUrl of the file packages/provider-utils/src/download-blob.ts of the component provider-utils. The manipulation results in server-side request forgery. The attack can be launched remotely. The exploit has been made… | |
| Analizada | Baja (1.3) | 7.0% | — | Vercel AI | 17/5/2026 | 17/6/2026 | A vulnerability has been found in vercel ai up to 3.0.97. Impacted is the function run of the file .github/workflows/prettier-on-automerge.yml of the component PR Branch Name Interpolation. The manipulation leads to os command injection. The attack can be initiated remotely. The complexity of an attack is rather high.… | |
| Analizada | Alta (8.4) | 0.24% | — | Vercel Turborepo Language Server Protocol | 15/5/2026 | 17/6/2026 | Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14000, the Turborepo LSP VS Code extension could execute shell commands derived from workspace-controlled values. The extension used string-based command execution for Turborepo daemon commands and task runs. A malicious… | |
| Analizada | Media (5.1) | 0.18% | — | Vercel Turborepo | 15/5/2026 | 17/6/2026 | Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14, Turborepo's self-hosted login and SSO browser flows did not validate a CSRF state value on the localhost callback. While the CLI was waiting for authentication, a malicious web page could send a request to the local… |