Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2622▼ 226 respecto a la semana anterior
Críticas / altas1383▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

144 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.23%—ClaraverseAI29/9/202630/9/2026
ClaraVerse through 0.3.1 contains server-side request forgery protection bypasses in the download_file and scrape_web agent tools. Authenticated users can bypass hostname validation and IPv6 transition address filtering to make the server request internal services and cloud instance metadata endpoints.
AplazadaMedia (6.4)0.19%—Jegstudio GutenverseAI25/9/202625/9/2026
The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Comment Block 'suffixMain' Attribute in all versions up to, and including, 4.0.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AnalizadaAlta (8.1)0.37%—Microsoft Dataverse17/9/202625/9/2026
Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.
Pendiente de análisisAlta (7.5)0.16%—IBM Security Verify Identity Access Reverse ProxyAI15/9/202616/9/2026
IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.
AplazadaAlta (8.8)0.51%—Jegstudio Gutenverse NewsAI11/9/202611/9/2026
The Gutenverse News WordPress plugin before 3.3.3 does not restrict the extra HTML it adds to WordPress's allowed elements to the context it is meant for, applying the same relaxed list to every sanitisation context including untrusted comments, allowing unauthenticated users to store JavaScript that will execute in…
AplazadaCrítica (9.3)0.85%—TouluniverseAIPythonAI27/8/202623/9/2026
ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication. The executor behind the python_code_executor tool, in python_executor_tool.py, inspected the submitted source for a denied list of attribute names and calls but left the attribute-lookup…
AplazadaMedia (6.4)0.35%—Gutenverse Ultimate Wordpress FSE Blocks Addons EcosystemAI26/8/202626/8/2026
The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the multiple blocks in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.4)0.19%—Jegstudio GutenverseAI25/8/202626/8/2026
The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'titleTag' Block Attribute in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (5.3)0.42%—Reverse ProxyAI23/8/202626/8/2026
Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unencoded to the upstream request line. PSGI hands PATH_INFO to an application percent-decoded, so a %XX sequence in the client URL has become a raw byte by the time the proxy sees it. The proxy appends…
AplazadaAlta (7.2)0.27%—Gutenverse CompanionAI13/8/202614/8/2026
Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions.
AplazadaMedia (5.3)0.26%—OverseerrAI23/7/202623/7/2026
Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscription API that allows authenticated users to list, read, and delete any other user's push subscriptions by supplying an arbitrary userId in the path parameters. Attackers can exploit the missing…
AplazadaMedia (6.5)0.36%—Universe Software Computer Marketing Trade AND Industry INC Online Registration AND Workflow Management SystemAI22/7/20265/8/2026
Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industry Inc. Online Registration and Workflow Management System allows Exploiting Trust in Client. This issue affects Online Registration and Workflow Management System: through 12022026.
AplazadaMedia (5.3)0.31%—Fediverse EmbedsAI9/7/20269/7/2026
The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated site-info endpoint before fetching it, allowing anonymous users (the gating nonce is exposed on public pages carrying an embed) to make the site request internal and…
AplazadaMedia (5.3)0.31%—Fediverse EmbedsAI9/7/20269/7/2026
The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated media-proxying endpoint, allowing anonymous users to make the site fetch arbitrary URLs, including internal and private-network addresses, and read back the response body.…
AplazadaMedia (4.4)0.40%—Jegstudio GutenverseAI27/6/202629/6/2026
The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaAlta (7.1)0.25%—Gutenverse FormAI26/6/202626/6/2026
Unauthenticated Cross Site Scripting (XSS) in Gutenverse Form <= 2.4.7 versions.
AplazadaAlta (7.5)0.35%—Gutenverse CompanionAI26/6/202626/6/2026
Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions.
AplazadaMedia (6.3)0.16%—HCL VerseAICompose-rich-editorAI19/6/202622/6/2026
The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input thereby allowing malicious content to be executed in certain situations.
AplazadaMedia (5.3)0.40%—Fediverse EmbedsAI11/6/202617/6/2026
Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.9, Fediverse Embeds registered the unauthenticated AJAX action wp_ajax_nopriv_ftf_get_site_info (includes/Site_Info.php) that verified a nonce ftf-fediverse-embeds-nonce and then called file_get_html($site_url) on the attacker-supplied…
AplazadaAlta (7.5)0.41%—Fediverse EmbedsAI11/6/202617/6/2026
Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.8, Fediverse Embeds registered an unauthenticated REST route ftf/media-proxy (includes/Media_Proxy.php) with permission_callback => __return_true that accepted a base64-encoded URL and forwarded it to wp_remote_get($url) without enforcing…
Pendiente de análisisCrítica (9.1)0.54%—ARM C1-ultraAIARM C1-premiumAIARM Neoverse V3AIARM Neoverse V3aeAI+179/6/20264/9/2026
Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher exception level.
AplazadaMedia (6.1)0.64%—Jegstudio GutenverseAI27/5/202617/6/2026
The Gutenverse plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 3.4.6 due to insufficient input sanitization and output escaping. Specifically, the `render_content()` method in `class-search-result-title.php` outputs the value of…
AplazadaCrítica (9.3)0.41%—LumiverseAI26/5/202624/7/2026
Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the component override system transpiles user-supplied TSX via Sucrase and evaluates it with new Function, shadowing dangerous globals (fetch, window, eval, etc.) with undefined. A static source validator (validateComponentOverrideSource) additionally…
AplazadaCrítica (9.9)0.68%—LumiverseAI26/5/202624/7/2026
Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the MCP server creation endpoint validates the command field against an allowlist of binary names but forwards the args array to the child process without any validation. Every binary on the allowlist accepts an inline-code execution flag (-e for…
AplazadaCrítica (9.1)0.86%—LumiverseAI26/5/202624/7/2026
Lumiverse is a full-featured AI chat application. Prior to 0.9.7, when the primary toSmbPath(fullPath) call throws, the method falls back to a dirname/basename split and only validates the directory prefix. The basename is concatenated directly into the smbclient -c script without validation. smbclient interprets ; as…