Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3038▲ 464 respecto a la semana anterior
Críticas / altas1416▲ 190 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)387▲ 170 respecto a la semana anterior
110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.4) | 0.47% | — | Raspap WebguiAI | 29/9/2026 | 29/9/2026 | A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::addSudoers of the file src/RaspAP/Plugins/PluginInstaller.php of the component sudo Configuration. Performing a manipulation results in improper privilege management. The attack may be initiated… | |
| Aplazada | Baja (2) | 2.1% | — | Raspap WebguiAI | 29/9/2026 | 29/9/2026 | A flaw has been found in RaspAP raspap-webgui up to 3.5.5. Affected is the function WiFiManager::writeWpaSupplicant of the file src/RaspAP/Networking/Hotspot/WiFiManager.php of the component SSID Processing. This manipulation of the argument ssid causes os command injection. The attack can be initiated remotely. The… | |
| Aplazada | Baja (2.1) | 1.6% | — | Raspap WebguiAI | 29/9/2026 | 1/10/2026 | A vulnerability has been found in RaspAP raspap-webgui up to 3.5.5. Affected by this vulnerability is the function escapeshellcmd of the file ajax/openvpn/del_ovpncfg.php of the component OpenVPN Configuration Handler. Such manipulation of the argument cfg_id leads to os command injection. The attack can be launched… | |
| Aplazada | Media (5.5) | 1.4% | — | Marcopiovanello Yt-dlp-web-uiAI | 18/9/2026 | 22/9/2026 | A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function NewGenericDownload of the file server/internal/downloaders/generic.go. Such manipulation of the argument params leads to command injection. It is possible to launch the attack remotely. The exploit has… | |
| Aplazada | Media (6.8) | 0.07% | — | Browser-use Web-uiAI | 30/8/2026 | 10/9/2026 | browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or access restrictions. Attackers with read access to the temporary settings directory can recover provider API keys from predictably-named JSON files. | |
| Aplazada | Media (6.9) | 0.41% | — | Browser-use Web-uiAI | 30/8/2026 | 2/9/2026 | browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing attackers to create directories at arbitrary locations by supplying absolute paths to save_recording_path, save_trace_path, save_agent_history_path, or save_download_path parameters. Attackers can… | |
| Analizada | Alta (7.2) | 0.68% | — | Get-hermes Hermes WEB UI | 21/4/2026 | 17/6/2026 | Hermes WebUI contains an arbitrary file deletion vulnerability in the /api/session/delete endpoint that allows authenticated attackers to delete files outside the session directory by supplying an absolute path or path traversal payload in the session_id parameter. Attackers can exploit unvalidated session identifiers… | |
| Analizada | Media (5.3) | 0.39% | — | Oobabooga Text Generation WEB UI | 7/4/2026 | 17/6/2026 | text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerability in load_prompt() allows reading any .txt file on the server filesystem. The file content is returned verbatim in the API response. This vulnerability is fixed in 4.3. | |
| Analizada | Alta (7.5) | 0.44% | — | Oobabooga Text Generation WEB UI | 7/4/2026 | 17/6/2026 | text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, he superbooga and superboogav2 RAG extensions fetch user-supplied URLs via requests.get() with zero validation — no scheme check, no IP filtering, no hostname allowlist. An attacker can access cloud metadata… | |
| Analizada | Crítica (9.1) | 1.7% | — | Lollms WEB UI | 24/3/2026 | 17/6/2026 | LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side Request Forgery (SSRF) vulnerability has been identified in all known existing versions of `lollms-webui`. The `@router.post("/api/proxy")` endpoint allows unauthenticated attackers to force the… | |
| Aplazada | Alta (8.7) | 1.4% | — | Raspap-webguiAI | 2/2/2026 | 17/6/2026 | RaspAP raspap-webgui versions prior to 3.3.6 contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be executed by a user who can log in to the product. | |
| Aplazada | Media (4.3) | 0.22% | — | SAP Product Designer WEB UIAISAP Business Server PagesAI | 13/1/2026 | 17/6/2026 | SAP Product Designer Web UI of Business Server Pages allows authenticated non-administrative users to access non-sensitive information. This results in a low impact on confidentiality, with no impact on integrity or availability of the application. | |
| Aplazada | Media (4.3) | 0.21% | — | Webbuilder143 Sticky Notes FOR WP DashboardAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in Web Builder 143 Sticky Notes for WP Dashboard wb-sticky-notes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sticky Notes for WP Dashboard: from n/a through <= 1.2.4. | |
| Aplazada | Alta (7.2) | 0.38% | — | 10webbuilder 10webmapbuilderAI | 18/10/2025 | 17/6/2026 | The 10WebMapBuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Plugin Settings Change in versions up to, and including, 1.0.63 due to insufficient input sanitization and output escaping and a lack of capability checks. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Media (6.1) | 0.21% | — | Radware Alteonos WEB UI ManagementAI | 1/10/2025 | 17/6/2026 | An authenticated cross-site scripting (XSS) vulnerability in the Administrative interface of Radware AlteonOS Web UI Management v33.0.4.50 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Description parameter. | |
| Analizada | Crítica (9.8) | 1.6% | — | Raspap-webgui | 27/8/2025 | 17/6/2026 | In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. The vulnerability is due to improper sanitizing of user input passed via the interface parameter. | |
| Aplazada | Crítica (9.8) | 0.52% | — | Egware Egos WebguiAI | 26/8/2025 | 17/6/2026 | The JWT secret key is embedded in the egOS WebGUI backend and is readable to the default user. An unauthenticated remote attacker can generate valid HS256 tokens and bypass authentication/authorization due to the use of hard-coded cryptographic key. | |
| Analizada | Media (6.3) | 0.60% | — | Raspap-webgui | 27/6/2025 | 17/6/2026 | RaspAP raspap-webgui 3.3.1 is vulnerable to Directory Traversal in ajax/networking/get_wgkey.php. An authenticated attacker can send a crafted POST request with a path traversal payload in the `entity` parameter to overwrite arbitrary files writable by the web server via abuse of the `tee` command used in shell… | |
| Modificada | Alta (7.5) | 0.63% | — | Lollms WEB UI | 20/3/2025 | 17/6/2026 | A vulnerability in parisneo/lollms-webui v13 arises from the server's handling of multipart boundaries in file uploads. The server does not limit or validate the length of the boundary or the characters appended to it, allowing an attacker to craft requests with excessively long boundaries, leading to resource… | |
| Analizada | Alta (8.8) | 1.4% | — | Lollms WEB UI | 20/3/2025 | 17/6/2026 | In version v12 of parisneo/lollms-webui, the 'Send file to AL' function allows uploading files with various extensions, including potentially dangerous ones like .py, .sh, .bat, and more. Attackers can exploit this by uploading files with malicious content and then using the '/open_file' API endpoint to execute these… | |
| Modificada | Alta (8.4) | 0.31% | — | Lollms WEB UI | 20/3/2025 | 17/6/2026 | A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauthorized directory deletions. The /uninstall/{app_name} API endpoint does not call the check_access() function to verify the client_id, enabling attackers to delete directories without proper… | |
| Analizada | Crítica (9.8) | 0.80% | — | Lollms WEB UI | 20/3/2025 | 17/6/2026 | A path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V12 (Strawberry). This vulnerability allows attackers to create or delete directories with arbitrary paths on the system. The issue arises due to insufficient sanitization of user-supplied input, which… | |
| Modificada | Media (6.5) | 0.24% | — | Lollms WEB UI | 20/3/2025 | 17/6/2026 | A Denial of Service (DoS) vulnerability exists in multiple file upload endpoints of parisneo/lollms-webui version V12 (Strawberry). The vulnerability can be exploited remotely via Cross-Site Request Forgery (CSRF). Despite CSRF protection preventing file uploads, the application still processes multipart boundaries,… | |
| Modificada | Crítica (9.1) | 0.95% | — | Lollms WEB UI | 20/3/2025 | 17/6/2026 | A vulnerability in the `upload_app` function of parisneo/lollms-webui V12 (Strawberry) allows an attacker to delete any file or directory on the system. The function does not implement user input filtering with the `filename` value, causing a Path Traversal error. | |
| Analizada | Media (4.4) | 0.33% | — | Lollms WEB UI | 20/3/2025 | 17/6/2026 | A vulnerability in the sanitize_path function in parisneo/lollms-webui v10 - latest allows an attacker to bypass path sanitization by using relative paths such as './'. This can lead to unauthorized access to directories within the personality_folder on the victim's computer. |