Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1734 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 1.6% | ⚠ Explotación activa | Mikrotik Routeros | 5/9/2026 | 11/9/2026 | RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted… | |
| Analizada | Media (6.9) | 1.0% | ⚠ Explotación activa💥 PoC | Mikrotik Routeros | 5/9/2026 | 26/9/2026 | RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and… | |
| Analizada | Alta (8.8) | 49% | ⚠ Explotación activa💥 PoC | Google ChromeGoogle V8 | 3/9/2026 | 21/9/2026 | Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Crítica (10) | 8.8% | ⚠ Explotación activa💥 Exploit | Sonicwall Sma8200vSonicwall Sma6210 FirmwareSonicwall Sma7210 Firmware | 1/9/2026 | 3/9/2026 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations. | |
| Analizada | Alta (7.8) | 11% | ⚠ Explotación activa💥 Exploit | Sonicwall Sma8200vSonicwall Sma6210 FirmwareSonicwall Sma7210 Firmware | 1/9/2026 | 21/9/2026 | Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary… | |
| Analizada | Crítica (9.8) | 14% | ⚠ Explotación activa💥 Exploit | Jfrog Artifactory | 28/8/2026 | 3/9/2026 | JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges. | |
| Analizada | Crítica (9.4) | 61% | ⚠ Explotación activa💥 Exploit | Papercut MFPapercut NG | 28/8/2026 | 14/9/2026 | An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system… | |
| Analizada | Alta (8.8) | 85% | ⚠ Explotación activa💥 Exploit | Papercut MFPapercut NG | 28/8/2026 | 14/9/2026 | An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated… | |
| Analizada | Crítica (9.8) | 24% | ⚠ Explotación activa💥 Exploit | Gitea | 26/8/2026 | 27/8/2026 | Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. | |
| Analizada | Crítica (9.5) | 1.7% | ⚠ Explotación activa💥 PoC | Trueconf Server | 19/8/2026 | 21/8/2026 | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system. | |
| Analizada | Crítica (9.3) | 1.5% | ⚠ Explotación activa | Trueconf Server | 19/8/2026 | 21/8/2026 | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function. | |
| Analizada | Crítica (9.3) | 23% | ⚠ Explotación activa💥 PoC | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 19/8/2026 | 10/9/2026 | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21. | |
| Analizada | Crítica (9.3) | 9.8% | ⚠ Explotación activa💥 Exploit | Lfprojects Mlflow | 17/8/2026 | 5/10/2026 | MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Starting in 3.3.0 and prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while… | |
| Analizada | Alta (8.9) | 72% | ⚠ Explotación activa💥 Exploit | Synacor Zimbra Collaboration Suite | 13/8/2026 | 24/8/2026 | A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted… | |
| Analizada | Alta (7.5) | 9.8% | ⚠ Explotación activa💥 Exploit | Jfrog Artifactory | 12/8/2026 | 1/10/2026 | JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. | |
| Analizada | Media (5.3) | 0.66% | ⚠ Explotación activa💥 PoC | Jfrog Artifactory | 12/8/2026 | 28/8/2026 | An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions. | |
| Analizada | Alta (7) | 0.33% | ⚠ Explotación activa💥 PoC | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 11/8/2026 | 16/8/2026 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.6) | 1.0% | ⚠ Explotación activa | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 11/8/2026 | 16/9/2026 | This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload,… | |
| Analizada | Crítica (9.1) | 88% | ⚠ Explotación activa💥 Exploit | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/8/2026 | 25/9/2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction. | |
| Analizada | Alta (8.8) | 2.1% | ⚠ Explotación activa💥 PoC | Microsoft Sharepoint Server | 11/8/2026 | 26/9/2026 | Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Crítica (10) | 19% | ⚠ Explotación activa💥 Exploit | Metabase | 10/8/2026 | 12/8/2026 | Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance. | |
| Analizada | Crítica (9.8) | 1.7% | ⚠ Explotación activa💥 PoC | Apple Macos | 6/8/2026 | 15/9/2026 | An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials. | |
| Analizada | Crítica (10) | 0.59% | ⚠ Explotación activa💥 PoC | Wso2 API Control PlaneWso2 API ManagerWso2 Traffic ManagerWso2 Universal Gateway | 6/8/2026 | 25/9/2026 | The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result… | |
| Analizada | Alta (8.2) | 15% | ⚠ Explotación activa💥 Exploit | N-able N-central | 2/8/2026 | 4/8/2026 | An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 | |
| Analizada | Alta (8.2) | 7.9% | ⚠ Explotación activa💥 PoC | N-able N-central | 1/8/2026 | 5/8/2026 | Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1. |