Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

1734 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)2.6%⚠ Explotación activa💥 PoCVmware Vcenter Server30/7/202619/8/2026
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
AnalizadaMedia (5.3)35%⚠ Explotación activaCisco Secure Firewall Management Center29/7/202616/9/2026
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.
AnalizadaAlta (8.8)8.6%⚠ Explotación activaJfrog Artifactory27/7/202612/9/2026
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
AnalizadaCrítica (9.8)90%⚠ Explotación activa💥 ExploitJetbrains Teamcity27/7/20266/8/2026
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
AnalizadaCrítica (10)1.0%⚠ Explotación activaArista Velocloud Orchestrator27/7/202628/7/2026
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.…
AnalizadaCrítica (9.3)78%⚠ Explotación activa💥 ExploitCheckpoint Multi-domain Security ManagementCheckpoint Quantum Security Management22/7/202610/8/2026
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security…
AnalizadaCrítica (9.8)10%⚠ Explotación activa💥 ExploitWordpress17/7/202622/7/2026
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
AnalizadaMedia (5.9)5.9%⚠ Explotación activa💥 ExploitWordpress17/7/202629/7/2026
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
AnalizadaCrítica (9.8)29%⚠ Explotación activa💥 ExploitLangflow17/7/202617/8/2026
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
AnalizadaCrítica (9.3)19%⚠ Explotación activa💥 ExploitSangoma Switchvox17/7/20263/9/2026
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated…
AnalizadaAlta (8.1)4.0%⚠ Explotación activaDd-wrt16/7/202622/7/2026
An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only…
AnalizadaAlta (7.2)12%⚠ Explotación activa💥 PoCSonicwall Sma6210 FirmwareSonicwall Sma7210 FirmwareSonicwall Sma8200v14/7/202616/7/2026
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
AnalizadaCrítica (10)6.8%⚠ Explotación activa💥 ExploitSonicwall Sma6210 FirmwareSonicwall Sma7210 FirmwareSonicwall Sma8200v14/7/202616/7/2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
AnalizadaCrítica (9.1)70%⚠ Explotación activa💥 ExploitMicrosoft Sharepoint Server14/7/202619/8/2026
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
AnalizadaCrítica (9.8)16%⚠ Explotación activa💥 ExploitMicrosoft Sharepoint Server14/7/202617/7/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
AnalizadaCrítica (9.8)1.0%⚠ Explotación activa💥 PoCMicrosoft Sharepoint Server14/7/202614/7/2026
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
AnalizadaAlta (7.8)0.35%⚠ Explotación activaMicrosoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows Server 2012Microsoft Windows Server 2016+314/7/202615/7/2026
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
AnalizadaCrítica (9.8)3.0%⚠ Explotación activa💥 PoCMicrosoft Sharepoint Server14/7/202623/7/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
AnalizadaCrítica (10)15%⚠ Explotación activa💥 ExploitBalbooa Forms9/7/202624/7/2026
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
AnalizadaAlta (8.8)0.84%⚠ Explotación activa💥 PoCLitellm8/7/20263/9/2026
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an…
AnalizadaAlta (7.8)0.71%⚠ Explotación activa💥 PoCLinux Kernel4/7/202628/8/2026
In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are computed as datalen already includes fraggap (datalen = length…
AnalizadaCrítica (10)42%⚠ Explotación activa💥 ExploitAdobe Coldfusion30/6/202628/8/2026
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
AnalizadaAlta (8.8)1.0%⚠ Explotación activa💥 PoCCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway30/6/202627/8/2026
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
AnalizadaCrítica (10)31%⚠ Explotación activa💥 ExploitJoomlack Page Builder CK29/6/202624/7/2026
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
AnalizadaCrítica (10)2.1%⚠ Explotación activa💥 PoCKestra26/6/20263/9/2026
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Because the check is a suffix match rather than an exact path match, any API path…
Orbitaley — Vulnerabilidades