Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
1734 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.83% | ⚠ Explotación activa💥 PoC | Linux Kernel | 25/6/2026 | 19/9/2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through… | |
| Analizada | Alta (8.4) | 0.89% | ⚠ Explotación activa💥 PoC | Langflow | 23/6/2026 | 8/7/2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This… | |
| Analizada | Crítica (10) | 20% | ⚠ Explotación activa💥 Exploit | Joomlic Icagenda | 20/6/2026 | 11/7/2026 | A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution. | |
| Analizada | Crítica (10) | 89% | ⚠ Explotación activa💥 Exploit | Ollyo SP Page Builder | 20/6/2026 | 8/7/2026 | A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code. | |
| Analizada | Crítica (9.3) | 46% | ⚠ Explotación activa | PTC FlexplmPTC Windchill Pdmlink | 18/6/2026 | 1/8/2026 | — | |
| Analizada | Alta (8.8) | 2.5% | ⚠ Explotación activa | Zyxel Gs1900-8 FirmwareZyxel Gs1900-8hp FirmwareZyxel Gs1900-10hp FirmwareZyxel Gs1900-16 Firmware+6 | 16/6/2026 | 22/9/2026 | A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request. | |
| Analizada | Media (6.5) | 28% | ⚠ Explotación activa💥 PoC | Cisco Catalyst Sd-wan Manager | 15/6/2026 | 24/7/2026 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate user-supplied input… | |
| Analizada | Alta (8.5) | 0.81% | ⚠ Explotación activa💥 PoC | Litespeedtech Litespeed Cpanel PluginLitespeedtech Litespeed WHM Plugin | 14/6/2026 | 23/7/2026 | LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026. | |
| Analizada | Crítica (9.5) | 5.7% | ⚠ Explotación activa💥 Exploit | Simple-help Simplehelp | 12/6/2026 | 30/6/2026 | SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a… | |
| Analizada | Crítica (9.8) | 9.4% | ⚠ Explotación activa💥 Exploit | Oracle Peoplesoft Enterprise Peopletools | 11/6/2026 | 23/7/2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise… | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | Splunk | 10/6/2026 | 23/7/2026 | In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any… | |
| Analizada | Crítica (9.8) | 76% | ⚠ Explotación activa💥 PoC | Fortinet FortisandboxFortinet Fortisandbox CloudFortinet Fortisandbox Paas | 9/6/2026 | 23/7/2026 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Ivanti Standalone Sentry | 9/6/2026 | 23/7/2026 | An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution | |
| Analizada | Alta (8.8) | 2.4% | ⚠ Explotación activa💥 PoC | Google Chrome | 9/6/2026 | 23/7/2026 | Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Crítica (9.3) | 6.4% | ⚠ Explotación activa💥 Exploit | Checkpoint Gaia OSCheckpoint Gaia Embedded | 8/6/2026 | 4/8/2026 | A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password. | |
| Analizada | Media (6.9) | 0.65% | ⚠ Explotación activa💥 PoC | Arista EOS | 5/6/2026 | 17/6/2026 | On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP… | |
| Analizada | Crítica (10) | 16% | ⚠ Explotación activa💥 Exploit | Widgetfactorylimited JCE | 5/6/2026 | 23/7/2026 | A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution. | |
| Analizada | Alta (7.8) | 25% | ⚠ Explotación activa💥 PoC | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vsmart Controller | 4/6/2026 | 23/7/2026 | A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to… | |
| Analizada | Alta (7.5) | 1.9% | ⚠ Explotación activa💥 PoC | Solarwinds Serv-u | 4/6/2026 | 22/7/2026 | SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update | |
| Analizada | Crítica (9.8) | 77% | ⚠ Explotación activa💥 Exploit | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster | 4/6/2026 | 1/10/2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints | |
| Analizada | Alta (8.6) | 88% | ⚠ Explotación activa💥 PoC | Cisco Unified Communications Manager | 3/6/2026 | 22/7/2026 | A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to… | |
| Analizada | Alta (8.4) | 1.7% | ⚠ Explotación activa💥 PoC | Google Android | 1/6/2026 | 22/7/2026 | In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Crítica (9.8) | 0.81% | ⚠ Explotación activa💥 PoC | Oracle E-business Suite | 28/5/2026 | 21/7/2026 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this… | |
| Analizada | Crítica (9.3) | 1.3% | ⚠ Explotación activa | NX Console | 27/5/2026 | 17/6/2026 | Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and the compromised version… | |
| Analizada | Media (6.5) | 7.1% | ⚠ Explotación activa💥 Exploit | Encode StarletteRedhat AI Inference ServerRedhat Ansible Automation PlatformRedhat Migration Toolkit FOR Applications+4 | 26/5/2026 | 1/10/2026 | Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make… |