Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

1734 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.3)2.1%⚠ Explotación activa💥 PoCMirasvit Full Page Cache Warmer26/5/202624/7/2026
Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can exploit the unrestricted call to PHP's native…
AnalizadaAlta (8.8)2.7%⚠ Explotación activa💥 PoCMicrosoft Sharepoint Server22/5/202623/7/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaCrítica (10)46%⚠ Explotación activa💥 ExploitUI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+2722/5/202623/7/2026
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
AnalizadaCrítica (10)1.8%⚠ Explotación activaUI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+2822/5/202623/7/2026
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.
AnalizadaCrítica (10)15%⚠ Explotación activa💥 ExploitUI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+2722/5/202623/7/2026
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.
AnalizadaMedia (6.7)0.54%⚠ Explotación activa💥 PoCTrendmicro Apex ONE21/5/202623/7/2026
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential…
AnalizadaCrítica (10)1.0%⚠ Explotación activa💥 PoCLitespeedtech Litespeed Cpanel PluginLitespeedtech Litespeed WHM Plugin21/5/202623/7/2026
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been…
AnalizadaCrítica (9.8)16%⚠ Explotación activa💥 ExploitDrupal20/5/202623/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from…
AnalizadaAlta (7.5)1.3%⚠ Explotación activa💥 PoCMicrosoft Defender Antimalware Platform20/5/202623/7/2026
Microsoft Defender Denial of Service Vulnerability
AnalizadaAlta (7.8)0.44%⚠ Explotación activa💥 PoCMicrosoft Malware Protection Engine20/5/202624/7/2026
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
AnalizadaCrítica (9.3)0.96%⚠ Explotación activaDisc-soft Daemon Tools15/5/202617/6/2026
A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc…
AnalizadaMedia (6.1)0.52%⚠ Explotación activa💥 PoCMicrosoft Exchange ServerMicrosoft Exchange Server Subscription Edition14/5/202617/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AnalizadaCrítica (10)92%⚠ Explotación activa💥 PoCCisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond OrchestratorCisco Sd-wan Vsmart Controller14/5/202617/6/2026
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain…
AnalizadaAlta (7.8)97%⚠ Explotación activa💥 ExploitPaloaltonetworks Pan-osPaloaltonetworks Prisma AccessSiemens Ruggedcom Ape1808 Firmware13/5/202617/6/2026
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.
AnalizadaCrítica (9.6)1.1%⚠ Explotación activa💥 PoCTanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+16712/5/202617/6/2026
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The…
AnalizadaAlta (8.7)93%⚠ Explotación activa💥 ExploitLitellmRedhat Openshift AI8/5/202615/7/2026
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration in the request…
AnalizadaCrítica (9.3)5.8%⚠ Explotación activa💥 ExploitLitellm8/5/202615/7/2026
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of passing it as a separate parameter. An unauthenticated attacker could…
AnalizadaAlta (7.2)2.5%⚠ Explotación activaIvanti Endpoint Manager Mobile7/5/202617/6/2026
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.
AnalizadaCrítica (9.3)32%⚠ Explotación activa💥 PoCPaloaltonetworks Pan-osSiemens Ruggedcom Ape1808 Firmware6/5/202617/6/2026
A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this…
AnalizadaCrítica (9.3)99%⚠ Explotación activa💥 ExploitCpanelCpanel WHMCpanel WP Squared29/4/202630/9/2026
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
AnalizadaAlta (7.8)3.4%⚠ Explotación activa💥 ExploitLinux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+4422/4/20268/9/2026
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different…
AnalizadaAlta (7.8)0.40%⚠ Explotación activa💥 PoCMicrosoft Defender Antimalware Platform14/4/202624/7/2026
Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (4.3)4.9%⚠ Explotación activa💥 ExploitMicrosoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+1014/4/202614/8/2026
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
AnalizadaMedia (6.5)43%⚠ Explotación activa💥 PoCMicrosoft Sharepoint Server14/4/202617/6/2026
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
AnalizadaCrítica (9.8)1.6%⚠ Explotación activa💥 PoCMicrosoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+914/4/202625/9/2026
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
Orbitaley — Vulnerabilidades