Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
1734 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 2.1% | ⚠ Explotación activa💥 PoC | Mirasvit Full Page Cache Warmer | 26/5/2026 | 24/7/2026 | Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can exploit the unrestricted call to PHP's native… | |
| Analizada | Alta (8.8) | 2.7% | ⚠ Explotación activa💥 PoC | Microsoft Sharepoint Server | 22/5/2026 | 23/7/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Crítica (10) | 46% | ⚠ Explotación activa💥 Exploit | UI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+27 | 22/5/2026 | 23/7/2026 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection. | |
| Analizada | Crítica (10) | 1.8% | ⚠ Explotación activa | UI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+28 | 22/5/2026 | 23/7/2026 | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account. | |
| Analizada | Crítica (10) | 15% | ⚠ Explotación activa💥 Exploit | UI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+27 | 22/5/2026 | 23/7/2026 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system. | |
| Analizada | Media (6.7) | 0.54% | ⚠ Explotación activa💥 PoC | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential… | |
| Analizada | Crítica (10) | 1.0% | ⚠ Explotación activa💥 PoC | Litespeedtech Litespeed Cpanel PluginLitespeedtech Litespeed WHM Plugin | 21/5/2026 | 23/7/2026 | LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been… | |
| Analizada | Crítica (9.8) | 16% | ⚠ Explotación activa💥 Exploit | Drupal | 20/5/2026 | 23/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from… | |
| Analizada | Alta (7.5) | 1.3% | ⚠ Explotación activa💥 PoC | Microsoft Defender Antimalware Platform | 20/5/2026 | 23/7/2026 | Microsoft Defender Denial of Service Vulnerability | |
| Analizada | Alta (7.8) | 0.44% | ⚠ Explotación activa💥 PoC | Microsoft Malware Protection Engine | 20/5/2026 | 24/7/2026 | Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally. | |
| Analizada | Crítica (9.3) | 0.96% | ⚠ Explotación activa | Disc-soft Daemon Tools | 15/5/2026 | 17/6/2026 | A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc… | |
| Analizada | Media (6.1) | 0.52% | ⚠ Explotación activa💥 PoC | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 14/5/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Crítica (10) | 92% | ⚠ Explotación activa💥 PoC | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond OrchestratorCisco Sd-wan Vsmart Controller | 14/5/2026 | 17/6/2026 | A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain… | |
| Analizada | Alta (7.8) | 97% | ⚠ Explotación activa💥 Exploit | Paloaltonetworks Pan-osPaloaltonetworks Prisma AccessSiemens Ruggedcom Ape1808 Firmware | 13/5/2026 | 17/6/2026 | Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues. | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa💥 PoC | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Analizada | Alta (8.7) | 93% | ⚠ Explotación activa💥 Exploit | LitellmRedhat Openshift AI | 8/5/2026 | 15/7/2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration in the request… | |
| Analizada | Crítica (9.3) | 5.8% | ⚠ Explotación activa💥 Exploit | Litellm | 8/5/2026 | 15/7/2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of passing it as a separate parameter. An unauthenticated attacker could… | |
| Analizada | Alta (7.2) | 2.5% | ⚠ Explotación activa | Ivanti Endpoint Manager Mobile | 7/5/2026 | 17/6/2026 | An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution. | |
| Analizada | Crítica (9.3) | 32% | ⚠ Explotación activa💥 PoC | Paloaltonetworks Pan-osSiemens Ruggedcom Ape1808 Firmware | 6/5/2026 | 17/6/2026 | A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this… | |
| Analizada | Crítica (9.3) | 99% | ⚠ Explotación activa💥 Exploit | CpanelCpanel WHMCpanel WP Squared | 29/4/2026 | 30/9/2026 | cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel. | |
| Analizada | Alta (7.8) | 3.4% | ⚠ Explotación activa💥 Exploit | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+44 | 22/4/2026 | 8/9/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different… | |
| Analizada | Alta (7.8) | 0.40% | ⚠ Explotación activa💥 PoC | Microsoft Defender Antimalware Platform | 14/4/2026 | 24/7/2026 | Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (4.3) | 4.9% | ⚠ Explotación activa💥 Exploit | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+10 | 14/4/2026 | 14/8/2026 | Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (6.5) | 43% | ⚠ Explotación activa💥 PoC | Microsoft Sharepoint Server | 14/4/2026 | 17/6/2026 | Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Crítica (9.8) | 1.6% | ⚠ Explotación activa💥 PoC | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 14/4/2026 | 25/9/2026 | Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. |