Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1734 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 47% | ⚠ Explotación activa💥 Exploit | Fortinet Fortisandbox | 14/4/2026 | 17/7/2026 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | |
| Analizada | Alta (8.6) | 2.2% | ⚠ Explotación activa💥 PoC | Adobe Acrobat DCAdobe Acrobat Reader DCAdobe Acrobat | 11/4/2026 | 28/8/2026 | Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user… | |
| Analizada | Crítica (9.3) | 38% | ⚠ Explotación activa💥 Exploit | Coreweave Marimo | 9/4/2026 | 17/6/2026 | marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands. Unlike other WebSocket endpoints (e.g.,… | |
| Analizada | Alta (7.5) | 6.6% | ⚠ Explotación activa💥 Exploit | Apache TomcatRedhat Jboss WEB ServerRedhat Enterprise LinuxRedhat Enterprise Linux ELS+3 | 9/4/2026 | 21/9/2026 | Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue. | |
| Analizada | Alta (8.8) | 15% | ⚠ Explotación activa💥 Exploit | Apache ActivemqApache Activemq Broker | 7/4/2026 | 4/8/2026 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ… | |
| Analizada | Crítica (9.8) | 9.1% | ⚠ Explotación activa💥 Exploit | Fortinet Forticlientems | 4/4/2026 | 24/7/2026 | A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. | |
| Analizada | Alta (8.8) | 0.70% | ⚠ Explotación activa💥 PoC | Google Chrome | 1/4/2026 | 24/7/2026 | Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (7.8) | 0.33% | ⚠ Explotación activa💥 PoC | Trueconf | 30/3/2026 | 17/6/2026 | TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of… | |
| Analizada | Crítica (9.4) | 1.7% | ⚠ Explotación activa💥 PoC | Aquasec Setup-trivyAquasec TrivyAquasec Trivy ActionLitellm+1 | 23/3/2026 | 17/6/2026 | Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with malicious commits. This… | |
| Analizada | Crítica (9.3) | 4.0% | ⚠ Explotación activa💥 Exploit | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 23/3/2026 | 17/6/2026 | Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread | |
| Analizada | Crítica (9.3) | 25% | ⚠ Explotación activa💥 Exploit | Langflow | 20/3/2026 | 17/6/2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the optional data parameter is supplied, the endpoint uses attacker-controlled flow… | |
| Analizada | Alta (8.8) | 1.0% | ⚠ Explotación activa💥 PoC | Google Chrome | 13/3/2026 | 17/6/2026 | Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 2.3% | ⚠ Explotación activa💥 PoC | Google Chrome | 13/3/2026 | 17/6/2026 | Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Crítica (9.3) | 19% | ⚠ Explotación activa💥 PoC | Lantronix Eds5008 FirmwareLantronix Eds5016 FirmwareLantronix Eds5032 FirmwareLantronix G526gp12s Firmware+29 | 11/3/2026 | 8/9/2026 | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter.… | |
| Analizada | Crítica (10) | 43% | ⚠ Explotación activa💥 PoC | Cisco Secure Firewall Management Center | 4/3/2026 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream.… | |
| Analizada | Crítica (10) | 88% | ⚠ Explotación activa💥 Exploit | Cisco Secure Firewall Management Center | 4/3/2026 | 16/9/2026 | — | |
| Analizada | Alta (7.8) | 1.3% | ⚠ Explotación activa💥 PoC | Qualcomm Sm7675p FirmwareQualcomm Sm8475p FirmwareQualcomm Sm8550p FirmwareQualcomm Sm8635 Firmware+233 | 2/3/2026 | 17/6/2026 | Memory corruption while using alignments for memory allocation. | |
| Analizada | Alta (8.1) | 18% | ⚠ Explotación activa | Vmware Aria OperationsVmware Cloud FoundationVmware Telco Cloud InfrastructureVmware Telco Cloud Platform | 25/2/2026 | 17/6/2026 | VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. To remediate CVE-2026-22719, apply the… | |
| Analizada | Alta (7.5) | 32% | ⚠ Explotación activa | Cisco Catalyst Sd-wan Manager | 25/2/2026 | 17/6/2026 | A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit this vulnerability by accessing the… | |
| Analizada | Alta (7.5) | 7.1% | ⚠ Explotación activa | Cisco Catalyst Sd-wan Manager | 25/2/2026 | 17/6/2026 | A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system. This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit… | |
| Analizada | Crítica (10) | 88% | ⚠ Explotación activa💥 PoC | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond OrchestratorCisco Sd-wan Vsmart Controller | 25/2/2026 | 17/6/2026 | A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain… | |
| Analizada | Media (5.4) | 25% | ⚠ Explotación activa | Cisco Catalyst Sd-wan Manager | 25/2/2026 | 17/6/2026 | A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system. This vulnerability is due to… | |
| Analizada | Crítica (10) | 13% | ⚠ Explotación activa | Dell Recoverpoint FOR Virtual Machines | 17/2/2026 | 17/6/2026 | Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading to unauthorized access to the underlying… | |
| Analizada | Alta (8.8) | 55% | ⚠ Explotación activa💥 Exploit | Google Chrome | 13/2/2026 | 17/6/2026 | Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.7) | 5.2% | ⚠ Explotación activa | Soliton Filezen | 13/2/2026 | 17/6/2026 | FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command. |