Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 336 respecto a la semana anterior
Críticas / altas1383▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 214 respecto a la semana anterior
39.978 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Crítica (9.3) | — | — | Sixapart Movable TypeAI | 7/10/2026 | 7/10/2026 | A code injection vulnerability exists in the upgrade script of Movable Type, which may allow an unauthenticated attacker to execute an arbitrary Perl script or an SQL query on the affected product. | |
| Recibida | Crítica (9.8) | — | — | LmcacheAI | 7/10/2026 | 7/10/2026 | LMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and share KV cache blocks. Messages on that socket are msgpack. Extension code 1 is passed to DeviceIPCWrapper.Deserialize, which calls pickle.loads, while the server is still decoding… | |
| Recibida | Crítica (9.3) | — | — | — | 7/10/2026 | 7/10/2026 | This vulnerability exists in the ERP system due to unsafe deserialization of user controlled data in the affected functionality. An unauthenticated remote attacker could exploit this vulnerability by supplying specially crafted data to the vulnerable functionality of the targeted system. Successful exploitation of… | |
| Recibida | Crítica (9.3) | — | — | — | 7/10/2026 | 7/10/2026 | This vulnerability exists in the ERP system due to insufficient validation and parameterization of user supplied input in an API endpoint. An unauthenticated remote attacker could exploit this vulnerability by supplying specially crafted input to the vulnerable endpoint. Successful exploitation of this vulnerability… | |
| Recibida | Crítica (9.3) | — | — | — | 7/10/2026 | 7/10/2026 | This vulnerability exists in the ERP system due to improper validation of payment callback parameters and inadequate authentication controls in API endpoint. An unauthenticated remote attacker could exploit this vulnerability by manipulating the parameter to cause the application to establish an authenticated session… | |
| Recibida | Crítica (9.3) | — | — | Eclipse Netx DUOAI | 7/10/2026 | 7/10/2026 | Out-of-bounds write via the TLS 1.3 handshake message cache in NetX Duo in Eclipse ThreadX NetX Duo 6.5.1.202602 allows a handshake message larger than the cache writes past it and on into the rest of the session control block, which holds pointers. A malicious or compromised server can make a TLS 1.3 client produce… | |
| Recibida | Crítica (9.3) | — | — | Ordasoft Simple MembershipAI | 7/10/2026 | 7/10/2026 | Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Simple Membership < 7.4.0 - site/simplemembership.php dispatches task=checkLoginPass with no authentication or access control check of any kind. The handler reads a login request parameter through Joomla’s generic, non-sanitizing input filter,… | |
| Recibida | Crítica (9.4) | — | — | Veeam Backup AND ReplicationAI | 7/10/2026 | 7/10/2026 | This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execute arbitrary code as SYSTEM on the backup server. | |
| Recibida | Crítica (9.3) | — | 💥 PoC | Vmware WorkstationAIVmware FusionAI | 7/10/2026 | 7/10/2026 | VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Affected versions: - VMware Workstation: 25H2, 26H1 (fixed in 26H1u1) - VMware… | |
| Recibida | Crítica (9.3) | — | — | Flexnet PublisherAI | 7/10/2026 | 7/10/2026 | A security vulnerability has been identified in FlexNet Publisher lmadmin. The vulnerability exists in a SOAP handler, where a hardcoded authentication bypass could allow an unauthenticated user to obtain a privileged administrator session without providing valid credentials. | |
| Recibida | Crítica (9) | — | — | Wolfssl WolfsshAI | 7/10/2026 | 7/10/2026 | wolfSSH does not validate that the ECDSA curve identifier in a KEXDH_REPLY host key blob matches the algorithm negotiated during key exchange. In ParseECCPubKey() (src/internal.c), the blob's algorithm string is used to derive the curve via NameToId/wcPrimeForId without checking against the negotiated… | |
| Recibida | Crítica (9.3) | — | — | Asus Router FirmwareAI | 7/10/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation (“Cross-site Scripting”) in ASUS router modules allows a remote attacker to read DOM information, modify router settings, and cause a denial-of-service condition when an authenticated user visits a crafted URL.Refer to the ' Security Update for ASUS Router… | |
| Recibida | Crítica (9.3) | — | — | Asus Router FirmwareAI | 7/10/2026 | 7/10/2026 | A stack-based buffer overflow in the ASUS router modules allows an authenticated nearby user to execute arbitrary code via a crafted configuration file upload that exceeds the expected buffer size.Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information. | |
| Recibida | Crítica (9.2) | — | — | Asustor ADMAI | 7/10/2026 | 7/10/2026 | An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files on the host system. By sending a crafted HTTP request with injected headers via the state parameter, the attacker can leverage the underlying web server's X-Sendfile mechanism to… | |
| Recibida | Crítica (9.8) | — | 💥 PoC | IBM LangflowAI | 6/10/2026 | 6/10/2026 | IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | |
| Recibida | Crítica (9.8) | — | — | IBM LangflowAI | 6/10/2026 | 6/10/2026 | IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper control of code generation. | |
| Recibida | Crítica (9.6) | — | — | Backstage Plugin Scaffolder BackendAI | 6/10/2026 | 6/10/2026 | Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensitive information exposure in scaffolder. An authenticated Backstage user who can read another user's Scaffolder task may receive internal execution… | |
| Recibida | Crítica (9.8) | — | — | Arista Clearpass Policy ManagerAI | 6/10/2026 | 6/10/2026 | An authenticated path traversal vulnerability exists in ClearPass Policy Manager. Successful exploitation could allow an attacker to read and modify certain files on the underlying operating system. | |
| Recibida | Crítica (9.8) | — | — | HPE Clearpass Policy ManagerAI | 6/10/2026 | 6/10/2026 | A missing integrity verification vulnerability in the client agent software of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to introduce untrusted code. Successful exploitation could allow an attacker to execute arbitrary code on the affected client system. | |
| Recibida | Crítica (9.9) | — | — | Aruba Clearpass Policy ManagerAI | 6/10/2026 | 6/10/2026 | SQL injection vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow a low-privileged authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands. | |
| Recibida | Crítica (9.8) | — | — | Aruba Clearpass Policy ManagerAI | 6/10/2026 | 6/10/2026 | Vulnerabilities have been identified in the affected interface of ClearPass Policy Manager that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain unauthorized access to the affected system. | |
| Recibida | Crítica (9.1) | — | — | Aruba Clearpass Policy ManagerAI | 6/10/2026 | 6/10/2026 | A SQL injection vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands. | |
| Recibida | Crítica (9.8) | — | — | Aruba Clearpass Policy ManagerAI | 6/10/2026 | 6/10/2026 | A vulnerability in an affected interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands. | |
| Recibida | Crítica (9.8) | — | — | HPE Clearpass Policy ManagerAI | 6/10/2026 | 6/10/2026 | A format string vulnerability in an affected service interface of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to corrupt process memory. Successful exploitation could allow an attacker to execute arbitrary code. | |
| Recibida | Crítica (9.8) | — | — | HPE Clearpass Policy ManagerAI | 6/10/2026 | 6/10/2026 | Authentication bypass vulnerabilities exist in the web-based management and API interfaces of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to circumvent existing authentication controls and gain administrative access to the affected system. |