Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
127 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2) | 0.19% | — | Anaconda DaskAI | 22/9/2026 | 23/9/2026 | A security vulnerability has been detected in Dask up to 2026.8.0. This affects the function from_npy_stack of the file dask/array/core.py of the component Loader. Such manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was… | |
| Pendiente de análisis | Alta (8.1) | 0.48% | — | Katacontainers Kata ContainersAI | 20/8/2026 | 1/9/2026 | A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can exploit insufficient validation of CreateContainer mount and storage rules. This allows them to mount arbitrary container-rootfs paths over sensitive host locations or… | |
| Aplazada | Alta (8.1) | 0.75% | — | Ventraconnect Social Login Passwordless LoginAI | 12/8/2026 | 12/8/2026 | The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the plugin trusting the unverified email field returned by Spotify's /v1/me… | |
| Aplazada | Media (5.7) | 0.18% | — | Katacontainers Kata ContainersAI | 7/8/2026 | 9/9/2026 | Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 4.0.0, the kata-agent is vulnerable to an authorization bypass in confidential-guest memory management. In Confidential Containers (CoCo) deployments, the kata-agent enforces an… | |
| Aplazada | Crítica (9.2) | 0.20% | — | Katacontainers Kata ContainersAI | 7/8/2026 | 9/9/2026 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to 3.31.0, the runtime-rs standalone virtio-fs path is vulnerable to a guest-root to host-root escape. In this configuration, Kata runs the host virtiofsd as root… | |
| Aplazada | Crítica (9.6) | 0.61% | — | Katacontainers Kata RuntimeAI | 7/8/2026 | 9/9/2026 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalidated configuration path annotation. The runtime accepts an arbitrary… | |
| Analizada | Media (5.8) | 0.59% | — | Katacontainers Kata Containers | 23/7/2026 | 6/8/2026 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Versions prior to 3.31.0 ship with a default configuration that allows pod creators to inject arbitrary command-line arguments into the virtiofsd process through the… | |
| Aplazada | Baja (2.3) | 0.29% | — | Anaconda DaskAI | 3/6/2026 | 22/7/2026 | A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of the file dask/dataframe/hyperloglog.py of the component HLL Handler. This manipulation causes resource consumption. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack.… | |
| Aplazada | Alta (7.5) | 0.23% | — | Alkacon OpencmsAI | 8/5/2026 | 17/6/2026 | Alkacon OpenCms before 16 allows XXE when the <!DOCTYPE> refers to an external host. | |
| Aplazada | Media (6.1) | 0.15% | — | Alkacon OpencmsAI | 8/5/2026 | 17/6/2026 | A Cross Site Scripting vulnerability in Alkacon OpenCms before 16 exists via updateModelGroups.jsp. | |
| Aplazada | Alta (7.3) | 2.2% | 💥 Exploit | Alkacon OpencmsAI | 8/5/2026 | 17/6/2026 | Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack on a Chemistry servlet. | |
| Aplazada | Media (6.1) | 0.59% | 💥 Exploit | Alkacon OpencmsAI | 8/5/2026 | 17/6/2026 | A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type. | |
| Modificada | Alta (8.2) | 0.37% | — | Katacontainers Confidential ContainersKatacontainers Kata Containers | 24/4/2026 | 24/8/2026 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an oversight in the CopyFile policy (and perhaps the CopyFile handler) allows untrusted hosts to write to arbitrary locations inside the guest… | |
| Analizada | Alta (8.1) | 0.53% | 💥 PoC | Dynaconf | 20/3/2026 | 17/6/2026 | dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values… | |
| Aplazada | Alta (8.1) | 0.58% | — | Themerex BeaconAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Beacon beacon allows PHP Local File Inclusion.This issue affects Beacon: from n/a through <= 2.24. | |
| Modificada | Alta (8.8) | 0.22% | — | Katacontainers Kata Containers | 19/2/2026 | 15/7/2026 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.27.0, an issue in Kata with Cloud Hypervisor allows a user of the container to modify the file system used by the Guest micro VM ultimately… | |
| Analizada | Media (5.1) | 0.27% | — | Alkacon Opencms | 19/2/2026 | 17/6/2026 | Reflected Cross-site Scripting (XSS) in Alkacon's OpenCms v18.0, which allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL containing the ‘q’ parameter in ‘/search/index.html’. This vulnerability can be exploited to steal sensitive user information such as… | |
| Analizada | Media (5.1) | 0.24% | — | Alkacon Opencms | 19/2/2026 | 17/6/2026 | Stored Cross-Site Scripting (XSS) in Alkacon's OpenCms v18.0, which occurs when user input is not properly validated when sending a POST request to ‘/blog/new-article/org.opencms.ugc.CmsUgcEditService.gwt’ using the ‘text’ parameter. | |
| Aplazada | Alta (8) | 0.42% | 💥 PoC | BeaconAI | 2/2/2026 | 17/6/2026 | The unified WEBUI application of the ONT/Beacon device contains an input handling flaw that allows authenticated users to trigger unintended system-level command execution. Due to insufficient validation of user-supplied data, a low-privileged authenticated attacker may be able to execute arbitrary commands on the… | |
| Analizada | Alta (8.8) | 0.50% | — | Katacontainers Kata Containers | 29/1/2026 | 17/6/2026 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.26.0, when a container image is malformed or contains no layers, containerd falls back to bind-mounting an empty snapshotter directory for the… | |
| Analizada | Media (5.3) | 0.24% | — | Anaconda Dask | 16/1/2026 | 17/6/2026 | Dask distributed is a distributed task scheduler for Dask. Prior to 2026.1.0, when Jupyter Lab, jupyter-server-proxy, and Dask distributed are all run together, it is possible to craft a URL which will result in code being executed by Jupyter due to a cross-side-scripting (XSS) bug in the Dask dashboard. It is… | |
| Aplazada | Media (5.9) | 0.17% | — | Janhenckels Wp-dashboard-beaconAI | 31/12/2025 | 23/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in janhenckens Dashboard Beacon wp-dashboard-beacon allows Stored XSS.This issue affects Dashboard Beacon: from n/a through <= 1.2.0. | |
| Analizada | Alta (7.8) | 0.20% | — | Anaconda3 | 17/12/2025 | 26/9/2026 | Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This allows a local low-privileged user to inject arbitrary commands, leading to code… | |
| Aplazada | Media (6.9) | 0.33% | — | Katacontainers Kata ContainersAI | 23/9/2025 | 17/6/2026 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In Kata Containers versions from 3.20.0 and before, a malicious host can circumvent initdata verification. On TDX systems running confidential guests, a malicious host can… | |
| Analizada | Alta (7.2) | 0.65% | — | Anaconda Conda-build | 16/6/2025 | 17/6/2026 | Conda-build contains commands and tools to build conda packages. Prior to version 25.3.0, the pyproject.toml lists conda-index as a Python dependency. This package is not published in PyPI. An attacker could claim this namespace and upload arbitrary (malicious) code to the package, and then exploit pip install… |