Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

14.241 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaMedia (6.5)——Pulp ContainerAI7/10/20267/10/2026
A flaw was found in pulp-container when it authenticates to an upstream registry. Basic and bearer credentials from one remote are reused for later downloads in the same worker. A user who can sync a container remote, and can point that remote at a server they control, receives the username, password, or bearer token…
Pendiente de análisisMedia (6)——LangchainAI6/10/20266/10/2026
LangChain is a framework for building LLM-powered applications. Prior to 1.3.1, MongoDBChatMessageHistory does not enforce the documented string type for an untrusted structured session identifier at runtime, allowing the identifier to be interpreted as a MongoDB query condition rather than as a literal value when…
Pendiente de análisisMedia (6.5)——Jetbrains TeamcityAI6/10/20266/10/2026
In JetBrains TeamCity before 2026.2.1 missing validation of Git submodule URLs allowed reading local repositories on the server
Pendiente de análisisAlta (8.8)——Jetbrains TeamcityAI6/10/20267/10/2026
In JetBrains TeamCity before 2026.1.3 2025.11.7 kotlin DSL sandbox escape leading to RCE on the server was possible
Pendiente de análisisAlta (7.7)——Dell Container Storage ModulesAI6/10/20266/10/2026
Dell Container Storage Modules, versions prior to 1.18.0 contain(s) an Use of Insufficiently Random Values vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information tampering.
Pendiente de análisisAlta (7.1)——Dell Container Storage ModulesAI6/10/20266/10/2026
Dell Container Storage Modules (CSM), versions prior to 1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-tenant gRPC service (TenantService). An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized creation…
Pendiente de análisisCrítica (9.6)——Dell Container Storage ModulesAI6/10/20266/10/2026
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Pendiente de análisisAlta (8.2)——Dell Container Storage ModulesAI6/10/20266/10/2026
Dell Container Storage Modules (CSM) versions prior to 1.18.0, contains an Improper Certificate Validation vulnerability in the proxy-server component. An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to information exposure of storage backend administrator credentials.
Pendiente de análisisMedia (6.1)——Dell Container Storage ModulesAI6/10/20266/10/2026
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authorization vulnerability in the Dell CSI Driver for PowerMax - csireverseproxy . An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Unauthorized access.
Pendiente de análisisMedia (6.5)——Dell Container Storage ModulesAI6/10/20266/10/2026
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
Pendiente de análisisAlta (7.7)——Dell Container Storage ModulesAI6/10/20266/10/2026
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
En análisisCrítica (9.9)——Dell Container Storage Modules OperatorAI6/10/20266/10/2026
Dell Container Storage Modules (CSM) Operator, versions prior to 1.18.0 contains an Improper Privilege Management vulnerability in the ContainerStorageModule Custom Resource reconciler. A low privileged remote attacker could potentially exploit this vulnerability, leading to escalation of privileges and gaining…
En análisisCrítica (10)——Dell Container Storage ModulesAI6/10/20266/10/2026
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
En análisisCrítica (10)——Dell Container Storage ModulesAI6/10/20266/10/2026
Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-storage gRPC server. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to storage backend…
En análisisCrítica (9.8)——Dell Container Storage ModulesAI6/10/20266/10/2026
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the CSM Authorization. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
En análisisCrítica (9.8)——Dell Container Storage ModulesAI6/10/20266/10/2026
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the csm-docs. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.9.8
Pendiente de análisisBaja (2.3)——Langchain RedisAI6/10/20266/10/2026
LangChain is a framework for building LLM-powered applications. Prior to 1.1.1, @langchain/redis does not escape attacker-controlled values in structured RediSearch TAG filters and structured RediSearch TEXT filters, allowing injected RediSearch syntax to alter or broaden the generated search query. When an…
Pendiente de análisisCrítica (9.6)——Progress Software Autonomous Rest Connector Genai AgentsAI6/10/20267/10/2026
An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user…
AplazadaMedia (5.3)——Pusula Communication Expert MailAI6/10/20266/10/2026
Improper Control of Interaction Frequency vulnerability in Pusula Communication, IT, and Internet Industry and Trade Co. Ltd. Expert Mail allows Brute Force. This issue affects Expert Mail: through 2026-09-18.
AplazadaMedia (5.3)0.25%—Mailjet Email MarketingAI6/10/20266/10/2026
Unauthenticated Sensitive Data Exposure in Mailjet Email Marketing <= 6.2.3 versions.
AplazadaAlta (7.1)0.19%—Kainelabs YouzifyAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in Youzify <= 1.3.7 versions.
AplazadaCrítica (9.8)0.48%—Metabox Meta BOX AIOAI6/10/20266/10/2026
Unauthenticated Privilege Escalation in Meta Box AIO <= 3.7.1 versions.
AplazadaAlta (8.5)0.28%—Paid Member SubscriptionsAI6/10/20266/10/2026
Subscriber SQL Injection in Paid Member Subscriptions <= 3.1.1 versions.
AplazadaAlta (7.1)0.24%—Wpmailster WP MailsterAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in WP Mailster <= 1.9.0.0 versions.
AplazadaMedia (6.3)0.30%—Chainguard ApkoAI5/10/20266/10/2026
apko allows users to build and publish OCI container images built from apk packages. From version 0.2.0 to before version 1.4.5, UserEntry.Parse and GroupEntry.Parse in pkg/passwd read the UID and GID fields of /etc/passwd and /etc/group entries with strconv.Atoi and convert them to uint32 without a range check. On…