Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
14.241 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (6.5) | — | — | Pulp ContainerAI | 7/10/2026 | 7/10/2026 | A flaw was found in pulp-container when it authenticates to an upstream registry. Basic and bearer credentials from one remote are reused for later downloads in the same worker. A user who can sync a container remote, and can point that remote at a server they control, receives the username, password, or bearer token… | |
| Pendiente de análisis | Media (6) | — | — | LangchainAI | 6/10/2026 | 6/10/2026 | LangChain is a framework for building LLM-powered applications. Prior to 1.3.1, MongoDBChatMessageHistory does not enforce the documented string type for an untrusted structured session identifier at runtime, allowing the identifier to be interpreted as a MongoDB query condition rather than as a literal value when… | |
| Pendiente de análisis | Media (6.5) | — | — | Jetbrains TeamcityAI | 6/10/2026 | 6/10/2026 | In JetBrains TeamCity before 2026.2.1 missing validation of Git submodule URLs allowed reading local repositories on the server | |
| Pendiente de análisis | Alta (8.8) | — | — | Jetbrains TeamcityAI | 6/10/2026 | 7/10/2026 | In JetBrains TeamCity before 2026.1.3 2025.11.7 kotlin DSL sandbox escape leading to RCE on the server was possible | |
| Pendiente de análisis | Alta (7.7) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0 contain(s) an Use of Insufficiently Random Values vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information tampering. | |
| Pendiente de análisis | Alta (7.1) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules (CSM), versions prior to 1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-tenant gRPC service (TenantService). An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized creation… | |
| Pendiente de análisis | Crítica (9.6) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Pendiente de análisis | Alta (8.2) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules (CSM) versions prior to 1.18.0, contains an Improper Certificate Validation vulnerability in the proxy-server component. An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to information exposure of storage backend administrator credentials. | |
| Pendiente de análisis | Media (6.1) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authorization vulnerability in the Dell CSI Driver for PowerMax - csireverseproxy . An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Pendiente de análisis | Media (6.5) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Pendiente de análisis | Alta (7.7) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |
| En análisis | Crítica (9.9) | — | — | Dell Container Storage Modules OperatorAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules (CSM) Operator, versions prior to 1.18.0 contains an Improper Privilege Management vulnerability in the ContainerStorageModule Custom Resource reconciler. A low privileged remote attacker could potentially exploit this vulnerability, leading to escalation of privileges and gaining… | |
| En análisis | Crítica (10) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| En análisis | Crítica (10) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-storage gRPC server. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to storage backend… | |
| En análisis | Crítica (9.8) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the CSM Authorization. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| En análisis | Crítica (9.8) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the csm-docs. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.9.8 | |
| Pendiente de análisis | Baja (2.3) | — | — | Langchain RedisAI | 6/10/2026 | 6/10/2026 | LangChain is a framework for building LLM-powered applications. Prior to 1.1.1, @langchain/redis does not escape attacker-controlled values in structured RediSearch TAG filters and structured RediSearch TEXT filters, allowing injected RediSearch syntax to alter or broaden the generated search query. When an… | |
| Pendiente de análisis | Crítica (9.6) | — | — | Progress Software Autonomous Rest Connector Genai AgentsAI | 6/10/2026 | 7/10/2026 | An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user… | |
| Aplazada | Media (5.3) | — | — | Pusula Communication Expert MailAI | 6/10/2026 | 6/10/2026 | Improper Control of Interaction Frequency vulnerability in Pusula Communication, IT, and Internet Industry and Trade Co. Ltd. Expert Mail allows Brute Force. This issue affects Expert Mail: through 2026-09-18. | |
| Aplazada | Media (5.3) | 0.25% | — | Mailjet Email MarketingAI | 6/10/2026 | 6/10/2026 | Unauthenticated Sensitive Data Exposure in Mailjet Email Marketing <= 6.2.3 versions. | |
| Aplazada | Alta (7.1) | 0.19% | — | Kainelabs YouzifyAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Youzify <= 1.3.7 versions. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Metabox Meta BOX AIOAI | 6/10/2026 | 6/10/2026 | Unauthenticated Privilege Escalation in Meta Box AIO <= 3.7.1 versions. | |
| Aplazada | Alta (8.5) | 0.28% | — | Paid Member SubscriptionsAI | 6/10/2026 | 6/10/2026 | Subscriber SQL Injection in Paid Member Subscriptions <= 3.1.1 versions. | |
| Aplazada | Alta (7.1) | 0.24% | — | Wpmailster WP MailsterAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Mailster <= 1.9.0.0 versions. | |
| Aplazada | Media (6.3) | 0.30% | — | Chainguard ApkoAI | 5/10/2026 | 6/10/2026 | apko allows users to build and publish OCI container images built from apk packages. From version 0.2.0 to before version 1.4.5, UserEntry.Parse and GroupEntry.Parse in pkg/passwd read the UID and GID fields of /etc/passwd and /etc/group entries with strconv.Atoi and convert them to uint32 without a range check. On… |