Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3020▼ 63 respecto a la semana anterior
Críticas / altas1413▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1881 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (6.7) | — | — | Aruba Clearpass ClientAI | 6/10/2026 | 6/10/2026 | A local privilege escalation vulnerability exists in the ClearPass client software. Successful exploitation could allow a low-privileged local user to execute commands with elevated privileges on the affected system, if certain conditions outside of the attacker's control are met. | |
| Pendiente de análisis | Media (5.7) | — | — | Rabbitmq Java ClientAI | 6/10/2026 | 6/10/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.35.0, ConnectionFactoryConfigurator.load() includes the raw uri value in wrapped exceptions when AMQP URI parsing fails. Because the URI may contain a plaintext username and password,… | |
| Pendiente de análisis | Media (6) | — | — | Rabbitmq Java Client LibraryAI | 6/10/2026 | 6/10/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.36.0, ValueReader.readShortstr decodes malformed UTF-8 bytes into replacement characters that can re-encode beyond the AMQP shortstr limit enforced by ValueWriter.writeShortstr. An… | |
| Pendiente de análisis | Media (4.9) | — | — | Rabbitmq Java ClientAI | 6/10/2026 | 6/10/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.37.0, com.rabbitmq.tools.json.JSONReader.read() fails to terminate when input ends inside a quoted string or a line comment because its string and whitespace scanners do not stop at… | |
| Pendiente de análisis | Alta (7.5) | — | — | Modelcontextprotocol SDKAIModelcontextprotocol ClientAI | 6/10/2026 | 6/10/2026 | MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Starting in version 1.12.0 and prior to versions 1.31.0 and 2.2.0, the SDK's OAuth client support let the MCP server a client connected to decide which authorization server received the client's OAuth credentials. Stored… | |
| Aplazada | Alta (8.4) | — | — | Openapi-python-clientAI | 6/10/2026 | 6/10/2026 | openapi-python-client generates Python clients from OpenAPI documents. Prior to 0.29.1, the generator does not safely neutralize malicious OpenAPI document content before rendering string, docstring, and f-string contexts in generated Python. The generated Python client can contain attacker-controlled Python that… | |
| Aplazada | Crítica (9.1) | 0.20% | — | Maclof Kubernetes ClientAI | 4/10/2026 | 6/10/2026 | maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfig lacks certificate-authority-data, ignoring insecure-skip-tls-verify. On-path attackers can impersonate the Kubernetes API server to capture Bearer tokens or Basic… | |
| Pendiente de análisis | Alta (7.4) | 0.20% | — | Confluent Kafka Python ClientAI | 1/10/2026 | 6/10/2026 | Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS certificate validation. | |
| Pendiente de análisis | Alta (8.5) | 0.12% | — | Catonetworks SDP ClientAI | 30/9/2026 | 30/9/2026 | Cato Networks SDP Client for Windows before 6.12.6 allows a local user to delete arbitrary files with SYSTEM privileges via improper validation of a client-supplied SID over a local IPC named pipe. | |
| Pendiente de análisis | Media (6.8) | 0.06% | — | Cato Windows SDP ClientAI | 30/9/2026 | 30/9/2026 | Cato Windows SDP Client before version 6.12.6 contains an arbitrary file disclosure vulnerability. A low-privileged local user can cause the Windows service, running as Local System, to read and disclose arbitrary local files due to improper file path validation and missing TLS certificate enforcement. | |
| Aplazada | Alta (8.7) | 0.33% | — | Codesys Gateway ClientAI | 30/9/2026 | 30/9/2026 | The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus… | |
| Pendiente de análisis | Alta (8.2) | 0.21% | — | Netx DUO Mqtt ClientAI | 29/9/2026 | 30/9/2026 | The NetX Duo MQTT client leaks the packet carrying a malformed PUBLISH message. Each malformed PUBLISH costs one packet, or one chain of packets, from the network driver's receive pool, and nothing returns it. A peer that can deliver a few dozen such messages exhausts the pool and stops all inbound network traffic on… | |
| Aplazada | Alta (7.8) | 0.09% | — | Seclore Filesecure Desktop ClientAI | 25/9/2026 | 30/9/2026 | Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in the kernel-mode driver component that allows an authenticated local user to gain elevated privileges to NT AUTHORITY\SYSTEM on affected systems. | |
| Pendiente de análisis | Alta (7.1) | 0.09% | — | Dell Trusted Device ClientAI | 24/9/2026 | 26/9/2026 | Dell Trusted Device Client, versions prior to 8.1.359.0, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering. | |
| Aplazada | Alta (8.7) | 0.30% | — | BSV Wallet ToolboxAIBSV Wallet Toolbox ClientAIBSV Wallet Toolbox MobileAI | 24/9/2026 | 30/9/2026 | `@bsv/wallet-toolbox` provides BRC-100 wallet signing and storage components, while `@bsv/wallet-toolbox-client` and `@bsv/wallet-toolbox-mobile` provide client-focused distributions for standard and mobile applications using wallet storage services. A vulnerability in these packages causes transactions created… | |
| Aplazada | Media (6.5) | 0.11% | — | Fabasoft Folio ClientAIFabasoft Egov-suiteAI | 24/9/2026 | 26/9/2026 | Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension via web messaging, does not restrict which web origins may invoke its functions by default. The registry value VALIDDOMAINS, which limits permitted origins, was optional and empty by default,… | |
| Pendiente de análisis | Alta (7.8) | 0.19% | — | Dell Inventory Collector ClientAI | 21/9/2026 | 24/9/2026 | Dell Inventory Collector Client, versions prior to 15.0.0, contain an Unquoted Search Path or Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of Privileges | |
| Pendiente de análisis | Alta (7.5) | 0.37% | — | IBM MQAIIBM MQ Java ClientAIIBM MQ JMS ClientAI | 18/9/2026 | 21/9/2026 | IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass in exception handling. | |
| Aplazada | Media (6.5) | 0.27% | — | Infinitewp ClientAI | 18/9/2026 | 18/9/2026 | The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection via the get_comments action in versions up to, and including, 1.13.9. This is due to insufficient escaping on the array-key names supplied in the JSON request body before use in a SQL statement: IWP_MMB_Comment::get_comments() calls extract() on… | |
| Pendiente de análisis | Media (5.9) | 0.27% | — | AsynchttpclientAI | 17/9/2026 | 24/9/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, a request using an HTTP proxy to reach an HTTPS origin can expose preemptive origin credentials because NettyRequestFactory and… | |
| Pendiente de análisis | Baja (3.7) | 0.41% | — | AsynchttpclientAI | 17/9/2026 | 24/9/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, processScramAuthenticationInfo and processAuthenticationInfo compute the SCRAM ServerSignature or Digest rspauth verification result but log a mismatch and… | |
| Pendiente de análisis | Alta (7.5) | 0.63% | — | AsynchttpclientAI | 17/9/2026 | 30/9/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, automatic response decompression on the HTTP/1.1 path uses ChannelManager.newHttpContentDecompressor() to install Http1ContentDecompressor without a… | |
| Pendiente de análisis | Alta (7.5) | 0.36% | — | AsynchttpclientAI | 17/9/2026 | 24/9/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 2.16.1 and 3.0.12, requests using an authenticated SOCKS proxy can expose the proxy's credentials to the origin because NettyRequestFactory and NettyRequestSender… | |
| Pendiente de análisis | Media (5.9) | 0.53% | — | AsynchttpclientAI | 17/9/2026 | 30/9/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, a client with maxConnections or maxConnectionsPerHost set above zero leaks one connection permit whenever TLS connection establishment fails before the… | |
| Pendiente de análisis | Media (6.8) | 0.53% | — | AsynchttpclientAI | 17/9/2026 | 30/9/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.14.5 to 2.16.0 and from 3.0.9 to 3.0.11, a client configured with a client-wide Realm and redirect following can disclose credentials after a cross-origin redirect because the… |