Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
11.338 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Baja (2.5) | 0.13% | — | Openbsd OpensshAI | 6/10/2026 | 6/10/2026 | In ssh in OpenSSH before 10.6, a $ or \ character can occur in a command-line username, leading to injection. | |
| Recibida | Media (5.5) | 0.12% | — | Nvidia TensorrtAI | 6/10/2026 | 6/10/2026 | NVIDIA TensorRT contains a vulnerability where an attacker can cause an out of bounds read. A successful exploit of this vulnerability may lead to denial of service. | |
| Recibida | Baja (2.9) | 0.08% | — | Openbsd OpensshAI | 6/10/2026 | 6/10/2026 | In sshd in OpenSSH through 10.6, in certain environments such as QNX 6 and SCO OpenServer 5, sshd-session can unexpectedly have root privileges. This is related to the GatewayPorts and StreamLocalForwarding configuration options, and lack of support for file-descriptor passing and unprivileged allocation of PTY… | |
| Recibida | Baja (3.1) | 0.13% | — | Openbsd OpensshAI | 6/10/2026 | 6/10/2026 | In sshd in OpenSSH through 10.6, use of the macOS 27 (or later) SDK has the side effect of loss of sandboxing, which is potentially unexpected. | |
| Recibida | Baja (3.6) | 0.08% | — | Openbsd OpensshAI | 6/10/2026 | 6/10/2026 | In sshd in OpenSSH before 10.6, the value "none" for a configuration option is sometimes interpreted as a filename but was intended to mean that a feature is disabled. | |
| Recibida | Baja (2.5) | 0.08% | — | Openbsd OpensshAI | 6/10/2026 | 6/10/2026 | In sshd in OpenSSH before 10.6, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not, a different vulnerability than CVE-2026-73283. | |
| Recibida | Media (6.5) | 0.19% | — | Openbsd OpensshAI | 6/10/2026 | 6/10/2026 | In sshd and ssh in OpenSSH before 10.6, there is no check for whether the maximum packet length is exceeded during decompression of highly compressed data. | |
| Recibida | Baja (2.5) | 0.06% | — | Openbsd OpensshAI | 6/10/2026 | 6/10/2026 | In ssh-keygen in OpenSSH before 10.6, certificates could have incorrect expiration times because of Daylight Saving mishandling. There can be a slightly more severe effect on users in certain Antarctic locations. | |
| Recibida | Baja (3.7) | 0.18% | — | Openbsd OpensshAI | 6/10/2026 | 6/10/2026 | In sshd and ssh in OpenSSH before 10.6, an LZ77 dictionary coder can be used even though this is contraindicated by the arXiv 2609.07709 "Crossing the Streams" findings. | |
| Recibida | Baja (2.2) | 0.08% | — | Openbsd OpensshAI | 6/10/2026 | 6/10/2026 | In sshd in OpenSSH before 10.6, GSSAPIAuthentication authentication state can incorrectly be persisted across authentication attempts. | |
| Recibida | Baja (2.2) | 0.08% | — | Openbsd OpensshAI | 6/10/2026 | 6/10/2026 | In sshd in OpenSSH before 10.6, credentials can incorrectly persist after failure of a GSSAPIAuthentication authentication attempt. | |
| Recibida | Media (4.2) | 0.29% | — | Openbsd OpensshAI | 6/10/2026 | 6/10/2026 | In sftp in OpenSSH before 10.6, a server can trigger directory traversal (causing files to be written to unintended locations) during a recursive copy operation. | |
| Pendiente de análisis | Alta (7.2) | 0.33% | — | Arista Cloudvision PortalAIArista Cloudvision SensorAI | 6/10/2026 | 7/10/2026 | On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vulnerability exists. An authenticated user with sufficient high privileges could exploit this to extract unintended data from the Sensor. | |
| Pendiente de análisis | Crítica (9.3) | 0.24% | — | Opensis ClassicAI | 5/10/2026 | 6/10/2026 | openSIS Classic 9.3 allows an authenticated user with the built-in teacher role can select an arbitrary staff record through staff_id and cause the School Information update path to reset that selected account's password. | |
| En análisis | Alta (7.3) | 0.15% | — | Siemens NXAI | 2/10/2026 | 5/10/2026 | Nx is a monorepo solution for TypeScript and polyglot codebases. From 21.4.0 until 22.7.8 and from 23.0.0 until 23.1.1, the @nx/docker release pipeline builds docker tag, image lookup, and docker push invocations as shell command strings. The release.docker.repositoryName and registryUrl configuration values are… | |
| Aplazada | Media (6.1) | 0.21% | — | Wpsoul GreenshiftAI | 2/10/2026 | 2/10/2026 | The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via '{{GET:}}' Dynamic Placeholder in all versions up to, and including, 13.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (5.1) | 0.19% | — | OpenscAI | 30/9/2026 | 5/10/2026 | A flaw has been found in OpenSC up to 0.27.1. The impacted element is the function setcos_construct_fci_44 of the file src/libopensc/card-setcos.c. Executing a manipulation of the argument type_attr can lead to stack-based buffer overflow. The attack can be launched remotely. This patch is called… | |
| Aplazada | Alta (8.6) | 0.27% | — | OpensaveAI | 30/9/2026 | 30/9/2026 | OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifest request handler. Attackers can specify arbitrary directories outside configured save locations to read and write files through manifest and sync routes. | |
| Aplazada | Media (6.3) | 0.22% | — | OpensaveAI | 30/9/2026 | 2/10/2026 | OpenSave before 2.4.0-beta.1 fails to validate sender identity in WAN relay requests, allowing unpaired room members to impersonate paired devices by spoofing the RelayMessage From field. Attackers who know the room code can join, read paired peer identifiers from announcements, and send forged requests to access… | |
| Aplazada | Baja (2.1) | 0.25% | — | Os4ed OpensisclassicAI | 30/9/2026 | 30/9/2026 | A weakness has been identified in OS4ED openSIS-Classic up to 9.3. This impacts the function DBQuery of the file functions/GetStuListFnc.php of the component Student List Search Endpoint. This manipulation of the argument LO_sort causes sql injection. The attack can be initiated remotely. The exploit has been made… | |
| Aplazada | Baja (2.1) | 0.25% | — | Os4ed Opensls ClassicAI | 30/9/2026 | 2/10/2026 | A security flaw has been discovered in OS4ED openSIS-Classic up to 9.3. This affects an unknown function of the file functions/CustomFieldsFnc.php of the component Student Search. The manipulation of the argument cust results in sql injection. It is possible to launch the attack remotely. The exploit has been released… | |
| Aplazada | Baja (2.1) | 0.20% | — | Os4ed Opensis-classicAI | 30/9/2026 | 30/9/2026 | A vulnerability was identified in OS4ED openSIS-Classic up to 9.3. The impacted element is the function DBQuery_assignment of the file modules/grades/Assignments.php of the component Assignment Management Endpoint. The manipulation of the argument Tables leads to sql injection. It is possible to initiate the attack… | |
| Aplazada | Baja (2) | 0.33% | — | Os4ed OpensisclassicAI | 30/9/2026 | 1/10/2026 | A vulnerability was determined in OS4ED openSIS-Classic up to 9.3. The affected element is the function save action of the file modules/students/Student.php of the component General Information Tab. Executing a manipulation of the argument students can lead to sql injection. The attack may be performed from remote.… | |
| Pendiente de análisis | Media (6.1) | 0.19% | — | Wikimedia Mediawiki Flow ExtensionAI | 29/9/2026 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Flow Extension allows Stored XSS. This issue affects Mediawiki - Flow Extension: from * before 1.46.1, 1.45.5, 1.43.10. | |
| En análisis | Alta (7.5) | 0.40% | — | OpensslAI | 29/9/2026 | 29/9/2026 | Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID… |