Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2963▼ 120 respecto a la semana anterior
Críticas / altas1404▲ 47 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1797 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (6.9) | — | — | Wolfssl WolfsshAI | 7/10/2026 | 7/10/2026 | src/internal.c in wolfSSL wolfSSH through 1.5.0 admits the server-to-client Diffie-Hellman group exchange messages SSH_MSG_KEX_DH_GEX_GROUP (31) and SSH_MSG_KEX_DH_GEX_REPLY (33) when a server receives them from an unauthenticated client. IsMessageAllowedServer() applies no direction check to the key exchange message… | |
| Recibida | Media (5.3) | — | — | Wolfssl WolfsshAI | 7/10/2026 | 7/10/2026 | Unsigned integer underflow in wstrncat() in src/port.c in wolfSSL wolfSSH from v1.4.11 through v1.5.0 on non-Windows platforms allows an authenticated remote attacker to write one out-of-bounds null byte past the end of a stack buffer by sending a crafted SFTP path. wolfSSH_RealPath() in src/ssh.c appends each path… | |
| Recibida | Alta (7.7) | — | — | Wolfssl WolfsshAI | 7/10/2026 | 7/10/2026 | When password or public key authentication is used with the Windows port of wolfSSHd, the Windows logon token acquired for one authenticated connection is not released before a token is acquired for a subsequent connection, resulting in user login poisoning between connections. A less privileged user with a valid… | |
| Recibida | Media (6.3) | — | — | WolfsshAI | 7/10/2026 | 7/10/2026 | In wolfSSH through 1.5.0 built with --enable-fwd, DoChannelOpen() in src/internal.c gates only direct-tcpip channel opens with the forwarding policy callback. forwarded-tcpip opens are admitted without an authorization check and are not capped in number, allowing a malicious SSH peer to make an endpoint allocate… | |
| Recibida | Crítica (9) | — | — | Wolfssl WolfsshAI | 7/10/2026 | 7/10/2026 | wolfSSH does not validate that the ECDSA curve identifier in a KEXDH_REPLY host key blob matches the algorithm negotiated during key exchange. In ParseECCPubKey() (src/internal.c), the blob's algorithm string is used to derive the curve via NameToId/wcPrimeForId without checking against the negotiated… | |
| Aplazada | Crítica (9.3) | 0.38% | — | Fs-code BookneticAI | 6/10/2026 | 6/10/2026 | Unauthenticated SQL Injection in Booknetic <= 4.8.5 versions. | |
| Pendiente de análisis | Alta (7.5) | 0.13% | — | AMD Zynq Ultrascale Plus MpsocAIAMD RfsocAI | 5/10/2026 | 6/10/2026 | Insufficient boundary validation in the USB boot mode implementation of AMD Zynq™ UltraScale+ MPSoC and RFSoC devices could allow unbounded Device Firmware Upgrade (DFU) download requests to overflow the DDR receive buffer into FSBL memory, potentially resulting in unauthorized code execution during the boot process.… | |
| Aplazada | Alta (8.8) | 0.32% | — | FsspecAI | 2/10/2026 | 5/10/2026 | fsspec is a specification and Python implementation framework for filesystem interfaces. From 0.9.0 until 2026.6.0, fsspec.implementations.reference.ReferenceFileSystem evaluates fields from Kerchunk reference JSON documents through unrestricted jinja2.Template(...).render(...) calls in… | |
| Aplazada | Media (5.6) | 0.12% | — | Johnsoncontrols Easyio Fs32AI | 1/10/2026 | 2/10/2026 | - External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack. This issue affects EasyIO FS32: before 3.0b63. | |
| Aplazada | Alta (7.2) | 0.68% | — | Johnsoncontrols Easyio Fs32AI | 1/10/2026 | 2/10/2026 | - OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection. This issue affects EasyIO FS32: before 3.0b63. | |
| Aplazada | Crítica (9.3) | 0.29% | — | Johnsoncontrols Easyio Fs32AI | 1/10/2026 | 2/10/2026 | : Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data. This issue affects EasyIO FS32: before 3.0b63. | |
| Aplazada | Media (5.6) | 0.15% | — | Johnsoncontrols Easyio Fs32AI | 1/10/2026 | 2/10/2026 | : Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse. This issue affects EasyIO FS32: before 3.0b63. | |
| Aplazada | Alta (7.2) | 0.24% | — | Johnsoncontrols Easyio Fs32AI | 1/10/2026 | 2/10/2026 | - On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations. This issue affects EasyIO FS32: before 3.3b63. | |
| Aplazada | Media (5.6) | 0.43% | — | Johnsoncontrols Easyio Fs32AI | 1/10/2026 | 2/10/2026 | - OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows - Command Injection. This issue affects EasyIO FS32: before 3.0b63. | |
| Aplazada | Media (5) | 0.14% | — | Johnsoncontrols Easyio Fs32AI | 1/10/2026 | 2/10/2026 | : Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials. This issue affects EasyIO FS32: before 3.0b63. | |
| Pendiente de análisis | Media (6.9) | 0.43% | — | Amazon EFS CSI DriverAI | 1/10/2026 | 2/10/2026 | Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) v3.1.0 through v3.4.2 might allow remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma-separated values in the mounttargetipmap… | |
| Aplazada | Media (5.5) | 0.39% | — | Modsetter SurfsenseAI | 29/9/2026 | 1/10/2026 | A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknown function of the file surfsense_backend/app/routes/circleback_webhook_route.py of the component circleback Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The… | |
| Aplazada | Baja (2.1) | 0.23% | — | Modsetter SurfsenseAI | 29/9/2026 | 29/9/2026 | A security flaw has been discovered in MODSetter SurfSense up to 0.0.36. Impacted is an unknown function of the file surfsense_backend/app/routes/editor_routes.py of the component Document Export Feature. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The… | |
| Aplazada | Baja (2.1) | 1.2% | — | Modsetter SurfsenseAI | 29/9/2026 | 29/9/2026 | A vulnerability was identified in MODSetter SurfSense up to 2.0.3. This issue affects some unknown processing of the file /api/search-source/connectors/mcp/test of the component MCP Connector Integration. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit is… | |
| Analizada | Baja (2.3) | 0.15% | — | Wolfssl | 27/9/2026 | 29/9/2026 | When an application enables both OCSP and CRL revocation checking on one WOLFSSL_CTX or certificate manager, wolfSSL skips the CRL check for any peer certificate that carries no Authority Information Access OCSP URL, and accepts a certificate the loaded CRL lists as revoked. The soft-fail policy for a missing… | |
| Analizada | Media (6.3) | 0.15% | — | Wolfssl | 27/9/2026 | 2/10/2026 | A (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange. No master secret has been derived at that point, so the client installs read keys derived from a known (deterministic) key and checks the server's Finished against that same key. An out-of-order ChangeCipherSpec can… | |
| Analizada | Alta (8.3) | 0.20% | — | Wolfssl | 27/9/2026 | 2/10/2026 | MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any that enable the macro WOLFSSL_TRUST_PEER_CERT and load CA certificates with wolfSSL_CTX_trust_peer_cert() or wolfSSL_trust_peer_cert(). The peer must know the certificates being loaded to either of… | |
| Analizada | Media (6.3) | 0.15% | — | Wolfssl | 27/9/2026 | 2/10/2026 | A failed X509_verify_cert call permanently plants an unverified attacker CA in the shared CertManager, bypassing certificate validation in every type-blind sibling consumer (native TLS, OCSP, CRL, direct CM verify). This affects version 5.8.4 through 5.9.2 of wolfSSL with the macros (OPENSSL_EXTRA && !NO_CERTS &&… | |
| Analizada | Media (6.3) | 0.16% | — | Wolfssl | 27/9/2026 | 2/10/2026 | A certificate with no dNSName SAN but another SAN type present (e.g. registeredID or iPAddress) bypassed the Subject CN dNSName name-constraint check. The CN-as-DNS fallback was gated on cert->subjectCN != NULL && cert->altNames == NULL && !cert->isCA instead of "no dNSName SAN", so an out-of-scope CN was accepted.… | |
| Analizada | Media (6.3) | 0.12% | — | Wolfssl | 27/9/2026 | 2/10/2026 | wolfSSL versions 5.9.2 and earlier contain a flaw in the X.509 certificate validation logic where it fails to properly enforce NameConstraints extensions when there is an unconstrained CA tier between a name-constrained intermediate CA and the leaf certificate. wolfSSL incorrectly accepted certificates for hostnames… |