Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1025 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (8.1) | — | — | Backstage Plugin-auth-backend-module-oidc-providerAI | 6/10/2026 | 6/10/2026 | Backstage is an open framework for building developer portals. Prior to 0.4.20, the @backstage/plugin-auth-backend-module-oidc-provider package is affected by improper authentication in the oidc provider. Deployments using OIDC email-based identity resolution with a provider that permits unverified email addresses may… | |
| Recibida | Alta (8.5) | — | — | Backstage Plugin Scaffolder Backend Module Bitbucket CloudAIBackstage Plugin Scaffolder Backend Module Bitbucket ServerAI | 6/10/2026 | 6/10/2026 | Backstage is an open framework for building developer portals. Prior to 0.3.10 in @backstage/plugin-scaffolder-backend-module-bitbucket-cloud and 0.2.25 in @backstage/plugin-scaffolder-backend-module-bitbucket-server, the Bitbucket pull-request Scaffolder actions did not sufficiently validate filesystem paths. An… | |
| Recibida | Media (5.4) | — | — | Backstage Plugin Catalog Backend Module GitlabAI | 6/10/2026 | 6/10/2026 | Backstage is an open framework for building developer portals. Prior to 0.8.7, the @backstage/plugin-catalog-backend-module-gitlab package is affected by improper authorization in gitlab organizational user ingestion. Deployments that enable GitLab organization event ingestion and rely on scoped catalog users as an… | |
| Recibida | Alta (8.5) | — | — | Backstage Plugin Scaffolder Backend Module SentryAI | 6/10/2026 | 6/10/2026 | Backstage is an open framework for building developer portals. From 0.3.0 until 0.3.8, the @backstage/plugin-scaffolder-backend-module-sentry package is affected by improper input validation in sentry scaffolder actions. An authenticated internal user who can execute the affected actions may cause the backend to… | |
| Recibida | Media (6.5) | — | — | Backstage Plugin Catalog Backend Module Bitbucket ServerAI | 6/10/2026 | 6/10/2026 | Backstage is an open framework for building developer portals. From 0.4.0 until 0.5.15, the @backstage/plugin-catalog-backend-module-bitbucket-server package is affected by inconsistent repository filtering in bitbucket server catalog event updates. Deployments using event-driven updates in the Bitbucket Server… | |
| Recibida | Media (6.8) | — | — | Backstage Plugin-auth-backend-module-cloudflare-access-providerAI | 6/10/2026 | 6/10/2026 | Backstage is an open framework for building developer portals. From 0.1.0 until 0.5.0, the @backstage/plugin-auth-backend-module-cloudflare-access-provider package is affected by insufficient audience validation in the cloudflare access auth provider. The Cloudflare Access auth provider verifies a token's signature… | |
| Pendiente de análisis | Alta (7.7) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0 contain(s) an Use of Insufficiently Random Values vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information tampering. | |
| Pendiente de análisis | Alta (7.1) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules (CSM), versions prior to 1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-tenant gRPC service (TenantService). An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized creation… | |
| Pendiente de análisis | Crítica (9.6) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Pendiente de análisis | Alta (8.2) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules (CSM) versions prior to 1.18.0, contains an Improper Certificate Validation vulnerability in the proxy-server component. An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to information exposure of storage backend administrator credentials. | |
| Pendiente de análisis | Media (6.1) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authorization vulnerability in the Dell CSI Driver for PowerMax - csireverseproxy . An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Pendiente de análisis | Media (6.5) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Pendiente de análisis | Alta (7.7) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |
| En análisis | Crítica (9.9) | — | — | Dell Container Storage Modules OperatorAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules (CSM) Operator, versions prior to 1.18.0 contains an Improper Privilege Management vulnerability in the ContainerStorageModule Custom Resource reconciler. A low privileged remote attacker could potentially exploit this vulnerability, leading to escalation of privileges and gaining… | |
| En análisis | Crítica (10) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| En análisis | Crítica (10) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-storage gRPC server. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to storage backend… | |
| En análisis | Crítica (9.8) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the CSM Authorization. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| En análisis | Crítica (9.8) | — | — | Dell Container Storage ModulesAI | 6/10/2026 | 6/10/2026 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the csm-docs. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.9.8 | |
| Aplazada | Media (5.9) | 0.19% | — | Supreme Modules LiteAI | 30/9/2026 | 30/9/2026 | Author Cross Site Scripting (XSS) in Supreme Modules Lite <= 2.5.63 versions. | |
| Aplazada | Media (5.9) | 0.17% | — | Mh-developer Smart Home ModuleAI | 28/9/2026 | 28/9/2026 | mH-DEVELOPER smart home module is vulnerable to Denial of Service due to uncontrolled resource consumption. The Express bodyParser is configured with a 250 MB limit for JSON and URL-encoded request bodies. An authenticated attacker on the LAN can send large request bodies that exhausts buffers in RAM, causing… | |
| Aplazada | Media (6.9) | 0.37% | — | Mh-developer Smart Home ModuleAI | 28/9/2026 | 28/9/2026 | mH-DEVELOPER smart home module ships with an end-of-life, unsupported Debian 8 and Node.js runtime v17.0.1 in its production firmware. This exposes the device to publicly known vulnerabilities that will not receive security patches. An attacker could exploit these known flaws to execute arbitrary code, access… | |
| Aplazada | Media (6) | 0.21% | — | Mh-developer Smart Home ModuleAI | 28/9/2026 | 28/9/2026 | mH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP. Passwords, authentication tokens, and device commands are transmitted in cleartext. An attacker on the same network can intercept this traffic, steal credentials and tokens, and hijack sessions. This issue was fixed in… | |
| Aplazada | Media (5.3) | 0.17% | — | Mh-developer Smart Home ModuleAI | 28/9/2026 | 28/9/2026 | mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed on the LAN without access control. Any client on the same network can reach every service. This issue was fixed in version 3.0.30 | |
| Aplazada | Media (6.4) | 0.21% | — | Mh-developer Smart Home ModuleAI | 28/9/2026 | 28/9/2026 | mH-DEVELOPER smart home module does not verify tokens in its authorization middleware, leaving all HTTP API and WebSocket endpoints accessible without authentication. An unauthenticated attacker on the LAN can query these endpoints, access system information, and send raw control commands to manipulate building… | |
| Aplazada | Media (6.3) | 0.24% | — | Mh-developer Smart Home ModuleAI | 28/9/2026 | 28/9/2026 | mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation. An attacker who extracts these keys from the firmware can set up a rogue SSH server that clients will trust without warning, enabling man-in-the-middle attacks and credential interception. This… |