Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
23.370 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (6.5) | — | — | Pulpproject Pulp AnsibleAI | 7/10/2026 | 7/10/2026 | A flaw was found in pulp-ansible's bearer-token refresh for collection remotes. The access token is kept in one module-level variable and reused for every token download in that worker. A user who can sync an Ansible remote that uses token refresh, and can point that remote at a server they control, receives an access… | |
| Recibida | Alta (8.1) | — | — | Candlepinproject CandlepinAI | 7/10/2026 | 7/10/2026 | A flaw was found in Candlepin. The central authorization filter incorrectly grants access when any one of multiple @Verify-annotated parameters is accessible, instead of requiring access to every verified entity. A low-privilege authenticated attacker who can access the first referenced object can bypass authorization… | |
| En análisis | Baja (2.1) | — | — | Vllm-project VllmAI | 6/10/2026 | 6/10/2026 | A security flaw has been discovered in vllm-project vLLM up to 0.31.0. This impacts the function get_token_bin_counts_and_mask of the file vllm/model_executor/layers/utils.py of the component Penalty Handler. Performing a manipulation results in denial of service. Remote exploitation of the attack is possible. The… | |
| Aplazada | Baja (2.1) | 0.30% | — | Vllm-project VllmAI | 6/10/2026 | 6/10/2026 | A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function conv_ssm_forward of the file vllm/model_executor/layers/mamba/mamba_mixer2.py of the component Completions Request Handler. The manipulation leads to out-of-bounds read. The attack is possible to be carried out… | |
| Aplazada | Baja (2) | 0.20% | — | Code-projects Human Resource Management SystemAI | 5/10/2026 | 6/10/2026 | A vulnerability was found in code-projects Human Resource Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /views/admin/liveEventHistory.php of the component Live Event History. The manipulation of the argument eventSubject results in cross site scripting. The attack may be… | |
| Aplazada | Baja (2) | 0.20% | — | Code-projects Human Resource ManagementAI | 4/10/2026 | 6/10/2026 | A flaw has been found in code-projects Human Resource Management 1.0. This affects an unknown part of the file /humanresourcemanagementsystem/src/store/EventStore.php of the component Event Creation. Executing a manipulation of the argument eventSubject can lead to cross site scripting. The attack may be launched… | |
| Aplazada | Alta (7.1) | 0.22% | 💥 PoC | PhprojectAI | 2/10/2026 | 6/10/2026 | Phproject before 1.8.7 contains a missing object-level authorization vulnerability in the REST API issue endpoints (single_get, single_comments, single_comments_post) that allows authenticated API key holders to bypass the security.restrict_access confidentiality control by never invoking the allowAccess()… | |
| Aplazada | Media (6.2) | 0.21% | — | Mobyproject BuildkitAI | 2/10/2026 | 2/10/2026 | The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in a SQL query, allowing a Contributor to inject SQL that runs against the database once the resulting content is published and viewed by any unauthenticated… | |
| Pendiente de análisis | Crítica (9) | 0.38% | — | 389project 389 DS BaseAI | 1/10/2026 | 2/10/2026 | A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's… | |
| Pendiente de análisis | Media (4.4) | 0.09% | — | Zephyrproject ZephyrAI | 1/10/2026 | 2/10/2026 | The SMBus driver API exposed smbus_smbalert_remove_cb() and smbus_host_notify_remove_cb() as Zephyr syscalls. Their verifiers in drivers/smbus/smbus_handlers.c validated only the dev argument with K_SYSCALL_OBJ(dev, K_OBJ_DRIVER_SMBUS) and forwarded the caller-supplied struct smbus_callback *cb pointer into… | |
| Aplazada | Media (6.3) | 0.25% | — | Wedevs WP Project ManagerAI | 1/10/2026 | 1/10/2026 | Subscriber Broken Access Control in WP Project Manager <= 4.0.7 versions. | |
| Analizada | Media (6.5) | 0.33% | — | Tnef Project Tnef | 1/10/2026 | 5/10/2026 | A flaw was found in tnef. A heap-based buffer overflow can occur in the find_free_number() function when generating numbered backup suffixes for duplicate filenames. When numbered backups are enabled and file overwriting is disabled, an attacker can supply a specially crafted Transport Neutral Encapsulation Format… | |
| Analizada | Media (6.5) | 0.28% | — | Tnef Project Tnef | 1/10/2026 | 5/10/2026 | A flaw was found in tnef. A remote attacker could exploit this vulnerability by providing a specially crafted Transport Neutral Encapsulation Format (TNEF) file containing multiple message bodies. During extraction, improper memory management triggers a use-after-free and double-free condition, causing the application… | |
| Analizada | Alta (8.1) | 0.24% | — | Tnef Project Tnef | 1/10/2026 | 5/10/2026 | A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input buffer boundaries before copying data in get_rtf_data_from_buf(), reading beyond the allocated memory… | |
| Analizada | Alta (8.7) | 0.34% | — | Pypdf Project Pypdf | 30/9/2026 | 5/10/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF can provide unusually large alphabetical page-label values that cause pypdf/_page_labels.py to generate strings beyond a reasonable page-label length when an application retrieves document page labels, consuming excessive memory… | |
| Analizada | Alta (8.7) | 0.34% | — | Pypdf Project Pypdf | 30/9/2026 | 5/10/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF containing many embedded files can cause the dictionary-based attachments API in pypdf/_doc_common.py to reparse the full attachment list for each content lookup, producing repeated work and long runtimes when an application… | |
| Analizada | Alta (8.7) | 0.34% | — | Pypdf Project Pypdf | 30/9/2026 | 5/10/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF with form field values can cause pypdf/generic/_appearance_stream.py appearance-stream generation to repeat invariant selection-data work inside a loop when an application updates fields with flattening enabled, resulting in… | |
| Analizada | Alta (8.7) | 0.34% | — | Pypdf Project Pypdf | 30/9/2026 | 5/10/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF containing a partially malformed /FlateDecode stream with padded data can force pypdf/filters.py to use inefficient byte-by-byte decompression while the earlier recovery counter fails to advance for bytes that successfully decode,… | |
| Analizada | Alta (8.7) | 0.34% | — | Pypdf Project Pypdf | 30/9/2026 | 5/10/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can provide a TrueType or Type1 simple font with an unusually large /Widths array, causing pypdf/_font.py Font._collect_tt_t1_character_widths to process entries beyond the 256 character codes meaningful for a simple font and… | |
| Analizada | Alta (8.7) | 0.34% | — | Pypdf Project Pypdf | 30/9/2026 | 5/10/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can place unusually large source-code or destination-string tokens in a font /ToUnicode mapping, causing pypdf/_cmap.py parse_bfchar to decode and retain oversized values during operations such as text extraction and consume… | |
| Analizada | Alta (8.7) | 0.34% | — | Pypdf Project Pypdf | 30/9/2026 | 5/10/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.18.0, a crafted PDF containing indirect-object identifiers or generation-number tokens that continue for a long time without whitespace can cause pypdf/_reader.py and pypdf/generic/_base.py to scan excessive input through read_until_whitespace,… | |
| Analizada | Alta (8.7) | 0.35% | — | Pypdf Project Pypdf | 30/9/2026 | 2/10/2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and… | |
| Pendiente de análisis | Media (6.3) | 0.37% | — | Palletsprojects WerkzeugAI | 29/9/2026 | 30/9/2026 | Werkzeug is a comprehensive WSGI web application library. Prior to 3.1.9, the safe_join function used by send_from_directory can allow a NUL: special-device path because safe_join checks the Windows device name without first removing an empty NTFS ADS marker. The trigger is that an application runs on Windows with… | |
| En análisis | Media (5.9) | 0.25% | — | Zephyrproject ZephyrAI | 28/9/2026 | 30/9/2026 | parse_write_op() in subsys/net/lib/lwm2m/lwm2m_message_handling.c handles inbound CoAP WRITE/CREATE requests that carry a Block1 option. For the first block of a transfer it called init_block_ctx() and then immediately stored the peer-selected block size with block_ctx->ctx.block_size = block_size before inspecting… | |
| En análisis | Media (6.5) | 0.18% | — | Zephyrproject ZephyrAI | 28/9/2026 | 30/9/2026 | The native BSD-socket layer recorded a pending asynchronous socket error by type-punning it into struct net_context's void user_data field (ctx->user_data = INT_TO_POINTER(-status) in zsock_accepted_cb(), zsock_received_cb(), zsock_connected_cb() and zsock_close_ctx() in subsys/net/lib/sockets/sockets_inet.c), reading… |