Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

293.912 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ExternaCrítica——Cisco NX OSAICisco Nexus 3000AICisco Nexus 9000AICisco Application Policy Infrastructure ControllerAI+47/10/2026—
Cisco published multiple security advisories on October 7, 2026, addressing critical vulnerabilities across NX-OS Software, Application Policy Infrastructure Controller, and Smart License products. The vulnerabilities include remote code execution flaws in MPLS OAM, NGOAM, and NX-API components, as well as…
ExternaCrítica——Cisco NX OSAICisco Nexus 3000AICisco Nexus 9000AICisco Application Policy Infrastructure ControllerAI+37/10/2026—
Cisco ha publicado múltiples avisos de seguridad el 7 de octubre de 2026 abordando vulnerabilidades críticas en NX-OS, Application Policy Infrastructure Controller, Smart License Manager, Meraki y Finesse. Las vulnerabilidades incluyen ejecución remota de código, inyección de comandos, bypass de autenticación y…
ExternaCrítica——Cisco NX OSAICisco Nexus 3000AICisco Nexus 9000AICisco Application Policy Infrastructure ControllerAI+37/10/2026—
Cisco ha publicado múltiples avisos de seguridad para octubre 2026 incluyendo vulnerabilidades críticas de ejecución remota de código en NX-OS, APIC y Smart License, junto con vulnerabilidades de mediana severidad en productos de infraestructura y licenciamiento. Las vulnerabilidades afectan a componentes clave como…
ExternaCrítica——Cisco NX OSAICisco Nexus 3000AICisco Nexus 9000AICisco Application Policy Infrastructure ControllerAI+37/10/2026—
Cisco publicó un aviso anticipado sobre múltiples vulnerabilidades críticas en productos NX-OS, Application Policy Infrastructure Controller, Smart License Manager, Meraki y Finesse, incluyendo fallos de ejecución remota de código, inyección de comandos y contornos de autenticación. Las vulnerabilidades tienen…
ExternaCrítica——Cisco NX OSAICisco Nexus 3000AICisco Nexus 9000AICisco Application Policy Infrastructure ControllerAI+47/10/2026—
Cisco published a batch of security advisories on October 7, 2026, covering multiple products including NX-OS Software, Application Policy Infrastructure Controller, Smart License Manager, Meraki, and Finesse. The vulnerabilities range from remote code execution, denial of service, sandbox escapes, to contract bypass…
ExternaCrítica——Cisco NX OSAICisco Nexus 3000AICisco Nexus 9000AICisco Application Policy Infrastructure ControllerAI+37/10/2026—
Cisco published multiple security advisories on October 7, 2026, addressing critical vulnerabilities across NX-OS software, Application Policy Infrastructure Controller, and Smart License products. The vulnerabilities include remote code execution flaws in MPLS OAM, NGOAM, and NX-API components, sandbox escape issues,…
ExternaCrítica——Cisco NX OSAICisco Nexus 3000AICisco Nexus 9000AICisco Application Policy Infrastructure ControllerAI+37/10/2026—
Cisco publicó múltiples vulnerabilidades de seguridad en octubre de 2026 afectando NX-OS, APIC, Smart License Manager, Meraki y Finesse, incluyendo ejecución remota de código, inyección de comandos, bypass de contratos y escapes de sandbox. Las vulnerabilidades van desde puntuaciones CVSS de 4.4 a 10.0, requiriendo…
ExternaCrítica——Cisco NX OSAICisco Nexus 3000AICisco Nexus 9000AICisco Application Policy Infrastructure ControllerAI+37/10/2026—
Cisco published multiple security advisories on October 7, 2026, addressing critical and medium-severity vulnerabilities across NX-OS software, Application Policy Infrastructure Controller, Smart Software Manager On-Prem, Meraki, and Finesse products. The vulnerabilities include remote code execution issues in MPLS…
ExternaCrítica——Cisco NX OSAICisco Nexus 3000AICisco Nexus 9000AICisco Application Policy Infrastructure ControllerAI+47/10/2026—
Cisco published multiple security advisories on October 7, 2026, addressing critical and medium severity vulnerabilities across NX-OS Software, Application Policy Infrastructure Controller, Smart License Manager, Meraki, and Finesse products. Vulnerabilities include remote code execution in MPLS OAM, NGOAM, and NX-API…
ExternaCrítica——Cisco NX OSAICisco Nexus 3000AICisco Nexus 9000AICisco Application Policy Infrastructure ControllerAI+37/10/2026—
Cisco published multiple security advisories on October 7, 2026, addressing critical and medium severity vulnerabilities across NX-OS Software, Application Policy Infrastructure Controller, Smart Software Manager On-Prem, Meraki, and Finesse products. Vulnerabilities include remote code execution in MPLS OAM, NGOAM,…
Pendiente de análisisSin puntuar——Iterm2AI7/10/20267/10/2026
An issue in iTerm2 macOS before 3.6.12 allows a local attacker to obtain sensitive information.
AplazadaMedia (6.5)——WgerAI7/10/20267/10/2026
wger is a free, open-source workout and fitness manager. Prior to version 2.6, an authenticated attacker can inject arbitrary workout log entries into any other user's `SlotEntry` by supplying the victim's `slot_entry` ID in a `POST /api/v2/workoutlog/` request. The `slot_entry` foreign key is not included in the…
AplazadaMedia (4.8)——WgerAI7/10/20267/10/2026
wger is a free, open-source workout and fitness manager. Versions prior to 2.6 have a vulnerability in the authentication/session lifecycle of `wger` where bearer-style API credentials remain valid after a user logs out and after a user changes their password. An attacker who steals a victim’s DRF authtoken…
AplazadaAlta (7.1)——WgerAI7/10/20267/10/2026
wger is a free, open-source workout and fitness manager. Prior to version 2.6, a user with only the `gym_trainer` permission can deactivate any account in the same gym, including `gym_manager` and `general_gym_manager` accounts. The `UserDeactivateView` grants access to anyone holding any one of `gym.manage_gym`,…
AplazadaMedia (5.4)——WgerAI7/10/20267/10/2026
wger is a free, open-source workout and fitness manager. Prior to version 2.6, the `trainer_login` view in wger accepts GET requests and executes `django_login()` without any CSRF protection, because Django's `CsrfViewMiddleware` only enforces tokens on unsafe methods (POST/PUT/PATCH/DELETE). An attacker can embed a…
AplazadaAlta (7.1)——WgerAI7/10/20267/10/2026
wger is a free, open-source workout and fitness manager. Prior to version 2.6, five gym management views in wger apply a flawed gym-scope guard (`gym_a != gym_b`) that silently passes when both operands are `None`. A trainer with `gym.gym_trainer` and `gym.add_adminusernote` permissions and no gym assignment…
Pendiente de análisisCrítica (9.2)——Sungrowpower IsolarcloudAI7/10/20267/10/2026
Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading to "local blackouts on the whole continent" in Europe. An email address for the user_account property is required; however, a user can view the email address associated with…
RecibidaAlta (8.6)——Telegram DesktopAI7/10/20267/10/2026
Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the interpret: scheme handler to upload local files, including tdata session keys, to…
RecibidaSin puntuar——Linux KernelAI7/10/20267/10/2026
In the Linux kernel, the following vulnerability has been resolved: tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack() When tcp_send_synack() replaces the cloned SYN skb at the head of the retransmit queue with a copy, it frees the original with tcp_rtx_queue_unlink_and_free() and only repairs…
RecibidaSin puntuar——Linux KernelAI7/10/20267/10/2026
In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: preserve mremap address delta when skipping page tables move_hugetlb_page_tables() optimizes mremap() by advancing to the last entry in the page table when the source page table does not exist, either initially or after unsharing a PMD…
RecibidaAlta (7.4)——Express-gateway Express GatewayAI7/10/20267/10/2026
Express Gateway through 1.16.11 contains a hardcoded cryptographic key vulnerability that allows attackers with datastore access to decrypt stored OAuth 2.0 token secrets via the default crypto.cipherKey 'sensitiveKey'. Attackers who can read Redis can decrypt tokenEncrypted values and combine them with stored token…
RecibidaAlta (7.6)——Express-gateway Express GatewayAI7/10/20267/10/2026
Express Gateway through 1.16.11 contains an authentication bypass vulnerability in the OAuth 2.0 refresh_token grant that fails to validate the token secret or issuing client. Attackers with any valid client credentials and the identifier portion of another user's refresh token can obtain that user's access token and…
Pendiente de análisisMedia (5.9)——Theforeman Smart Proxy DynflowAI7/10/20267/10/2026
Missing authentication has been found in remote-execution task updates in the smart_proxy_dynflow package. The progress and completion callbacks accept a report when the one-time token is missing. A network attacker or user must already know the identifier of a running job. This applies when remote execution is set to…
Pendiente de análisisAlta (7.7)——Anthropic Claude CodeAI7/10/20267/10/2026
Claude Code validated that a target file path resided within the project working directory at permission-check time, but re-resolved the path at write time without repeating that validation. This time-of-check to time-of-use (TOCTOU) gap allowed an attacker who could write to the workspace to atomically replace a…
AplazadaAlta (7.6)——10web Slider WDAI7/10/20267/10/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Slider by 10Web slider-wd allows Blind SQL Injection.This issue affects Slider by 10Web: from n/a through 1.2.63.