Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
2151 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.56% | — | Mbs-solutions X-serie GatewayAI | 4/9/2026 | 9/9/2026 | An issue in /cgi-bin/wwwugw.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to invoke hidden network diagnostic methods (ugw-ping, ugw-traceroute) that are not exposed in the web UI, allowing attackers to obtain sensitive information. | |
| Aplazada | Media (6.5) | 0.55% | — | Mbs-solutions X-serie GatewayAI | 4/9/2026 | 8/9/2026 | An arbitrary file read vulnerability in /cgi-bin/ugwdownload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to retrieve arbitrary files from the device filesystem via the file query string parameter. | |
| Aplazada | Media (6.5) | 0.45% | — | Mbs-solutions X-serie GatewayAI | 4/9/2026 | 8/9/2026 | An information disclosure vulnerability in the ugw-deviceinfo method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 returns detailed system version fields (operatingsystem, gatewayversion) to any authenticated user, including users with the low-privileged Standard role. | |
| Aplazada | Media (6.5) | 0.65% | — | Mbs-solutions X-serie GatewayAI | 4/9/2026 | 9/9/2026 | An information disclosure vulnerability in the opcua-configuration method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows any remote authenticated user, including users with the low-privileged Standard role, to retrieve the configured OPC-UA authentication credentials in cleartext via… | |
| Aplazada | Alta (8.8) | 0.77% | — | Mbs-solutions X-serie GatewayAI | 4/9/2026 | 9/9/2026 | An issue in the ugw-restart method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to inject arbitrary code into the dpcheck system utility executed as root. | |
| Aplazada | Crítica (9.1) | 0.60% | — | Citrix Gateway FirmwareAI | 4/9/2026 | 8/9/2026 | An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi. | |
| Aplazada | Media (5.3) | 0.16% | — | Epayco Payment GatewayAI | 4/9/2026 | 8/9/2026 | The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders as paid without a valid gateway signature. | |
| Analizada | Alta (8.4) | 0.22% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+4 | 3/9/2026 | 9/9/2026 | The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely. Successful exploitation enables a threat actor with administrative privileges and Carbon… | |
| Aplazada | Alta (8.6) | 0.64% | — | Seppmail Secure Email GatewayAI | 3/9/2026 | 4/9/2026 | SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges. | |
| Aplazada | Alta (7.7) | 0.47% | — | Seppmail Secure Email GatewayAI | 3/9/2026 | 3/9/2026 | SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access protected functionality without providing a second factor. | |
| Aplazada | Alta (8.6) | 1.2% | — | Seppmail Secure Email GatewayAI | 3/9/2026 | 3/9/2026 | SEPPmail Secure Email Gateway before 15.0.7 contains a command injection vulnerability that allows authenticated administrators to execute commands with elevated privileges. | |
| Pendiente de análisis | Alta (8.6) | 0.57% | — | Nginx PlusAINginx Gateway FabricAI | 2/9/2026 | 3/9/2026 | Description: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the Authentication Filter Custom Resource Definition clientID or cookieName fields, or in the… | |
| Analizada | Baja (2.3) | 0.23% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 2/9/2026 | 15/9/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session.… | |
| Aplazada | Alta (8.7) | 0.48% | — | Portkey AI GatewayAI | 28/8/2026 | 24/9/2026 | Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1/proxy/* route that lacks requestValidator middleware. Attackers can set the x-portkey-custom-host header to internal addresses and forward requests with Authorization headers to reach internal services and exfiltrate… | |
| Aplazada | Crítica (9.8) | 0.43% | — | Grpc-gatewayAI | 28/8/2026 | 8/9/2026 | grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-www-form-urlencoded includes this header, the request method is rewritten to an… | |
| Aplazada | Alta (7.2) | 0.37% | — | Ebyte GatewayAI | 28/8/2026 | 31/8/2026 | Ebyte gateway product's vendor configuration utility does not require authentication before allowing certain disruptive administrative actions when default credentials remain configured. An unauthenticated attacker on the adjacent network could reboot the device or restore factory settings, resulting in a loss of… | |
| Aplazada | Crítica (9.3) | 0.65% | — | Ebyte GatewayAI | 28/8/2026 | 31/8/2026 | An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication tokens used by the web management interface are insufficiently protected during client-side session handling, which may allow an attacker with access to exposed session information to obtain and reuse… | |
| Aplazada | Alta (8.7) | 0.22% | — | Ebyte GatewayAI | 28/8/2026 | 31/8/2026 | A cleartext transmission of sensitive information vulnerability exists in certain Ebyte gateway products. The web management interface does not adequately protect sensitive communications using transport-layer encryption. An attacker with access to network traffic could intercept authentication or session-related… | |
| Pendiente de análisis | Alta (8.1) | 0.37% | — | CephAICeph Object GatewayAI | 28/8/2026 | 8/9/2026 | Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Ceph Object Gateway (RGW) SigV4 handler does not reject requests that carry x-amz-* headers absent from the signed header set, allowing anyone holding a presigned URL to attach… | |
| Pendiente de análisis | Alta (8.8) | 0.29% | — | CephAICeph Rados GatewayAI | 28/8/2026 | 8/9/2026 | Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the RADOS Gateway (RGW) protects STS session tokens with an AES-128-CBC handler that provides no message authentication, allowing an attacker who holds any valid STS token to tamper… | |
| Pendiente de análisis | Alta (8.2) | 0.22% | — | Gitlab AI GatewayAI | 27/8/2026 | 28/8/2026 | GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.9.0 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2 that could have allowed an authenticated user with Duo Agent Platform access to redirect model requests to an externally-controlled endpoint via… | |
| Aplazada | Media (6.9) | 0.37% | — | Openfaas GatewayAI | 27/8/2026 | 24/9/2026 | The OpenFaaS gateway registers GET /system/telemetry in gateway/main.go and, when basic_auth is enabled, wraps each administrative /system/* handler in auth.DecorateWithBasicAuth. TelemetryHandler was left out of that wrap block from 0.27.11, which introduced the route, until 0.27.14, which added it. On an affected… | |
| Analizada | Alta (8.7) | 0.33% | — | Vmware Spring Cloud Gateway | 27/8/2026 | 10/9/2026 | Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 5.0.0 - 5.0.2 Spring Cloud Gateway 4.3.0 - 4.3.5 Spring Cloud Gateway 4.0.0 - 4.2.9 Spring Cloud Gateway 3.1.13 and earlier | |
| Aplazada | Media (5.3) | 0.33% | — | Conekta Payment GatewayAI | 22/8/2026 | 26/8/2026 | The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway webhook notifications, nor bind the confirmed payment to the targeted order or verify its amount, allowing unauthenticated attackers to mark arbitrary orders as paid without payment. | |
| Pendiente de análisis | Alta (7.7) | 0.40% | — | Tensorzero GatewayAI | 21/8/2026 | 11/9/2026 | TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026.6.0, the TensorZero Gateway /internal/object_storage endpoint accepts a caller-supplied JSON storage_path parameter that dynamically overrides the [object_storage]… |