Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
21.613 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.3) | 0.16% | — | Midnightbsd MportAI | 17/9/2026 | 24/9/2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, ping() in libmport/ping.c accepted ICMP replies without validating icmp_id or icmp_seq and parsed the reply using a fixed IP-header offset instead of ip_hl. A network attacker able to inject or spoof visible ICMP replies could influence mirror latency… | |
| Aplazada | Baja (2) | 0.11% | — | Midnightbsd MportAI | 17/9/2026 | 18/9/2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, mport_verify_package() in libmport/verify.c could continue after MD5File() or SHA256_File() failed and compare an expected checksum with stale data in the hash buffer rather than a newly computed digest. An attacker able to influence an installed file or the… | |
| Aplazada | Baja (2) | 0.16% | — | Midnightbsd MportAI | 17/9/2026 | 24/9/2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, the audit command in mport/mport.c computed option-adjusted local_argv and local_argc values but passed the original argument entry to audit_package(). When an operator or automation used an option such as -r before a package name, stale optind state and the… | |
| Aplazada | Media (5.8) | 0.10% | — | Midnightbsd MportAI | 17/9/2026 | 18/9/2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_install() in libmport/bundle_read_install_pkg.c used path-based lstat(), chown(), stat(), and chmod() operations while installing package files. A local attacker with write access to a target directory could replace a checked file with a symlink… | |
| Aplazada | Media (5.8) | 0.12% | — | Midnightbsd MportAI | 17/9/2026 | 21/9/2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, privileged package fetch and cache-cleaning operations used race-prone path handling across libmport/fetch.c, libmport/clean.c, libmport/util.c, libmport/bundle_read_install_pkg.c, libmport/delete_primative.c, and libexec/mport.create/mport.create.c. A local… | |
| Aplazada | Media (5.3) | 0.51% | — | Infiniflow RagflowAI | 17/9/2026 | 21/9/2026 | RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints that allows authenticated attackers to read arbitrary files by supplying absolute file paths in the file_path parameter. Attackers with valid access tokens can exploit missing… | |
| Pendiente de análisis | Media (6.5) | 0.51% | — | SanicAI | 17/9/2026 | 30/9/2026 | Sanic is an opensource python web server/framework. In version 25.12.0, Sanic's core HTTP/1.1 chunked-body handling does not fully consume the trailer-part after the terminating zero chunk before reusing the keep-alive connection buffer. A remote unauthenticated client can place attacker-controlled bytes in that… | |
| Pendiente de análisis | Alta (8.2) | 0.48% | — | SanicAI | 17/9/2026 | 24/9/2026 | Sanic is an opensource python web server/framework. Prior to version 24.12.1, and in version 25.12.0, the HTTP/1.1 response pipeline in sanic/response/types.py serializes response header names and values without rejecting carriage-return or line-feed characters. Applications that place attacker-controlled data in… | |
| Analizada | Media (6.8) | 0.13% | — | Dell Openmanage Server Administrator | 17/9/2026 | 6/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering. | |
| Analizada | Alta (7.4) | 0.37% | — | Dell Openmanage Server Administrator | 17/9/2026 | 6/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. | |
| Analizada | Alta (7.2) | 0.46% | — | Dell Openmanage Server Administrator | 17/9/2026 | 6/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (7.3) | 0.14% | — | Dell Openmanage Server Administrator | 17/9/2026 | 6/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. | |
| Aplazada | Crítica (9.1) | 0.91% | — | Team-alembic ASH Authentication PhoenixAIAlembic ASH AuthenticationAI | 17/9/2026 | 18/9/2026 | Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated. A resource configured with session_identifier :jti and require_token_presence_for_authentication? disabled stores its session value as <jti>:<subject>.… | |
| Aplazada | Alta (7.2) | 0.21% | — | Team-alembic ASH Authentication PhoenixAIAlembic ASH AuthenticationAI | 17/9/2026 | 18/9/2026 | Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to recover a single-use sign-in token and authenticate as its owner. After a successful password sign-in,… | |
| Analizada | Media (6.5) | 0.45% | — | Dell Openmanage Server Administrator | 17/9/2026 | 6/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. | |
| Analizada | Media (6.4) | 0.23% | — | Dell Openmanage Server Administrator | 17/9/2026 | 6/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. | |
| Analizada | Alta (8.1) | 0.38% | — | Dell Openmanage Server Administrator | 17/9/2026 | 6/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Unauthorized access. | |
| Analizada | Media (5.4) | 0.21% | — | Dell Openmanage Server Administrator | 17/9/2026 | 6/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. | |
| Pendiente de análisis | Media (5.3) | 0.23% | — | Openstack IronicAI | 17/9/2026 | 18/9/2026 | In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and significantly increases its complexity. | |
| Analizada | Alta (7.5) | 0.53% | — | Dell Openmanage Server Administrator | 17/9/2026 | 2/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. | |
| Analizada | Alta (7.2) | 0.62% | — | Dell Openmanage Server Administrator | 17/9/2026 | 2/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Stack-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. | |
| Analizada | Media (5.5) | 0.17% | — | Dell Openmanage Server Administrator | 17/9/2026 | 2/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service. | |
| Analizada | Crítica (9.8) | 0.29% | — | Dell Openmanage Server Administrator | 17/9/2026 | 6/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analizada | Alta (7.2) | 0.62% | — | Dell Openmanage Server Administrator | 17/9/2026 | 6/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. | |
| Analizada | Crítica (9.8) | 0.95% | — | Dell Openmanage Server Administrator | 17/9/2026 | 1/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |