Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
294.004 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.8) | 0.53% | — | HPE Clearpass Policy ManagerAI | 6/10/2026 | 7/10/2026 | Deserialization of untrusted data vulnerabilities exist in the web interface of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code on the affected system. | |
| Pendiente de análisis | Media (5.5) | 0.23% | — | Kubernetes Cri-oAI | 6/10/2026 | 7/10/2026 | A flaw was found in CRI-O's `bind_mount_prefix` handling. When configured with a non-empty `bind_mount_prefix`, a malicious container or local attacker could use a Container Runtime Interface (CRI) hostPath containing an intermediate absolute symlink. This could cause the bind mount source to resolve outside the… | |
| Pendiente de análisis | Alta (8.9) | 0.40% | — | Peteroupc CborAI | 6/10/2026 | 7/10/2026 | StableLib is a stable library of useful TypeScript and JavaScript code. Prior to 2.0.4, the @stablelib/cbor CBOR map decoding path creates ordinary JavaScript objects and assigns attacker-controlled keys with bracket assignment. A map key named __proto__ invokes the inherited prototype setter instead of creating an… | |
| Pendiente de análisis | Crítica (9.8) | 0.64% | — | Handlebarsjs HandlebarsAI | 6/10/2026 | 7/10/2026 | Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.compile() and Handlebars.precompile() accept pre-parsed AST objects while validating only selected PathExpression, NumberLiteral, and BooleanLiteral values. This issue bypasses the AST validation… | |
| Pendiente de análisis | Crítica (9.2) | 0.41% | — | Handlebarsjs HandlebarsAI | 6/10/2026 | 7/10/2026 | Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars lookupProperty returns Function.prototype.constructor before applying the prototype-access deny list because constructor is an own property of Function.prototype. When an attacker can render a controlled… | |
| Pendiente de análisis | Media (4.7) | 0.29% | — | Handlebarsjs HandlebarsAI | 6/10/2026 | 7/10/2026 | Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.precompile() uses quotedString() in lib/handlebars/compiler/code-gen.js to emit static template text into generated JavaScript without escaping sequences that terminate an enclosing HTML script element.… | |
| Pendiente de análisis | Alta (7.1) | 0.24% | — | ElasticsearchAI | 6/10/2026 | 7/10/2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Elasticsearch can lead to Information Disclosure via a specially crafted cross-cluster search request that references an unauthorized shard identifier. Elasticsearch contains an authorization bypass weakness in its handling of cross-cluster search requests… | |
| Pendiente de análisis | Media (6.5) | 0.30% | — | ElasticsearchAI | 6/10/2026 | 7/10/2026 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted request that causes the server to construct and process a deeply nested data structure with no bound on recursion depth. Elasticsearch contains an uncontrolled recursion weakness in how it builds and serializes… | |
| Pendiente de análisis | Alta (7.2) | 0.34% | — | ElasticsearchAI | 6/10/2026 | 7/10/2026 | Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a delegated administrative privilege whose scope is not fully enforced during authorization checks. Elasticsearch contains an incorrect authorization weakness in a configurable, non-default privilege that lets an administrator… | |
| Pendiente de análisis | Media (6.5) | 0.40% | — | ElasticsearchAI | 6/10/2026 | 7/10/2026 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted, deeply nested request submitted to the aggregation feature of the search API. Elasticsearch contains an uncontrolled recursion weakness in its search aggregation processing. An authenticated user with read access… | |
| Pendiente de análisis | Media (6.5) | 0.30% | — | ElasticsearchAI | 6/10/2026 | 7/10/2026 | Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with connector management privileges could cause the cluster to allocate an uncontrolled amount of memory when connector resources with an excessively large… | |
| Pendiente de análisis | Media (6.5) | 0.30% | — | ElasticsearchAI | 6/10/2026 | 7/10/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to Denial of Service via Excessive Allocation (CAPEC-130). Elasticsearch enforces a size limit on the user-supplied metadata field for each individual template resource, but does not limit the total memory used when multiple such… | |
| Pendiente de análisis | Media (6.5) | 0.30% | — | ElasticsearchAI | 6/10/2026 | 7/10/2026 | Uncontrolled Recursion (CWE-674) in Elasticsearch can allow an authenticated user with low privileges to terminate an Elasticsearch node, resulting in denial of service, via Excessive Allocation (CAPEC-130). | |
| Pendiente de análisis | Media (4.3) | 0.34% | — | ElasticsearchAI | 6/10/2026 | 7/10/2026 | Inefficient Regular Expression Complexity (CWE-1333) in Elasticsearch can lead to denial of service via Regular Expression Exponential Blowup (CAPEC-492). The ES|QL CHUNK function's recursive chunking strategy accepts a list of user-supplied regular expressions used as text-splitting separators, without validating… | |
| Pendiente de análisis | Media (5.4) | 0.22% | — | ElasticsearchAI | 6/10/2026 | 7/10/2026 | Incorrect Authorization (CWE-863) in Elasticsearch can lead to unauthorized data stream modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user with sufficient privileges over a single resource could use the Modify Data Streams API to modify a data stream to which… | |
| Pendiente de análisis | Media (6.5) | 0.30% | — | ElasticsearchAI | 6/10/2026 | 7/10/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can submit a specially crafted query that causes uncontrolled memory growth in the query processing engine, resulting in an out-of-memory condition that… | |
| Pendiente de análisis | Alta (7.1) | 0.28% | — | Arista WI FI Access PointAI | 6/10/2026 | 7/10/2026 | On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a captive-portal-enabled SSID can crash the portal service with a crafted HTTP request. The service automatically restarts, but a sustained low-rate attack can cause a persistent denial of service of the… | |
| Pendiente de análisis | Alta (7.1) | 0.28% | — | Arista Wi-fi Access PointAI | 6/10/2026 | 7/10/2026 | On affected Arista Wi-Fi access points with Captive Portal enabled, an unauthenticated wireless client connected to a Captive-Portal-enabled SSID can crash the portal service with a crafted HTTP request. This results in a temporary denial of service until the service automatically restarts. Remote code execution is… | |
| Pendiente de análisis | Crítica (9) | 0.23% | — | Arista WI FI Access PointAI | 6/10/2026 | 7/10/2026 | On affected Arista Wi-Fi access points, a memory corruption vulnerability exists in access point's wired uplink network endpoints. An unauthenticated attacker can crash the sensor service or potentially achieve remote code execution. Exploitation requires the attacker to be on the same network segment as the access… | |
| Pendiente de análisis | Alta (7.7) | 0.24% | — | Arista WI FI Access PointAI | 6/10/2026 | 7/10/2026 | On affected Arista Wi-Fi access points, an unauthenticated attacker with network access to the capture service can send a crafted packet to cause the service to crash or potentially achieve remote code execution. This exploit requires an uncommonly used non-default streaming mode. | |
| Pendiente de análisis | Baja (2.3) | 0.19% | — | Arista Access PointAI | 6/10/2026 | 7/10/2026 | On affected Arista access points configured with VXLAN tunnelling and L2-proxy (a specific configuration unique to the VESPA use-case), a wireless client associated to the tunnelled SSID can send a crafted packet, causing the access point to reveal memory contents in network traffic. No write primitive or remote code… | |
| Pendiente de análisis | Alta (8.7) | 0.31% | — | Arista Access PointAI | 6/10/2026 | 7/10/2026 | On affected Arista access points with Wireless Intrusion Prevention System (WIPS) active, an unauthenticated attacker within radio frequency (RF) proximity can send a crafted frame to crash the sensor service, disabling WIPS monitoring on the access point, or potentially achieve remote code execution. No wireless… | |
| Pendiente de análisis | Crítica (9.4) | 0.25% | — | Arista Wi-fi Access PointsAI | 6/10/2026 | 7/10/2026 | On affected Arista Wi-Fi access points with captive portal, or application firewall enabled on at least one SSID, a vulnerability in the wireless gateway service could allow an unauthenticated network-adjacent attacker to send a crafted packet that triggers a stack overflow, resulting in a denial-of-service condition… | |
| Pendiente de análisis | Alta (8.6) | 1.4% | — | Arista Cloudvision CUEAI | 6/10/2026 | 7/10/2026 | An operating system (OS) command injection vulnerability in CloudVision CUE backup management may allow an authenticated Super User to submit a crafted backup request and execute arbitrary commands with the privileges of the affected service. | |
| Pendiente de análisis | Alta (7.1) | 0.29% | — | Juniper Cloudvision CUEAI | 6/10/2026 | 7/10/2026 | Improper validation of selected CloudVision CUE application programming interface (API) request parameters may allow an authenticated network user to perform SQL injection against the backend impacting its availability. |