Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
401.024 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.20% | — | Avez Electronics Learning Management SystemAI | 2/10/2026 | 2/10/2026 | Missing Authorization vulnerability in AVEZ Electronics Communication Training and Consultancy Trade Inc. Learning Management System (LMS) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Learning Management System (LMS): through 2026-09-18. | |
| Aplazada | Alta (8.7) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift nodejs and D lang bindings. Both bindings' WebSocket server transports read the payload length out of the frame header and allocate that many bytes immediately, without checking that the… | |
| Aplazada | Alta (8.7) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Uncontrolled Recursion vulnerability in Apache Thrift go bindings. Both Go transports satisfy a read out of a buffered frame and, when that frame yields no payload bytes, read the next frame and call `Read` again instead of looping. A peer produces such a frame for 4 bytes in `TFramedTransport` (a declared size of… | |
| Aplazada | Crítica (9.2) | 0.38% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Allocation of resources without limits or throttling, Integer overflow or wraparound, Heap-based buffer overflow vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.7) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | NULL Pointer Dereference, Use of Uninitialized Variable vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.7) | 0.26% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | The protocol skip routine in several Apache Thrift bindings did not apply the binding's recursion limit, so a message that nests unknown fields deeply enough can exhaust the stack. Affected: the Python C++ accelerator (the pure-Python protocols are not affected), the PHP library and its thrift_protocol extension, and… | |
| Aplazada | Alta (8.7) | 0.29% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Stack-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in Apache Thrift php bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Media (6.9) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 3/10/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Delphi bindings buffered transport. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.7) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Access of Uninitialized Pointer vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.2) | 0.26% | — | Apache ThriftAI | 2/10/2026 | 3/10/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift C++, Java, Go, netstd, Python and Delphi bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Media (6.9) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 3/10/2026 | Allocation of Resources Without Limits or Throttling, Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.7) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 3/10/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift go bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (7.1) | 0.24% | — | Apache ThriftAI | 2/10/2026 | 3/10/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Media (5.3) | 0.20% | — | Softtr Informatics E-commerce PackAI | 2/10/2026 | 2/10/2026 | Observable discrepancy vulnerability in Softtr Informatics Trading Limited Company E-Commerce Pack allows Account Footprinting. This issue affects E-Commerce Pack: through 2026-10-02. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Alta (7.4) | 0.21% | — | Process-one EjabberdAI | 2/10/2026 | 2/10/2026 | User Impersonation in ProcessOnes XMMP Server ejabberd <= 26.04 allows an attacker to impersonate arbitrary users via unvalidated authzid parameter in SASL-PLAIN mechanism. | |
| Aplazada | Baja (2.1) | 0.27% | — | Sourcecodester Student Result Management SystemAI | 2/10/2026 | 2/10/2026 | A vulnerability was found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file script/academic/core/new_announcement.php of the component Announcement Module. The manipulation of the argument title/announcement results in cross site scripting. It is possible to launch the… | |
| Aplazada | Alta (8.5) | 0.49% | — | Tenda AC9AI | 2/10/2026 | 2/10/2026 | A vulnerability was detected in Tenda AC9 15.03.02.13. Affected is an unknown function of the file /goform/fast_setting_internet_set of the component POST Request Handler. Performing a manipulation of the argument netWanType results in stack-based buffer overflow. The attack is possible to be carried out remotely. The… | |
| Aplazada | Crítica (9.3) | 0.64% | — | Tenda HG7AITenda HG9AITenda Hg10AI | 2/10/2026 | 2/10/2026 | A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_en_xpon. This impacts the function boaGetVar of the file /boaform/formLoopBack of the component Boa Web Server. Such manipulation of the argument Ethtype leads to stack-based buffer overflow. The attack can be executed remotely. The… | |
| Aplazada | Media (6.5) | 0.13% | — | Themerex TRX AddonsAI | 2/10/2026 | 2/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeREX Group ThemeREX Addons trx_addons allows Stored XSS.This issue affects ThemeREX Addons: from n/a through 2.46.0. | |
| Aplazada | Media (6.4) | 0.14% | — | Themerex TRX AddonsAI | 2/10/2026 | 2/10/2026 | Server-Side Request Forgery (SSRF) vulnerability in ThemeREX Group ThemeREX Addons trx_addons allows Server Side Request Forgery.This issue affects ThemeREX Addons: from n/a through 2.46.0. | |
| Aplazada | Alta (8.7) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift NodeJS bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.2) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Inefficient regular expression complexity, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.2) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Uncontrolled Recursion, Allocation of resources without limits or throttling vulnerability in Apache Thrift Erlang bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Alta (8.2) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Inefficient Algorithmic Complexity vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Aplazada | Media (6.3) | 0.43% | — | Apache ThriftAI | 2/10/2026 | 2/10/2026 | Missing release of memory after effective lifetime vulnerability in Apache Thrift c++ bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |