Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2706▼ 533 respecto a la semana anterior
Críticas / altas1274▼ 219 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 249 respecto a la semana anterior
40.014 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.3) | 0.21% | 💥 PoC | CapacitorAI | 1/10/2026 | 2/10/2026 | Capacitor is a cross-platform native runtime for web applications. From 6.0.0 until 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1, the Android and iOS WebView navigation guard validates a target URL's host and scheme but not its path, allowing a victim who activates an untrusted link to navigate a frame to… | |
| En análisis | Crítica (9.1) | 0.33% | — | Theforeman ForemanAI | 1/10/2026 | 7/10/2026 | A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the user can access sensitive data, such as host root passwords. Furthermore, under… | |
| En análisis | Crítica (9.9) | 0.72% | — | Theforeman ForemanAI | 1/10/2026 | 7/10/2026 | A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to improper handling of delegated methods, an attacker can append unauthorized functions to the allowed execution list, enabling… | |
| Analizada | Crítica (9.8) | 0.52% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Analizada | Crítica (9.8) | 0.60% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Analizada | Crítica (9.8) | 0.56% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| En análisis | Crítica (9.3) | 0.14% | — | Watchguard Kernel Memory Access DriverAI | 1/10/2026 | 2/10/2026 | A missing authentication vulnerability in the Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products allows a local, authenticated attacker to bypass the driver's access-control handshake and issue arbitrary privileged commands to the driver, resulting in disclosure of kernel and process… | |
| Aplazada | Crítica (9.4) | 0.41% | — | Classroom50AI | 1/10/2026 | 2/10/2026 | Classroom 50 is a free and open-source tool for managing and grading programming assignments via GitHub. Prior to version 1.11.0, `gh teacher download` clones each student's assignment repository and then writes autograde artifacts (`result.json` and `results.json`) into the just-cloned working tree. The write… | |
| Pendiente de análisis | Crítica (9.8) | 0.44% | — | Fortra Core Privileged Access ManagerAI | 1/10/2026 | 1/10/2026 | Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing. | |
| Pendiente de análisis | Crítica (9.1) | 0.98% | — | Fortra Boks ManagerAI | 1/10/2026 | 1/10/2026 | Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs through BCC, the WSI REST or SOAP API, or the cacrl command-line interface could cause shell command substitution to be processed by crlserver as root on the BoKS Master. BCC and WSI provide… | |
| Aplazada | Crítica (9.3) | 0.24% | — | Wordpress File UploadAI | 1/10/2026 | 1/10/2026 | Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions. | |
| Aplazada | Crítica (9.8) | 0.27% | 💥 PoC | AuthorizerAI | 1/10/2026 | 1/10/2026 | Unauthenticated Privilege Escalation in Authorizer <= 3.15.3 versions. | |
| Aplazada | Crítica (9.9) | 0.27% | — | Boks KeytabmdAI | 1/10/2026 | 1/10/2026 | In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a… | |
| En análisis | Crítica (9.3) | 0.32% | — | FleetAI | 1/10/2026 | 1/10/2026 | Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials as authentication tokens in addition to device UUIDs. Unauthenticated attackers who know or guess these non-secret identifiers can authenticate as iOS/iPadOS hosts to read device… | |
| Pendiente de análisis | Crítica (9.3) | 0.56% | — | Ground Station Ground-stationAI | 1/10/2026 | 1/10/2026 | ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.restore command that allows unauthenticated attackers to execute arbitrary SQL during first-run setup mode. Attackers can invoke setup.restore via Socket.IO to plant admin users and forged session tokens, then authenticate… | |
| Aplazada | Crítica (9.3) | 0.31% | — | MispAI | 1/10/2026 | 1/10/2026 | MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its time-based validity window. The issue exists in the user login flow where a TOTP code is verified as a second authentication factor. Because the system… | |
| Aplazada | Crítica (9.8) | 0.58% | — | Ultimate MultisiteAI | 1/10/2026 | 1/10/2026 | The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.15.0 via the `checkout_form` parameter of the `login_customer_after_checkout` function. This is due to the publicly accessible… | |
| Aplazada | Crítica (9.8) | 0.29% | 💥 PoC | Super-forms Super FormsAI | 1/10/2026 | 1/10/2026 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that… | |
| Pendiente de análisis | Crítica (9.3) | 0.59% | — | — | 1/10/2026 | 1/10/2026 | The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to… | |
| Aplazada | Crítica (10) | 0.31% | — | Backupsheep Wordpress Backup PluginAI | 1/10/2026 | 1/10/2026 | The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to delete arbitrary files… | |
| Aplazada | Crítica (9.1) | 0.45% | 💥 PoC | LatepointAI | 1/10/2026 | 1/10/2026 | The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.0. This is due to the software allowing users to execute an action that does not properly validate a value before running… | |
| Aplazada | Crítica (9.3) | 0.29% | — | Hitachi Coding Software SuiteAI | 1/10/2026 | 1/10/2026 | Hitachi Coding Software Suite contains a vulnerability related to Hidden Functionality vulnerability which allows an attacker to gain unauthorized access by exploiting hidden accounts or hard coded credentials. This issue affects Hitachi Coding Software Suite: through 3.3.0. | |
| Aplazada | Crítica (9.3) | 0.27% | — | Hitachi Coding Software SuiteAI | 1/10/2026 | 1/10/2026 | Hitachi Coding Software Suite contains a vulnerability related to Use of Hard-coded Cryptographic Key. The Hardcoding of JWT signing secret key allows an attacker to generate unauthorized Bearer tokens and exploit administrative functions. This issue affects Hitachi Coding Software Suite: through 3.3.0. | |
| Aplazada | Crítica (9.3) | 0.34% | — | Hitachi Coding Software SuiteAI | 1/10/2026 | 1/10/2026 | Hitachi Coding Software Suite contains a vulnerability related to Missing Authentication for Critical Function. This allows an unauthenticated attacker to invoke a critical API, potentially leading to unauthorized retrieval or alteration of sensitive information, or unauthorized manipulation. This issue affects… | |
| Aplazada | Crítica (9.3) | 0.38% | — | Hitachi Coding Software SuiteAI | 1/10/2026 | 1/10/2026 | Hitachi Coding Software Suite contains a vulnerability related to Path Traversal vulnerability that allows an attacker to access, create, modify, or delete files. This issue affects Hitachi Coding Software Suite: through 3.3.0. |