Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
14.243 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Media (4.3) | 1.0% | — | CAI Content CredentialsAI | 22/9/2026 | 22/9/2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue requires user interaction in that a victim… | |
| En análisis | Media (5.5) | 0.24% | — | CAI Content CredentialsAI | 22/9/2026 | 26/9/2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim… | |
| En análisis | Alta (7.5) | 0.90% | — | CAI Content CredentialsAI | 22/9/2026 | 23/9/2026 | CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user… | |
| En análisis | Alta (7.5) | 0.65% | — | CAI Content CredentialsAI | 22/9/2026 | 22/9/2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction. | |
| Aplazada | Baja (2.1) | 1.7% | — | Moonshot AI Kimi CodeAI | 22/9/2026 | 22/9/2026 | A security flaw has been discovered in Moonshot AI Kimi Code up to 0.31.0. The affected element is an unknown function of the file agent-core-v2/src/agent/mcp/config-loader.ts of the component MCP Configuration Loader. The manipulation results in os command injection. The attack may be launched remotely. The exploit… | |
| Analizada | Crítica (9.9) | 0.53% | — | Adobe Campaign | 22/9/2026 | 26/9/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does… | |
| Analizada | Crítica (10) | 1.2% | — | Adobe Campaign | 22/9/2026 | 23/9/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require… | |
| Analizada | Crítica (10) | 1.2% | — | Adobe Campaign | 22/9/2026 | 23/9/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require… | |
| Analizada | Crítica (10) | 0.34% | — | Adobe Campaign | 22/9/2026 | 25/9/2026 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Analizada | Crítica (9.9) | 0.35% | — | Adobe Campaign | 22/9/2026 | 23/9/2026 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is… | |
| Analizada | Crítica (9.9) | 0.82% | — | Adobe Campaign | 22/9/2026 | 26/9/2026 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is… | |
| Analizada | Crítica (9.1) | 0.55% | — | Adobe Campaign | 22/9/2026 | 24/9/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and… | |
| Analizada | Crítica (9.9) | 0.43% | — | Adobe Campaign | 22/9/2026 | 23/9/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code.… | |
| Analizada | Crítica (9.1) | 0.99% | — | Adobe Campaign | 22/9/2026 | 25/9/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary SQL… | |
| Analizada | Crítica (9.9) | 0.53% | — | Adobe Campaign | 22/9/2026 | 23/9/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction.… | |
| Analizada | Alta (8.5) | 0.46% | — | Adobe Campaign | 22/9/2026 | 26/9/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control.… | |
| Analizada | Crítica (9.1) | 1.0% | — | Adobe Campaign | 22/9/2026 | 24/9/2026 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. | |
| Analizada | Crítica (10) | 1.2% | — | Adobe Campaign | 22/9/2026 | 23/9/2026 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Analizada | Crítica (10) | 1.2% | — | Adobe Campaign | 22/9/2026 | 25/9/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require… | |
| Analizada | Crítica (10) | 1.2% | — | Adobe Campaign | 22/9/2026 | 23/9/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require… | |
| Analizada | Crítica (10) | 1.2% | — | Adobe Campaign | 22/9/2026 | 26/9/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require… | |
| Analizada | Crítica (10) | 1.2% | — | Adobe Campaign | 22/9/2026 | 24/9/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require… | |
| Pendiente de análisis | Alta (8.4) | 0.32% | 💥 PoC | NetdataAIFail2banAI | 22/9/2026 | 23/9/2026 | Netdata is an open source observability tool. Prior to 2.10.4, the setuid-root ndsudo helper command fail2ban-client-status-socket in src/collectors/utils/ndsudo.c accepts a caller-controlled --socket_path from the low-privileged netdata service account. The account can direct root fail2ban-client to a malicious UNIX… | |
| Analizada | Media (5.4) | 0.21% | — | Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux | 22/9/2026 | 7/10/2026 | A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `lockout`, a fail-open condition in the LDAP ppolicy access check can occur if a user lookup returns zero results. This can incorrectly return success and cache an allow decision, permitting continued… | |
| Analizada | Crítica (9.8) | 20% | ⚠ Explotación activa💥 PoC | Checkpoint Multi-domain Security ManagementCheckpoint Quantum Security Management | 22/9/2026 | 23/9/2026 | A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server. |