Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
3277 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.72% | — | Mbs-solutions X-serie GatewayAI | 4/9/2026 | 9/9/2026 | An arbitrary file upload vulnerability in /cgi-bin/ugwupload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with Admin role to upload files with arbitrary content to hardcoded paths. | |
| Aplazada | Media (6.3) | 0.42% | — | Mbs-solutions X-serie GatewayAI | 4/9/2026 | 8/9/2026 | An issue in the ugw-editfile method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to write arbitrary content to files within /uxx/config/ and /ugw/config/. | |
| Aplazada | Media (4.3) | 0.41% | — | Mbs-solutions X-serie GatewayAI | 4/9/2026 | 14/9/2026 | A broken access control vulnerability in the ugw-usr-edit method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to change the password of arbitrary accounts. | |
| Aplazada | Alta (8.8) | 0.74% | — | Mbs-solutions X-serie GatewayAI | 4/9/2026 | 9/9/2026 | Insecure Permission vulnerability in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows the low-privileged service user to execute /usr/bin/tcpdump as root without a password. By leveraging the tcpdump -z option, an authenticated attacker can achieve arbitrary command execution. | |
| Aplazada | Media (6.5) | 0.56% | — | Mbs-solutions X-serie GatewayAI | 4/9/2026 | 9/9/2026 | An issue in /cgi-bin/wwwugw.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to invoke hidden network diagnostic methods (ugw-ping, ugw-traceroute) that are not exposed in the web UI, allowing attackers to obtain sensitive information. | |
| Aplazada | Media (6.5) | 0.55% | — | Mbs-solutions X-serie GatewayAI | 4/9/2026 | 8/9/2026 | An arbitrary file read vulnerability in /cgi-bin/ugwdownload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to retrieve arbitrary files from the device filesystem via the file query string parameter. | |
| Aplazada | Media (6.5) | 0.45% | — | Mbs-solutions X-serie GatewayAI | 4/9/2026 | 8/9/2026 | An information disclosure vulnerability in the ugw-deviceinfo method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 returns detailed system version fields (operatingsystem, gatewayversion) to any authenticated user, including users with the low-privileged Standard role. | |
| Aplazada | Media (6.5) | 0.65% | — | Mbs-solutions X-serie GatewayAI | 4/9/2026 | 9/9/2026 | An information disclosure vulnerability in the opcua-configuration method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows any remote authenticated user, including users with the low-privileged Standard role, to retrieve the configured OPC-UA authentication credentials in cleartext via… | |
| Aplazada | Alta (8.8) | 0.77% | — | Mbs-solutions X-serie GatewayAI | 4/9/2026 | 9/9/2026 | An issue in the ugw-restart method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to inject arbitrary code into the dpcheck system utility executed as root. | |
| Aplazada | Crítica (9.1) | 0.60% | — | Citrix Gateway FirmwareAI | 4/9/2026 | 8/9/2026 | An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi. | |
| Aplazada | Media (5.3) | 0.16% | — | Epayco Payment GatewayAI | 4/9/2026 | 8/9/2026 | The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders as paid without a valid gateway signature. | |
| Analizada | Alta (8.4) | 0.22% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+4 | 3/9/2026 | 9/9/2026 | The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely. Successful exploitation enables a threat actor with administrative privileges and Carbon… | |
| Aplazada | Alta (8.7) | 0.63% | — | DbgateAI | 3/9/2026 | 23/9/2026 | DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to read and write arbitrary files via file:// scheme resolution. Attackers can exploit getJslFileName() to bypass directory containment and access sensitive files including encrypted database credentials stored in… | |
| Aplazada | Alta (8.6) | 0.64% | — | Seppmail Secure Email GatewayAI | 3/9/2026 | 4/9/2026 | SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges. | |
| Aplazada | Alta (7.7) | 0.47% | — | Seppmail Secure Email GatewayAI | 3/9/2026 | 3/9/2026 | SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access protected functionality without providing a second factor. | |
| Aplazada | Alta (8.6) | 1.2% | — | Seppmail Secure Email GatewayAI | 3/9/2026 | 3/9/2026 | SEPPmail Secure Email Gateway before 15.0.7 contains a command injection vulnerability that allows authenticated administrators to execute commands with elevated privileges. | |
| Pendiente de análisis | Alta (8.6) | 0.57% | — | Nginx PlusAINginx Gateway FabricAI | 2/9/2026 | 3/9/2026 | Description: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the Authentication Filter Custom Resource Definition clientID or cookieName fields, or in the… | |
| Analizada | Baja (2.3) | 0.23% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 2/9/2026 | 15/9/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session.… | |
| Analizada | Alta (7.8) | 0.40% | — | Nvidia Nemo Megatron Bridge | 1/9/2026 | 2/9/2026 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | |
| Analizada | Alta (7.8) | 0.40% | — | Nvidia Nemo Megatron Bridge | 1/9/2026 | 2/9/2026 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | |
| Analizada | Alta (7.8) | 0.40% | — | Nvidia Nemo Megatron Bridge | 1/9/2026 | 2/9/2026 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | |
| Analizada | Alta (7.8) | 0.40% | — | Nvidia Nemo Megatron Bridge | 1/9/2026 | 2/9/2026 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | |
| Analizada | Alta (7.8) | 0.40% | — | Nvidia Nemo Megatron Bridge | 1/9/2026 | 2/9/2026 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | |
| Analizada | Alta (7.8) | 0.40% | — | Nvidia Nemo Megatron Bridge | 1/9/2026 | 2/9/2026 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | |
| Analizada | Alta (7.8) | 0.40% | — | Nvidia Nemo Megatron Bridge | 1/9/2026 | 2/9/2026 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |