Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

2154 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.7)0.33%—Vmware Spring Cloud Gateway27/8/202610/9/2026
Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 5.0.0 - 5.0.2 Spring Cloud Gateway 4.3.0 - 4.3.5 Spring Cloud Gateway 4.0.0 - 4.2.9 Spring Cloud Gateway 3.1.13 and earlier
AplazadaMedia (5.3)0.33%—Conekta Payment GatewayAI22/8/202626/8/2026
The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway webhook notifications, nor bind the confirmed payment to the targeted order or verify its amount, allowing unauthenticated attackers to mark arbitrary orders as paid without payment.
Pendiente de análisisAlta (7.7)0.40%—Tensorzero GatewayAI21/8/202611/9/2026
TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026.6.0, the TensorZero Gateway /internal/object_storage endpoint accepts a caller-supplied JSON storage_path parameter that dynamically overrides the [object_storage]…
AnalizadaAlta (8.8)0.42%—SplunkSplunk Secure Gateway19/8/202621/8/2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use crafted report notification data to cause Splunk Secure Gateway to send a request to the Splunk Enterprise…
AnalizadaMedia (5.4)0.29%—SplunkSplunk Secure Gateway19/8/202621/8/2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use Server-Side Request Forgery (SSRF) in report notifications to send system-authenticated requests to…
AnalizadaMedia (6.4)0.26%—SplunkSplunk Secure Gateway19/8/202626/8/2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, an unauthenticated user could trick a user who holds the "admin" or "sc_admin" Splunk roles into opening a crafted Splunk Web Uniform Resource Locator (URL). The resulting…
AnalizadaMedia (6.5)0.29%—SplunkSplunk Secure Gateway19/8/202626/8/2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could read Spacebridge asymmetric private keys, which are secrets that compromise affected Spacebridge private-key…
AnalizadaMedia (6.5)0.34%—SplunkSplunk Secure Gateway19/8/202626/8/2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10, 3.9.24, and 3.8.71, a user who does not hold the "admin" or "power" Splunk roles could register an arbitrary companion app and cause Splunk Secure Gateway to forward mobile user requests, including…
AnalizadaMedia (6.5)0.34%—SplunkSplunk Secure Gateway19/8/202626/8/2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10, 3.9.24, and 3.8.71, a user who holds a Splunk role with permissions to list storage passwords but does not hold Splunk Secure Gateway administration privileges could access Mobile Device Management…
AnalizadaMedia (4.3)0.30%—SplunkSplunk Secure Gateway19/8/202626/8/2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could read sensitive Security Assertion Markup Language setup and instance settings information through Splunk Secure…
Pendiente de análisisAlta (8.8)3.2%—Citrix Netscaler ADCAICitrix Netscaler GatewayAI19/8/20261/9/2026
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
AnalizadaCrítica (9.3)23%⚠ Explotación activa💥 PoCCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway19/8/20267/10/2026
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
AplazadaCrítica (9.8)0.50%—Tabapay GatewayAI19/8/202626/8/2026
The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session for the account associated with the referenced order, allowing unauthenticated attackers to log in as any registered user, including an administrator.
AplazadaMedia (6.5)0.42%—Piraeus Bank Woocommerce Payment GatewayAI18/8/202620/8/2026
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
AplazadaAlta (7.5)0.42%—Duitku Payment GatewayAI18/8/202620/8/2026
Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.
AplazadaCrítica (10)2.9%—Haiwell IOT Cloud HMI GatewayAI14/8/20268/9/2026
A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying…
AplazadaMedia (5.3)0.31%—Revolut Gateway FOR WoocommerceAI13/8/202614/8/2026
Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.
AplazadaAlta (7.5)0.35%—Smepay UPI Gateway FOR WoocommerceAI13/8/202614/8/2026
Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions.
AplazadaAlta (7.5)0.35%—Clink Bitcoin Lightning Payment GatewayAI13/8/202614/8/2026
Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions.
AplazadaMedia (6.5)0.33%—Piraeus Bank Secure Card Gateway FOR Epay PaycenterAI13/8/202614/8/2026
Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions.
AnalizadaMedia (4.2)0.16%—IBM Datapower Gateway12/8/20264/10/2026
IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9 allows a race condition that results in improper isolation of request state when handling the built‑in X‑Client‑IP header. Under concurrent request processing,…
AplazadaMedia (5.3)0.16%—Paypal Payment Gateway FOR WoocommerceAI12/8/202626/8/2026
The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succeeded before completing an order in its PayPal return handler: it reads attacker-controlled parameters, performs no amount comparison and no order-ownership check, and completes the order even when the…
AplazadaBaja (2.1)1.8%—Abdullah1854 McpgatewayAI8/8/202612/8/2026
A vulnerability was identified in abdullah1854 MCPGateway up to 549f494a9e363f40530149de324b8097de424230. This impacts the function getUsageByDateRange of the file src/services/claude-usage.ts of the component Claude Usage Range Endpoint. The manipulation of the argument since leads to command injection. The attack…
AplazadaAlta (7.5)0.19%—Redyx Payment Gateway FOR Redsys AND Woocommerce LiteAI6/8/202626/8/2026
The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a payment-confirmation callback and complete their own…
AnalizadaCrítica (9.8)0.48%—Wso2 API Control PlaneWso2 API ManagerWso2 Traffic ManagerWso2 Universal Gateway6/8/202610/8/2026
Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This…