Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
972 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.20% | — | Exagate Sysguard 6001AI | 5/2/2026 | 17/6/2026 | Exagate SYSGuard 6001 contains a cross-site request forgery vulnerability that allows attackers to create unauthorized admin accounts through a crafted HTML form. Attackers can trick users into submitting a malicious form to /kulyon.php that adds a new user with administrative privileges without the victim's consent. | |
| Analizada | Media (5.5) | 0.19% | — | Chainguard Melange | 4/2/2026 | 17/6/2026 | melange allows users to build apk packages using declarative pipelines. From version 0.14.0 to before 0.40.3, an attacker who can influence a melange configuration file (e.g., through pull request-driven CI or build-as-a-service scenarios) could read arbitrary files from the host system. The LicensingInfos function in… | |
| Analizada | Alta (7.8) | 0.20% | — | Chainguard Melange | 4/2/2026 | 17/6/2026 | melange allows users to build apk packages using declarative pipelines. From version 0.10.0 to before 0.40.3, an attacker who can influence inputs to the patch pipeline could execute arbitrary shell commands on the build host. The patch pipeline in pkg/build/pipelines/patch.yaml embeds input-derived values (series… | |
| Analizada | Alta (8.8) | 0.20% | — | Chainguard Melange | 4/2/2026 | 17/6/2026 | melange allows users to build apk packages using declarative pipelines. From version 0.3.0 to before 0.40.3, an attacker who can provide build input values, but not modify pipeline definitions, could execute arbitrary shell commands if the pipeline uses ${{vars.*}} or ${{inputs.*}} substitutions in working-directory.… | |
| Analizada | Alta (8.4) | 0.19% | — | Chainguard Melange | 4/2/2026 | 17/6/2026 | melange allows users to build apk packages using declarative pipelines. In version 0.11.3 to before 0.40.3, an attacker who can influence the tar stream from a QEMU guest VM could write files outside the intended workspace directory on the host. The retrieveWorkspace function extracts tar entries without validating… | |
| Analizada | Alta (7.5) | 0.41% | — | Chainguard Apko | 4/2/2026 | 17/6/2026 | apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, an attacker who controls or compromises an APK repository used by apko could cause resource exhaustion on the build host. The ExpandApk function in pkg/apk/expandapk/expandapk.go expands .apk… | |
| Analizada | Media (5.5) | 0.13% | — | Chainguard Apko | 4/2/2026 | 17/6/2026 | apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.0, expandapk.Split drains the first gzip stream of an APK archive via io.Copy(io.Discard, gzi) without explicit bounds. With an attacker-controlled input stream, this can force large gzip inflation… | |
| Analizada | Alta (7.5) | 0.42% | — | Chainguard Apko | 4/2/2026 | 17/6/2026 | apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, a path traversal vulnerability was discovered in apko's dirFS filesystem abstraction. An attacker who can supply a malicious APK package (e.g., via a compromised or typosquatted repository) could… | |
| Aplazada | Alta (7) | 0.93% | — | Watchguard Fireware OSAI | 30/1/2026 | 10/8/2026 | An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from a connected LDAP authentication server through an exposed authentication or management web interface. This vulnerability may also allow a remote attacker to authenticate as an… | |
| Analizada | Media (5.3) | 0.29% | — | Adguard Trusttunnel | 29/1/2026 | 17/6/2026 | TrustTunnel is an open-source VPN protocol with a rule bypass issue in versions prior to 0.9.115. In `tls_listener.rs`, `TlsListener::listen()` peeks 1024 bytes and calls `extract_client_random(...)`. If `parse_tls_plaintext` fails (for example, a fragmented/partial ClientHello split across TCP writes),… | |
| Analizada | Alta (7.1) | 0.26% | — | Adguard Trusttunnel | 29/1/2026 | 17/6/2026 | TrustTunnel is an open-source VPN protocol with a server-side request forgery and and private network restriction bypass in versions prior to 0.9.114. In `tcp_forwarder.rs`, SSRF protection for `allow_private_network_connections = false` was only applied in the `TcpDestination::HostName(peer)` path. The… | |
| Analizada | Media (5) | 0.19% | — | Chainguard Malcontent | 29/1/2026 | 17/6/2026 | malcontent discovers supply-chain compromises through. context, differential analysis, and YARA. Starting in version 1.8.0 and prior to version 1.20.3, malcontent could be made to create symlinks outside the intended extraction directory when scanning a specially crafted tar or deb archive. The `handleSymlink`… | |
| Analizada | Media (6.5) | 0.38% | — | Chainguard Malcontent | 29/1/2026 | 17/6/2026 | malcontent discovers supply-chain compromises through. context, differential analysis, and YARA. Starting in version 0.10.0 and prior to version 1.20.3, malcontent could be made to expose Docker registry credentials if it scanned a specially crafted OCI image reference. malcontent uses google/go-containerregistry for… | |
| Analizada | Alta (8.7) | 1.1% | — | Datadoghq Guarddog | 13/1/2026 | 17/6/2026 | GuardDog is a CLI tool to identify malicious PyPI packages. Prior to 2.7.1, there is a path traversal vulnerability exists in GuardDog's safe_extract() function that allows malicious PyPI packages to write arbitrary files outside the intended extraction directory, leading to Arbitrary File Overwrite and Remote Code… | |
| Analizada | Alta (7.1) | 0.52% | — | Datadoghq Guarddog | 13/1/2026 | 17/6/2026 | GuardDog is a CLI tool to identify malicious PyPI packages. Prior to 2.7.1, GuardDog's safe_extract() function does not validate decompressed file sizes when extracting ZIP archives (wheels, eggs), allowing attackers to cause denial of service through zip bombs. A malicious package can consume gigabytes of disk space… | |
| Analizada | Crítica (9.3) | 27% | ⚠ Explotación activa💥 PoC | Watchguard Fireware | 19/12/2025 | 9/9/2026 | An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was… | |
| Modificada | Alta (7.2) | 0.40% | — | Nozominetworks CMCNozominetworks Guardian | 18/12/2025 | 17/6/2026 | A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validation of the input file. An authenticated user with limited privileges, by uploading a specifically-crafted Arc data archive, can potentially write arbitrary files in arbitrary paths, altering the device… | |
| Modificada | Media (5.3) | 0.20% | — | Nozominetworks CMCNozominetworks Guardian | 18/12/2025 | 17/6/2026 | A Stored HTML Injection vulnerability was discovered in the Asset List functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets to inject HTML tags into asset attributes. When a victim views the affected assets in the Asset List (and… | |
| Modificada | Alta (7.1) | 0.26% | — | Nozominetworks CMCNozominetworks Guardian | 18/12/2025 | 17/6/2026 | A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report containing a JavaScript payload, or a victim can be socially engineered to import a malicious report… | |
| Modificada | Baja (2.3) | 0.18% | — | Nozominetworks CMCNozominetworks Guardian | 18/12/2025 | 30/9/2026 | A Stored HTML Injection vulnerability was discovered in the Time Machine Snapshot Diff functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets at two different times to inject HTML tags into asset attributes across two snapshots.… | |
| Aplazada | Alta (8.7) | 0.37% | — | Automation Systems Engineering 432es-ig3 Series AAIAutomation Systems Engineering Guardlink Ethernet IP InterfaceAI | 9/12/2025 | 17/6/2026 | A security issue exists within 432ES-IG3 Series A, which affects GuardLink® EtherNet/IP Interface, resulting in denial-of-service. A manual power cycle is required to recover the device. | |
| Aplazada | Media (6.5) | 0.19% | — | Watchguard FireboxAI | 9/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FirePlugins FireBox firebox allows Stored XSS.This issue affects FireBox: from n/a through <= 3.1.0-free. | |
| Modificada | Alta (8.6) | 0.62% | — | Watchguard Fireware | 4/12/2025 | 10/8/2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command. | |
| Modificada | Alta (8.6) | 0.69% | — | Watchguard Fireware | 4/12/2025 | 10/8/2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via specially crafted IPSec configuration CLI commands. | |
| Modificada | Alta (8.6) | 0.44% | — | Watchguard Fireware | 4/12/2025 | 10/8/2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS’s certificate request command could allow an authenticated privileged user to execute arbitrary code via specially crafted CLI commands. |