Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
8451 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Wewoo Dynamic Pricing With Discount RulesAI | 27/7/2026 | 27/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions. | |
| Aplazada | Media (5.1) | 0.31% | — | Milkdown Preset CommonmarkAITennisconnect ComponentsAI | 24/7/2026 | 27/7/2026 | Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/components packages that allows attackers with document write access to execute arbitrary JavaScript in the browser context of any user who opens the document or clicks a rendered link. The… | |
| Aplazada | Alta (8.1) | 0.46% | — | Miniorange Discord IntegrationAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions. | |
| En análisis | Alta (8.6) | 0.21% | — | ISC BindAI | 22/7/2026 | 22/7/2026 | The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1. | |
| En análisis | Alta (7.5) | 0.52% | — | ISC BindAI | 22/7/2026 | 22/7/2026 | If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through… | |
| En análisis | Alta (7.5) | 0.50% | — | ISC BindAI | 22/7/2026 | 22/7/2026 | The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Specifically, if a client queries for a DNAME and A record below the DNAME to the resolver, and the authoritative server responds positively to the A query but delays the… | |
| En análisis | Alta (7.5) | 0.40% | — | ISC BindAI | 22/7/2026 | 22/7/2026 | It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have… | |
| En análisis | Alta (7.5) | 0.54% | — | ISC BindAI | 22/7/2026 | 22/7/2026 | A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the… | |
| En análisis | Alta (7.5) | 0.54% | — | ISC BindAI | 22/7/2026 | 22/7/2026 | The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone which returns many valid but superfluous RRSIG records causes the validator to waste disproportionate… | |
| En análisis | Alta (7.5) | 0.43% | — | ISC BindAI | 22/7/2026 | 22/7/2026 | An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software.… | |
| En análisis | Media (6.5) | 0.38% | — | ISC BindAI | 22/7/2026 | 22/7/2026 | If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit. BIND will first need to store a DNS record for a key (KEY, DNSKEY, etc.). That key must specify a PRIVATEDNS algorithm (253), and in the algorithm identifier, improperly give a… | |
| En análisis | Media (6.8) | 0.27% | — | ISC BindAI | 22/7/2026 | 22/7/2026 | BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1. | |
| Analizada | Alta (7.5) | 0.41% | — | Oracle In-memory Cost Management FOR Discrete Industries | 21/7/2026 | 19/8/2026 | Vulnerability in the Oracle In-Memory Cost Management for Discrete Industries product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Peoplesoft In-memory Project Discovery | 21/7/2026 | 6/8/2026 | Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle PeopleSoft (component: Project Discovery). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft In-Memory Project Discovery.… | |
| Aplazada | Alta (7.5) | 0.61% | — | Riscv Picorv32AI | 17/7/2026 | 23/7/2026 | An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch in the PCPI INSN and memory address can lead to unexpected behavior. | |
| Aplazada | Crítica (9.1) | 0.63% | — | Openrisc Or1200AI | 17/7/2026 | 23/7/2026 | An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or1200 cpu output port can lead to unexpected behavior. | |
| En análisis | Alta (7.5) | 0.47% | — | Cisco RoomosCisco Roomos Cloud | 15/7/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by… | |
| En análisis | Alta (7.5) | 0.47% | — | Cisco RoomosCisco Roomos Cloud | 15/7/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by… | |
| En análisis | Crítica (9.8) | 0.19% | — | Cisco RoomosCisco Roomos Cloud | 15/7/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by… | |
| En análisis | Crítica (9.8) | 0.46% | — | Cisco RoomosCisco Roomos Cloud | 15/7/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by… | |
| En análisis | Alta (7.5) | 0.47% | — | Cisco RoomosCisco Roomos Cloud | 15/7/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by… | |
| En análisis | Alta (8.8) | 0.42% | — | Cisco RoomosCisco Roomos Cloud | 15/7/2026 | 14/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by… | |
| Analizada | Media (5.5) | 0.50% | — | Cisco Identity Services Engine Passive Identity ConnectorCisco Identity Services Engine | 15/7/2026 | 25/9/2026 | This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system. | |
| Pendiente de análisis | Alta (8.7) | 0.43% | — | Cisco Catalyst 1719 AentrAI | 14/7/2026 | 14/7/2026 | A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network storm, which causes the device to become overloaded and lose communication. A power cycle is required to recover. | |
| Pendiente de análisis | Media (6) | 0.33% | — | Cisco HyperflexAI | 14/7/2026 | 15/7/2026 | An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger decompression of a large file that consumes an excessive amount of system resources thus causing a Denial of Service. |