Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

8451 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Wewoo Dynamic Pricing With Discount RulesAI27/7/202627/7/2026
Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.
AplazadaMedia (5.1)0.31%—Milkdown Preset CommonmarkAITennisconnect ComponentsAI24/7/202627/7/2026
Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/components packages that allows attackers with document write access to execute arbitrary JavaScript in the browser context of any user who opens the document or clicks a rendered link. The…
AplazadaAlta (8.1)0.46%—Miniorange Discord IntegrationAI23/7/202623/7/2026
Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.
En análisisAlta (8.6)0.21%—ISC BindAI22/7/202622/7/2026
The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
En análisisAlta (7.5)0.52%—ISC BindAI22/7/202622/7/2026
If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through…
En análisisAlta (7.5)0.50%—ISC BindAI22/7/202622/7/2026
The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Specifically, if a client queries for a DNAME and A record below the DNAME to the resolver, and the authoritative server responds positively to the A query but delays the…
En análisisAlta (7.5)0.40%—ISC BindAI22/7/202622/7/2026
It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have…
En análisisAlta (7.5)0.54%—ISC BindAI22/7/202622/7/2026
A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the…
En análisisAlta (7.5)0.54%—ISC BindAI22/7/202622/7/2026
The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone which returns many valid but superfluous RRSIG records causes the validator to waste disproportionate…
En análisisAlta (7.5)0.43%—ISC BindAI22/7/202622/7/2026
An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software.…
En análisisMedia (6.5)0.38%—ISC BindAI22/7/202622/7/2026
If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit. BIND will first need to store a DNS record for a key (KEY, DNSKEY, etc.). That key must specify a PRIVATEDNS algorithm (253), and in the algorithm identifier, improperly give a…
En análisisMedia (6.8)0.27%—ISC BindAI22/7/202622/7/2026
BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
AnalizadaAlta (7.5)0.41%—Oracle In-memory Cost Management FOR Discrete Industries21/7/202619/8/2026
Vulnerability in the Oracle In-Memory Cost Management for Discrete Industries product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…
AnalizadaCrítica (9.9)0.43%—Oracle Peoplesoft In-memory Project Discovery21/7/20266/8/2026
Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle PeopleSoft (component: Project Discovery). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft In-Memory Project Discovery.…
AplazadaAlta (7.5)0.61%—Riscv Picorv32AI17/7/202623/7/2026
An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch in the PCPI INSN and memory address can lead to unexpected behavior.
AplazadaCrítica (9.1)0.63%—Openrisc Or1200AI17/7/202623/7/2026
An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or1200 cpu output port can lead to unexpected behavior.
En análisisAlta (7.5)0.47%—Cisco RoomosCisco Roomos Cloud15/7/202614/8/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by…
En análisisAlta (7.5)0.47%—Cisco RoomosCisco Roomos Cloud15/7/202614/8/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by…
En análisisCrítica (9.8)0.19%—Cisco RoomosCisco Roomos Cloud15/7/202614/8/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by…
En análisisCrítica (9.8)0.46%—Cisco RoomosCisco Roomos Cloud15/7/202614/8/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by…
En análisisAlta (7.5)0.47%—Cisco RoomosCisco Roomos Cloud15/7/202614/8/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by…
En análisisAlta (8.8)0.42%—Cisco RoomosCisco Roomos Cloud15/7/202614/8/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by…
AnalizadaMedia (5.5)0.50%—Cisco Identity Services Engine Passive Identity ConnectorCisco Identity Services Engine15/7/202625/9/2026
This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system.
Pendiente de análisisAlta (8.7)0.43%—Cisco Catalyst 1719 AentrAI14/7/202614/7/2026
A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network storm, which causes the device to become overloaded and lose communication. A power cycle is required to recover.
Pendiente de análisisMedia (6)0.33%—Cisco HyperflexAI14/7/202615/7/2026
An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger decompression of a large file that consumes an excessive amount of system resources thus causing a Denial of Service.