Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

21.612 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.11%—Dell Openmanage Server Administrator17/9/20261/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Denial of service.
AnalizadaCrítica (9.8)0.21%—Dell Openmanage Server Administrator17/9/20261/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
AplazadaMedia (5.3)0.16%—Wpmanageninja FluentauthAI17/9/202619/9/2026
Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity Spoofing. This issue affects FluentAuth: from n/a through 2.1.2.
AnalizadaAlta (7.8)0.15%—Dell Openmanage Server Administrator17/9/20261/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
AnalizadaMedia (6.5)0.17%—Dell Openmanage Server Administrator17/9/20261/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
AnalizadaAlta (7.5)0.15%—Dell Openmanage Server Administrator17/9/20261/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
AnalizadaAlta (7.5)0.20%—Dell Openmanage Server Administrator17/9/20266/10/2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
AplazadaAlta (7.4)0.13%—Acer NitrosenseAIAcer PredatorsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense due to insufficient access controls in a privileged service. An authenticated local user may be able to access the service and perform unauthorized registry modifications, potentially resulting in…
AplazadaAlta (7.4)0.13%—Acer NitrosenseAIAcer PredicatsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. Insufficient access controls within a privileged Named Pipe service may allow an authenticated local user to perform unauthorized registry operations. In certain situations, this could lead to…
AplazadaBaja (1.2)0.21%—Acer NitrosenseAIAcer PredatorsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The WebSocket handshake process does not properly require authentication before allowing connections to the service. Under certain circumstances, unauthorized access to service functionality may be…
AplazadaBaja (2.7)0.43%—Acer NitrosenseAIAcer PredatorsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. A WebSocket service was configured to listen on all network interfaces, which may expose the service to unintended network access.
AplazadaBaja (1.2)0.10%—Acer NitrosenseAIAcer PredatorsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected…
AplazadaAlta (7.4)0.13%—Acer NitrosenseAIAcer PredatorsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. Insufficient access controls within a privileged service may allow an authenticated local user to perform unauthorized registry operations. In certain situations, this could lead to privilege escalation…
AplazadaAlta (7.1)0.28%—Realtyna Organic IDXAIRealtyna WPL Real EstateAI17/9/202618/9/2026
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its parameters before reflecting them back in the page, allowing unauthenticated attackers to run arbitrary web scripts in a visitor's browser if they can trick the visitor into following a crafted link…
AplazadaMedia (4.9)0.21%—Acer NitrosenseAIAcer PredatorsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the service. Under certain circumstances, an unauthorized connection may be established, potentially…
AnalizadaAlta (7.5)0.19%—Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+37217/9/202622/9/2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
AnalizadaAlta (7.4)0.10%—Qualcomm Ar8035 FirmwareQualcomm C110100 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 Firmware+14817/9/202622/9/2026
Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
AplazadaMedia (4.9)0.10%—Acer NitrosenseAIAcer PredatorsenseAI17/9/202618/9/2026
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected…
AplazadaAlta (7.7)0.15%—Canva AffinityAI17/9/202618/9/2026
The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files leading to a stack-based buffer overflow. A threat actor could craft a Affinity document that when opened by a user in Affinity could result in arbitrary code execution.
Pendiente de análisisAlta (8)0.52%—Noelware Docker-manifest-actionAIQuay Builder-qemuAI16/9/202618/9/2026
A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to inject arbitrary code, leading to the exfiltration of sensitive registry credentials…
Pendiente de análisisAlta (8.7)0.64%—Amazon EKS Network Policy AgentAIAmazon VPC CNIAI16/9/202617/9/2026
Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS Network Policy Agent before v1.4.0 might allow an authenticated remote user to bypass NetworkPolicy enforcement on co-located pods in other namespaces via crafted pod and namespace names that produce pod identifier collisions.…
AplazadaCrítica (9.3)0.64%—Uvdesk Community SkeletonAI16/9/202622/9/2026
UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wizard endpoints, gaining full control…
AplazadaCrítica (9.8)0.40%—Zenith Satellite TrackerAI16/9/202622/9/2026
A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0. The script accepts an attacker-controlled address URL parameter and passes it to curl_setopt(CURLOPT_URL) without host or scheme validation. An unauthenticated remote attacker can leverage this to make arbitrary HTTP…
AnalizadaAlta (7.2)0.79%—Apache Nifi16/9/202621/9/2026
Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests. The default file persistence provider used coordinates as filesystem path components without rejected parent-directory names, and…
Pendiente de análisisMedia (6.5)0.34%—Tanium Threat ResponseAI16/9/202618/9/2026
Tanium addressed a server-side request forgery vulnerability in Threat Response.