Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
294.004 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6) | 0.25% | — | Arista Cloudvision CUEAI | 6/10/2026 | 7/10/2026 | An insecure direct object reference (IDOR) vulnerability in a CloudVision CUE file-serving interface may allow an authenticated network user, under specific attack conditions, to access another user's transient data. | |
| Pendiente de análisis | Alta (7.1) | 0.33% | — | SpectralightAI | 6/10/2026 | 7/10/2026 | An XML External Entity (XXE) injection vulnerability in the WiFi-server Spectralight application allows any authenticated user to send malicious requests, leading to arbitrary local file disclosure and partial denial of service. | |
| Pendiente de análisis | Alta (7.2) | 0.33% | — | Arista Cloudvision PortalAIArista Cloudvision SensorAI | 6/10/2026 | 7/10/2026 | On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vulnerability exists. An authenticated user with sufficient high privileges could exploit this to extract unintended data from the Sensor. | |
| Pendiente de análisis | Alta (7.6) | 0.38% | — | Arista CloudvisionAI | 6/10/2026 | 7/10/2026 | Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, causes the identity provider (IdP) to deliver authentication material to an attacker-controlled URL instead of to CloudVision. | |
| Pendiente de análisis | Media (6.8) | 0.22% | — | Devolutions ServerAI | 6/10/2026 | 7/10/2026 | Authentication bypass in the Azure AD external login flow in Devolutions Server 2026.3.7.0 and earlier allows a remote attacker to take over a user's account via replay of a captured login-session token exposed in a redirect URL. | |
| En análisis | Alta (8.7) | 0.41% | — | Github Enterprise ServerAI | 6/10/2026 | 7/10/2026 | A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed a repository contributor to cause the appliance to issue requests to attacker-controlled internal hosts, which could be chained to achieve remote code execution on the appliance. The secret scanning validator for… | |
| Pendiente de análisis | Alta (7.1) | 0.21% | — | Prometheus Postgres ExporterAI | 6/10/2026 | 7/10/2026 | A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the cluster network can access these endpoints. This allows for information disclosure, potentially revealing process arguments, full… | |
| Pendiente de análisis | Alta (7.4) | 0.27% | — | Dell Command ConfigureAI | 6/10/2026 | 6/10/2026 | Dell Command | Configure (DCC), versions prior to 5.2.3.35, contain an Improper Handling of Mixed Encoding vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Pendiente de análisis | Media (5.5) | 0.10% | — | Dell Command ConfigureAI | 6/10/2026 | 7/10/2026 | Dell Command | Configure (DCC), versions prior to 5.2.3.35, contain a Plaintext Storage of Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure. | |
| Pendiente de análisis | Media (6.8) | 0.10% | — | Linux KernelAI | 6/10/2026 | 6/10/2026 | In wacom_hid_set_device_mode of wacom_sys.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Pendiente de análisis | Alta (7) | 0.05% | — | Linux KernelAI | 6/10/2026 | 7/10/2026 | In ep_free of eventpoll.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Aplazada | Crítica (9.8) | 0.15% | — | Multiversx Multisig ImprovedAI | 6/10/2026 | 7/10/2026 | MultiversX's multisig-improved (repository: mx-multisig-and-modules) reference implementation of their on-chain multisig smart contract system contains a vulnerability where a missing independent authorization check allows any account with the Proposer role to perform explicitly barred actions. This vulnerability… | |
| Aplazada | Alta (8.8) | 0.69% | — | Kozea WeasyprintAI | 6/10/2026 | 6/10/2026 | WeasyPrint helps web developers to create PDF documents. Prior to 70.0, the image-loading path in weasyprint/images.py passes fetched image bytes from HTML img URLs, CSS image values, SVG image references, and data URIs to Pillow's generic image dispatcher without excluding EPS or PostScript formats. On hosts with… | |
| Pendiente de análisis | Alta (7.8) | 0.16% | — | HydraAI | 6/10/2026 | 7/10/2026 | Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.6 and 1.4.0.dev9, the instantiate() target blacklist introduced for CVE-2026-68508 incompletely checks the effective callable selected by the target field. Execution wrappers such as timeit.timeit, executable deserialization… | |
| Pendiente de análisis | Alta (7.8) | 0.17% | — | HydraAI | 6/10/2026 | 7/10/2026 | Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.6 and 1.4.0.dev9, Hydra passes Python logging configuration to logging.config.dictConfig() without applying Hydra's target policy to handler class values or formatter, filter, handler, queue, and listener factories. An attacker who… | |
| Pendiente de análisis | Alta (7.8) | 0.27% | — | Hydra-optuna-sweeperAI | 6/10/2026 | 6/10/2026 | Hydra is a framework for elegantly configuring complex applications. From 1.2.0 until 1.3.0 and 1.4.0.dev10, the hydra-optuna-sweeper package accepts a configuration-controlled dotted path in hydra.sweeper.custom_search_space, resolves it with hydra.utils.get_method(), and later invokes the returned callable in the… | |
| Pendiente de análisis | Alta (8.5) | 0.46% | — | HydraAI | 6/10/2026 | 6/10/2026 | Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.7 and 1.4.0.dev10, Hydra stores legacy instantiate target blocklists and related execution-policy collections in mutable module-level state. An attacker who controls multiple sibling target entries can resolve… | |
| En análisis | Media (5.4) | 0.18% | — | Google ChromeAI | 6/10/2026 | 7/10/2026 | Confused deputy in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Low) | |
| Analizada | Alta (8.3) | 0.22% | — | Google Chrome | 6/10/2026 | 7/10/2026 | Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| En análisis | Sin puntuar | 0.19% | — | Google ChromeAI | 6/10/2026 | 6/10/2026 | Missing authorization in BrowserTag in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | |
| En análisis | Media (4) | 0.16% | — | Google ChromeAI | 6/10/2026 | 7/10/2026 | Information leak in Audio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium) | |
| Analizada | Alta (8.8) | 0.27% | — | Google Chrome | 6/10/2026 | 7/10/2026 | Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| En análisis | Sin puntuar | 0.19% | — | Google ChromeAI | 6/10/2026 | 6/10/2026 | Incorrect authorization in API in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | |
| Analizada | Alta (8.8) | 0.27% | — | Google Chrome | 6/10/2026 | 7/10/2026 | Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Media (5.4) | 0.16% | — | Google Chrome | 6/10/2026 | 7/10/2026 | Incorrect calculation in API in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted Chrome extension. (Chromium security severity: Medium) |