Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

2676 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.87%—Apache Httpcomponents Core1/7/202624/7/2026
Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of headers / excessive header length
AplazadaMedia (5.9)0.24%—Hester CoreAI26/6/202626/6/2026
Author Cross Site Scripting (XSS) in Hester Core <= 1.1.8 versions.
AplazadaAlta (7.5)0.43%—Goya CoreAI26/6/20265/10/2026
Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.
AplazadaMedia (5.3)0.33%—Auros CoreAI26/6/20265/10/2026
Unauthenticated Content Injection in Auros Core <= 5.3.1 versions.
AplazadaAlta (7.2)0.61%—Xray-coreAIMhsanaei 3x-uiAI25/6/202625/6/2026
3X-UI is a web control panel for managing Xray-core servers. Prior to 3.3.1, an authenticated administrator can abuse the database import functionality to achieve arbitrary file write on the host by modifying Xray configuration values stored in the database. This can be leveraged to obtain code execution and…
AplazadaAlta (7)0.18%—QOS Logback-coreAIJaninoAI24/6/20261/7/2026
ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.36 in Java applications, allows an attacker to execute arbitrary code circumventing existing protections against CVE-2025-11226 by compromising an existing logback configuration file or by injecting an…
Pendiente de análisisMedia (5.1)0.20%—Caliptra Core Runtime FirmwareAI24/6/202625/6/2026
Missing cryptographic step in Caliptra Core Firmware (aes_256_gcm_update module) results in an incorrect GCM authentication tag. When the streaming AES-256-GCM API is used with empty AAD, the hardware GHASH accumulator state is not saved after the first update call, causing the final tag to exclude the first batch of…
Pendiente de análisisAlta (7.2)0.24%—Caliptra Core Runtime FirmwareAI24/6/202625/6/2026
Incorrect check of function return value in Caliptra Core Runtime Firmware (ActivateFirmwareCmd::activate_fw modules) allows bypass of Caliptra Core's verification of the MCU FW during a hitless update. This issue affects Core Runtime Firmware: from 2.0.0 through 2.0.1, 2.1.0.
AplazadaAlta (8.1)0.72%💥 PoCVmware CRMAIVmware Pivotal.core.common.dllAIVmware Pivotal.engine.client.services.conversion.dllAI23/6/202625/6/2026
An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll and Pivotal.Engine.Client.Services.Conversion.dll components.
AplazadaMedia (6.5)0.40%—Steeltoe Management EndpointAISteeltoe Management EndpointcoreAIVmware Spring BootAI17/6/202622/6/2026
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.Endpoint prior to version 4.2.0 and Steeltoe.Management.EndpointCore prior to version 3.4.0, all Steeltoe actuator endpoints default to `EndpointPermissions.Restricted`,…
AplazadaMedia (5.1)0.40%—Coreweave MarimoAI17/6/202614/7/2026
marimo before 0.23.9 contains a reflected cross-site scripting vulnerability in the notebook page that allows unauthenticated attackers to inject arbitrary JavaScript by exploiting improper escaping of single quotes in the file query parameter reflected into an inline JavaScript string literal. Attackers can craft a…
AplazadaAlta (7.5)0.31%—Steeltoe Management EndpointAISteeltoe Management EndpointcoreAI17/6/202622/6/2026
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.Endpoint prior to version 4.2.0 and Steeltoe.Management.EndpointCore prior to version 3.4.0, the `Sanitizer` component in the Environment actuator redacts configuration…
Pendiente de análisisAlta (8.4)0.34%—Amazon Bedrock Agentcore Python SDKAI17/6/202622/6/2026
Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK versions >= 1.1.3 and < 1.6.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. To mitigate this issue, users…
AplazadaAlta (8.6)0.62%—PimcoreAI17/6/202623/6/2026
Pimcore CMS/DXP version 12.3.8 contains a sandbox bypass vulnerability that allows authenticated administrative attackers to execute arbitrary methods on PHP objects by exploiting empty checkMethodAllowed() and checkPropertyAllowed() implementations in the custom Twig SecurityPolicy. Attackers can supply malicious…
AplazadaAlta (8.4)0.39%💥 PoCJazzcore Python-pdfkitAI17/6/20265/10/2026
In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files.
AplazadaMedia (6.5)0.41%—Workscout-coreAI17/6/202617/6/2026
Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions.
AplazadaAlta (8.1)0.47%—Solene CoreAI17/6/202617/6/2026
Unauthenticated Local File Inclusion in Solene Core <= 2.3.2 versions.
AplazadaAlta (8.1)0.47%—Mikado CoreAI17/6/202617/6/2026
Unauthenticated Local File Inclusion in Mikado Core <= 1.6 versions.
AplazadaAlta (8.1)0.47%—Softlab CoreAI17/6/202617/6/2026
Unauthenticated Local File Inclusion in Softlab Core < 1.2.11 versions.
AplazadaAlta (8.1)0.47%—Integrio CoreAI17/6/202617/6/2026
Unauthenticated Local File Inclusion in Integrio Core < 1.2.8 versions.
AplazadaAlta (8.1)0.47%—Thegov CoreAI17/6/202617/6/2026
Unauthenticated Local File Inclusion in Thegov Core < 2.0.23 versions.
AplazadaAlta (7.1)0.18%—Sweetdate CoreAI17/6/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in SweetDate Core < 1.1.5 versions.
AplazadaAlta (7.5)0.39%—Jupiterx CoreAI16/6/202617/6/2026
Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.
AplazadaMedia (6.5)0.22%—Jupiterx CoreAI15/6/202617/6/2026
Subscriber Cross Site Scripting (XSS) in JupiterX Core <= 4.14.1 versions.
AnalizadaAlta (8.8)1.0%—Fortra Core Privileged Access Manager Server15/6/202628/7/2026
Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Master during client…