Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
2676 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.87% | — | Apache Httpcomponents Core | 1/7/2026 | 24/7/2026 | Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of headers / excessive header length | |
| Aplazada | Media (5.9) | 0.24% | — | Hester CoreAI | 26/6/2026 | 26/6/2026 | Author Cross Site Scripting (XSS) in Hester Core <= 1.1.8 versions. | |
| Aplazada | Alta (7.5) | 0.43% | — | Goya CoreAI | 26/6/2026 | 5/10/2026 | Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions. | |
| Aplazada | Media (5.3) | 0.33% | — | Auros CoreAI | 26/6/2026 | 5/10/2026 | Unauthenticated Content Injection in Auros Core <= 5.3.1 versions. | |
| Aplazada | Alta (7.2) | 0.61% | — | Xray-coreAIMhsanaei 3x-uiAI | 25/6/2026 | 25/6/2026 | 3X-UI is a web control panel for managing Xray-core servers. Prior to 3.3.1, an authenticated administrator can abuse the database import functionality to achieve arbitrary file write on the host by modifying Xray configuration values stored in the database. This can be leveraged to obtain code execution and… | |
| Aplazada | Alta (7) | 0.18% | — | QOS Logback-coreAIJaninoAI | 24/6/2026 | 1/7/2026 | ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.36 in Java applications, allows an attacker to execute arbitrary code circumventing existing protections against CVE-2025-11226 by compromising an existing logback configuration file or by injecting an… | |
| Pendiente de análisis | Media (5.1) | 0.20% | — | Caliptra Core Runtime FirmwareAI | 24/6/2026 | 25/6/2026 | Missing cryptographic step in Caliptra Core Firmware (aes_256_gcm_update module) results in an incorrect GCM authentication tag. When the streaming AES-256-GCM API is used with empty AAD, the hardware GHASH accumulator state is not saved after the first update call, causing the final tag to exclude the first batch of… | |
| Pendiente de análisis | Alta (7.2) | 0.24% | — | Caliptra Core Runtime FirmwareAI | 24/6/2026 | 25/6/2026 | Incorrect check of function return value in Caliptra Core Runtime Firmware (ActivateFirmwareCmd::activate_fw modules) allows bypass of Caliptra Core's verification of the MCU FW during a hitless update. This issue affects Core Runtime Firmware: from 2.0.0 through 2.0.1, 2.1.0. | |
| Aplazada | Alta (8.1) | 0.72% | 💥 PoC | Vmware CRMAIVmware Pivotal.core.common.dllAIVmware Pivotal.engine.client.services.conversion.dllAI | 23/6/2026 | 25/6/2026 | An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll and Pivotal.Engine.Client.Services.Conversion.dll components. | |
| Aplazada | Media (6.5) | 0.40% | — | Steeltoe Management EndpointAISteeltoe Management EndpointcoreAIVmware Spring BootAI | 17/6/2026 | 22/6/2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.Endpoint prior to version 4.2.0 and Steeltoe.Management.EndpointCore prior to version 3.4.0, all Steeltoe actuator endpoints default to `EndpointPermissions.Restricted`,… | |
| Aplazada | Media (5.1) | 0.40% | — | Coreweave MarimoAI | 17/6/2026 | 14/7/2026 | marimo before 0.23.9 contains a reflected cross-site scripting vulnerability in the notebook page that allows unauthenticated attackers to inject arbitrary JavaScript by exploiting improper escaping of single quotes in the file query parameter reflected into an inline JavaScript string literal. Attackers can craft a… | |
| Aplazada | Alta (7.5) | 0.31% | — | Steeltoe Management EndpointAISteeltoe Management EndpointcoreAI | 17/6/2026 | 22/6/2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.Endpoint prior to version 4.2.0 and Steeltoe.Management.EndpointCore prior to version 3.4.0, the `Sanitizer` component in the Environment actuator redacts configuration… | |
| Pendiente de análisis | Alta (8.4) | 0.34% | — | Amazon Bedrock Agentcore Python SDKAI | 17/6/2026 | 22/6/2026 | Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK versions >= 1.1.3 and < 1.6.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. To mitigate this issue, users… | |
| Aplazada | Alta (8.6) | 0.62% | — | PimcoreAI | 17/6/2026 | 23/6/2026 | Pimcore CMS/DXP version 12.3.8 contains a sandbox bypass vulnerability that allows authenticated administrative attackers to execute arbitrary methods on PHP objects by exploiting empty checkMethodAllowed() and checkPropertyAllowed() implementations in the custom Twig SecurityPolicy. Attackers can supply malicious… | |
| Aplazada | Alta (8.4) | 0.39% | 💥 PoC | Jazzcore Python-pdfkitAI | 17/6/2026 | 5/10/2026 | In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files. | |
| Aplazada | Media (6.5) | 0.41% | — | Workscout-coreAI | 17/6/2026 | 17/6/2026 | Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions. | |
| Aplazada | Alta (8.1) | 0.47% | — | Solene CoreAI | 17/6/2026 | 17/6/2026 | Unauthenticated Local File Inclusion in Solene Core <= 2.3.2 versions. | |
| Aplazada | Alta (8.1) | 0.47% | — | Mikado CoreAI | 17/6/2026 | 17/6/2026 | Unauthenticated Local File Inclusion in Mikado Core <= 1.6 versions. | |
| Aplazada | Alta (8.1) | 0.47% | — | Softlab CoreAI | 17/6/2026 | 17/6/2026 | Unauthenticated Local File Inclusion in Softlab Core < 1.2.11 versions. | |
| Aplazada | Alta (8.1) | 0.47% | — | Integrio CoreAI | 17/6/2026 | 17/6/2026 | Unauthenticated Local File Inclusion in Integrio Core < 1.2.8 versions. | |
| Aplazada | Alta (8.1) | 0.47% | — | Thegov CoreAI | 17/6/2026 | 17/6/2026 | Unauthenticated Local File Inclusion in Thegov Core < 2.0.23 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Sweetdate CoreAI | 17/6/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in SweetDate Core < 1.1.5 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | Jupiterx CoreAI | 16/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Jupiterx CoreAI | 15/6/2026 | 17/6/2026 | Subscriber Cross Site Scripting (XSS) in JupiterX Core <= 4.14.1 versions. | |
| Analizada | Alta (8.8) | 1.0% | — | Fortra Core Privileged Access Manager Server | 15/6/2026 | 28/7/2026 | Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Master during client… |