Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
3953 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.5) | 1.4% | 💥 Exploit | Servicenow AI PlatformAI | 13/7/2026 | 14/7/2026 | ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying a security update to… | |
| Aplazada | Baja (2.1) | 0.41% | — | Parseplatform Parse ServerAI | 11/7/2026 | 13/7/2026 | Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and <= 8.6.83. When an uploaded file's extension is not recognized by the mime package, Parse Server preserves the client-supplied Content-Type. A malformed Content-Type that is not a valid type/subtype… | |
| Aplazada | Alta (7.1) | 0.46% | — | Praisonai PlatformAI | 11/7/2026 | 13/7/2026 | PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner/admin authorization on the PATCH routes for projects, issues, and agents, which only require workspace-member role. A workspace member can modify owner-created records; for projects, a member can reassign lead_id to their own user id and then… | |
| Aplazada | Alta (7.1) | 0.41% | — | Praisonai PlatformAI | 10/7/2026 | 10/7/2026 | PraisonAI Platform (praisonai-platform) before 0.1.9 improperly authorizes deletion of issue dependencies. The DELETE dependency route accepts either endpoint of a dependency edge and checks delete permission only against the caller-selected URL issue. A workspace member who cannot delete a dependency through an… | |
| Aplazada | Baja (2.3) | 0.53% | — | Parseplatform Parse ServerAI | 8/7/2026 | 10/7/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.13 and 8.6.83, a LiveQuery subscriber could receive object field values they were not authorized to read when a single save changed both an object field and the subscriber's ACL read access,… | |
| Aplazada | Alta (8.7) | 0.59% | — | Parseplatform Parse ServerAI | 8/7/2026 | 10/7/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.12 and 8.6.82, deeply nested $or, $and, and $nor query condition operators in the REST API or LiveQuery query handling could trigger exponential-time processing in the internal query-traversal… | |
| Analizada | Alta (8.8) | 0.11% | — | Qualcomm Wsa8835 FirmwareQualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Cq7790 Firmware+124 | 6/7/2026 | 7/7/2026 | Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations. | |
| Analizada | Media (5.3) | 0.08% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Lemans AU Lgit Firmware+75 | 6/7/2026 | 7/7/2026 | Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits. | |
| Analizada | Alta (7.1) | 0.10% | — | Qualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Lemans AU Lgit FirmwareQualcomm Lemansau Firmware+49 | 6/7/2026 | 8/7/2026 | Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Aqt1000 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+43 | 6/7/2026 | 7/7/2026 | Memory Corruption when allocating memory with sizes that exceed the maximum allowed value. | |
| Analizada | Media (5.3) | 0.08% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm G3X GEN 2 Firmware+87 | 6/7/2026 | 7/7/2026 | Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values. | |
| Analizada | Media (5.3) | 0.08% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+105 | 6/7/2026 | 7/7/2026 | Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification. | |
| Analizada | Media (5.3) | 0.08% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm G3X GEN 2 Firmware+87 | 6/7/2026 | 7/7/2026 | Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks. | |
| Analizada | Alta (7.3) | 0.09% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Molokai Firmware+44 | 6/7/2026 | 29/9/2026 | Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Molokai Firmware+44 | 6/7/2026 | 29/9/2026 | Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Molokai Firmware+56 | 6/7/2026 | 29/9/2026 | Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffers due to improper synchronization. | |
| Aplazada | Media (5.5) | 0.41% | — | Hanwang E-face General Management PlatformAI | 5/7/2026 | 6/7/2026 | A vulnerability was identified in Hanwang e-Face General Management Platform 6.3.5.4. This impacts an unknown function of the file /sysAuthStr/querySysAuthStr.do. The manipulation of the argument order leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might… | |
| Pendiente de análisis | Media (5.3) | 0.21% | — | Dell Client Platform BiosAI | 3/7/2026 | 7/7/2026 | Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure. | |
| Aplazada | Media (6.5) | 0.34% | — | Api-platform API Platform CoreAI | 1/7/2026 | 2/7/2026 | API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions prior to 4.1.30, 4.2.26 and 4.3.12, the serializer's AbstractItemNormalizer does not validate the resource type returned when resolving relation IRIs, allowing type confusion where a resource of an unintended type can be… | |
| Pendiente de análisis | Media (5.9) | 0.32% | — | Api-platform API Platform CoreAI | 1/7/2026 | 2/7/2026 | API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions from 2.6.0 prior to 4.1.29, 4.2.26, and 4.3.12, a missing isCacheKeySafe gate in the JSON:API and HAL item normalizers causes a cross-user attribute leak. #[ApiProperty(security: ...)] is evaluated per request to decide… | |
| Modificada | Media (4.3) | 0.39% | — | Redhat Build OF KeycloakRedhat Jboss Enterprise Application Platform Expansion Pack | 30/6/2026 | 5/8/2026 | A vulnerability was discovered in Keycloak's Admin UI extension that allows certain administrative users to bypass security restrictions. When Fine-Grained Admin Permissions (FGAPv2) are enabled, an administrator who should only be able to search for users (but not view their full details) can use a specific… | |
| Modificada | Media (6.2) | 0.20% | — | Redhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise LinuxP11-kit Project P11-kit | 29/6/2026 | 28/9/2026 | A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes.… | |
| Analizada | Media (5.3) | 0.17% | — | Redhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise LinuxKernel Util-linux | 29/6/2026 | 31/8/2026 | A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer… | |
| Aplazada | Media (5.5) | 0.47% | — | Hanwang E-face General Management PlatformAI | 29/6/2026 | 29/6/2026 | A vulnerability was determined in Hanwang e-Face General Management Platform 6.3.5.4. This issue affects some unknown processing of the file /manage/resourceUpload/upload.do. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be launched remotely. The exploit has been… | |
| Aplazada | Alta (8.3) | 0.35% | — | Hitachi Virtual Storage Platform E390AIHitachi Virtual Storage Platform E590AIHitachi Virtual Storage Platform E790AIHitachi Virtual Storage Platform E990AI+23 | 29/6/2026 | 29/6/2026 | Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H: before DKCMAIN Ver. 93-07-26-xx/00, GUM Ver. 93-07-26/00; Hitachi Virtual Storage Platform 5100, 5500, 5100H,… |