Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

8750 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)1.0%—HoppscotchAI9/7/202610/7/2026
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the updateInfraConfigs GraphQL mutation in admin/infra.resolver.ts accepts an attacker-controlled MAILER_SMTP_URL value, and validateSMTPUrl in utils.ts permits path, query, or fragment content that nodemailer parses into sendmail transport…
AplazadaAlta (7.5)0.59%—HoppscotchAI9/7/202610/7/2026
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, mock server creation in mock-server.service.ts does not persist the isPublic input field while schema.prisma defaults isPublic to true, causing mock servers linked to private collections to be publicly accessible without authentication and…
AnalizadaAlta (8.1)0.60%—Discourse9/7/202614/7/2026
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, under certain non-default configurations, processing of PDF uploads could be exploited to obtain RCE on the server. This issue is patched in 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.
AnalizadaAlta (7.2)1.9%—Cisco Rv130 FirmwareCisco Rv130w FirmwareCisco Rv110w Firmware8/7/202610/7/2026
An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The machine_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute…
AnalizadaAlta (7.2)1.5%—Cisco Rv130 FirmwareCisco Rv130w FirmwareCisco Rv110w Firmware8/7/202610/7/2026
An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The lan_ipv6_prefixlen configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to…
AnalizadaAlta (7.2)1.5%—Cisco Rv130 FirmwareCisco Rv130w FirmwareCisco Rv110w Firmware8/7/202610/7/2026
An OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The model_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker…
AnalizadaAlta (7.2)1.5%—Cisco Rv130 FirmwareCisco Rv130w FirmwareCisco Rv110w Firmware8/7/202610/7/2026
An OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The wan_hostname configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to…
AnalizadaCrítica (10)1.7%💥 ExploitHoppscotch1/7/20262/7/2026
Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and earlier, the unauthenticated POST /v1/onboarding/config endpoint is vulnerable to mass assignment. The global NestJS ValidationPipe is configured without whitelist: true, so extra properties on the…
AnalizadaAlta (7.5)0.57%—Cisco Secure EndpointClamav1/7/20269/7/2026
A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in DMG files during scanning,…
AnalizadaAlta (7.5)0.57%—Cisco Secure EndpointClamav1/7/20269/7/2026
A vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in ALZ files during scanning,…
AnalizadaAlta (7.5)0.57%💥 PoCCisco Secure EndpointClamav1/7/20269/7/2026
A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during…
AnalizadaAlta (7.5)0.57%—Cisco Secure EndpointClamav1/7/20269/7/2026
A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper handling of temporary resources during file scanning. An attacker could exploit this vulnerability by submitting a…
AnalizadaAlta (7.5)0.57%—Cisco Secure EndpointClamav1/7/20269/7/2026
A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in 7z files during scanning,…
AnalizadaAlta (7.5)0.57%—Cisco Secure EndpointClamav1/7/20269/7/2026
A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in FSG files during scanning,…
AnalizadaAlta (7.5)0.57%—Cisco Secure EndpointClamav1/7/20269/7/2026
A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PE files during scanning,…
AnalizadaAlta (7.5)0.65%—Cisco Catalyst CenterCisco Catalyst Center Global Manager1/7/202617/9/2026
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to read arbitrary files from a restricted container of the affected device.
AplazadaMedia (6.5)0.33%—Woocart Payment Gateway Based Fees AND Discounts FOR WoocommerceAI26/6/202629/6/2026
Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce <= 3.0.0 versions.
AplazadaAlta (7.5)0.61%—Steeltoe Discovery EurekaAI17/6/202622/6/2026
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Discovery.Eureka prior to versions 4.2.0 and 3.4.0, `DataCenterInfo.FromJson` throws `ArgumentException` for any `name` value other than `"MyOwn"` or `"Amazon"`, despite the Java…
AnalizadaMedia (4.3)0.20%—Cisco Webex WEB APP17/6/202622/6/2026
A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker to redirect users to a malicious webpage. Cisco has addressed this vulnerability in the Cisco Webex App, and no customer action is needed. This vulnerability existed due to improper input validation…
AnalizadaMedia (6)0.10%—Cisco Umbrella Virtual Appliance17/6/202622/6/2026
A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied commands. An attacker with vmadmin privileges could exploit this vulnerability by using…
AnalizadaMedia (6.3)0.25%—Cisco Crosswork Network Controller17/6/202622/6/2026
A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an&nbsp;authenticated, remote attacker to execute arbitrary commands on an affected device.
ModificadaCrítica (9.2)6.5%💥 PoCF5 DOSF5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance Manager+717/6/202614/9/2026
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the…
AnalizadaAlta (7.5)0.50%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector17/6/202625/9/2026
A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected…
AnalizadaCrítica (9.1)8.9%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector17/6/202625/9/2026
A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of…
AplazadaMedia (6.5)0.41%—Workscout-coreAI17/6/202617/6/2026
Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions.