Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

883 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.5)0.08%—Strongdm Windows ServiceAI20/8/202517/6/2026
The StrongDM Windows service incorrectly handled communication related to system certificate management. Attackers could exploit this behavior to install untrusted root certificates or remove trusted ones.
AplazadaAlta (8.5)0.15%—StrongdmAI20/8/202517/6/2026
The StrongDM Windows service incorrectly handled input validation. Authenticated attackers could potentially exploit this leading to privilege escalation.
AplazadaAlta (8.5)0.11%—Strongdm ClientAI20/8/202517/6/2026
The StrongDM Client insufficiently protected a pre-authentication token. Attackers could exploit this to intercept and reuse the token, potentially redeeming valid authentication credentials through a race condition.
AnalizadaAlta (7.8)0.21%—Nvidia Megatron-lm13/8/202517/6/2026
NVIDIA Megatron-LM for all platforms contains a vulnerability in the megatron/training/ arguments.py component where an attacker could cause a code injection issue by providing a malicious input. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure,…
AnalizadaAlta (7.8)0.21%—Nvidia Megatron-lm13/8/202517/6/2026
NVIDIA Megatron-LM for all platforms contains a vulnerability in the tools component, where an attacker may exploit a code injection issue. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering.
AplazadaMedia (5.4)0.11%—Electronhub AI PlaygroundAI12/8/202517/6/2026
Incorrect default permissions for some AI Playground software before version v2.3.0 alpha may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaBaja (2.1)0.43%—Qiyuesuo Electronic Signature9/8/202517/6/2026
A vulnerability was found in Qiyuesuo Eelectronic Signature Platform up to 4.34 and classified as critical. Affected by this issue is the function execute of the file /api/code/upload of the component Scheduled Task Handler. The manipulation of the argument File leads to unrestricted upload. The attack may be launched…
AplazadaMedia (6.3)0.15%—Ruijie Eg306mgAIStrongswanAI9/8/202517/6/2026
A vulnerability was found in Ruijie EG306MG 3.0(1)B11P309. It has been rated as problematic. This issue affects some unknown processing of the file /etc/strongswan.conf of the component strongSwan. The manipulation of the argument i_dont_care_about_security_and_use_aggressive_mode_psk leads to missing encryption of…
AnalizadaAlta (7.8)0.23%—Electroncapture Electron Capture5/8/202517/6/2026
Electron Capture facilitates video playback for screen-sharing and capture. In versions 2.19.1 and below, the elecap app on macOS allows local unprivileged users to bypass macOS TCC privacy protections by enabling ELECTRON_RUN_AS_NODE. This environment variable allows arbitrary Node.js code to be executed via the -e…
AnalizadaMedia (6.1)0.36%—Electronhub AI Playground30/7/202517/6/2026
playground.electronhub.ai v1.1.9 was discovered to contain a cross-site scripting (XSS) vulnerability.
AplazadaCrítica (9.1)0.66%💥 PoCApache AirflowAIAstronomer Dag-factoryAI26/7/202517/6/2026
dag-factory is a library for Apache Airflow® to construct DAGs declaratively via configuration files. In versions 0.23.0a8 and below, a high-severity vulnerability has been identified in the cicd.yml workflow within the astronomer/dag-factory GitHub repository. The workflow, specifically when triggered by…
AplazadaMedia (6.8)0.27%—Medtronic Mycareelink Patient MonitorAI24/7/202517/6/2026
Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with physical access to log in with no password and access modify system functionality. This issue affects MyCareLink Patient Monitor models 24950 and 24952: before June 25, 2025
AplazadaMedia (6.8)0.19%—Medtronic Mycarelink Patient MonitorAI24/7/202517/6/2026
Medtronic MyCareLink Patient Monitor uses an unencrypted filesystem on internal storage, which allows an attacker with physical access to read and modify files. This issue affects MyCareLink Patient Monitor models 24950 and 24952: before June 25, 2025
AplazadaMedia (6.5)0.17%—Medtronic Mycarelink Patient MonitorAI24/7/202517/6/2026
Medtronic MyCareLink Patient Monitor has an internal service that deserializes data, which allows a local attacker to interact with the service by crafting a binary payload to crash the service or elevate privileges. This issue affects MyCareLink Patient Monitor models 24950 and 24952: before June 25, 2025
AplazadaAlta (8.6)1.8%💥 ExploitLantronix Provisioning ManagerAI22/7/202517/6/2026
Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network devices, leading to unauthenticated remote code execution on hosts with Provisioning Manager installed.
AnalizadaBaja (1.9)0.13%—Eluktronics Control Center20/7/202517/6/2026
A vulnerability classified as problematic was found in Eluktronics Control Center 5.23.51.41. Affected by this vulnerability is an unknown functionality of the component REG File Handler. The manipulation leads to insufficient verification of data authenticity. It is possible to launch the attack on the local host.…
AnalizadaAlta (7.1)1.7%—Eluktronics Control Center20/7/202517/6/2026
A vulnerability classified as critical has been found in Eluktronics Control Center 5.23.51.41. Affected is an unknown function of the file \AiStoneService\MyControlCenter\Command of the component Powershell Script Handler. The manipulation leads to command injection. Attacking locally is a requirement. The exploit…
AplazadaMedia (6.4)0.25%—Strong TestimonialsAI15/7/202517/6/2026
The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Custom Fields in all versions up to, and including, 3.2.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to…
AnalizadaMedia (4.2)0.20%—Amauri Tarteaucitronjs3/7/202517/6/2026
tarteaucitron.js is a compliant and accessible cookie banner. Prior to version 1.22.0, a vulnerability was identified in tarteaucitron.js where document.currentScript was accessed without verifying that it referenced an actual <script> element. If an attacker injected an HTML element, it could clobber the…
AplazadaMedia (4.4)0.16%—ElectronAI1/7/202517/6/2026
Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions prior to 28.3.2, 29.3.3, and 30.0.3, the nativeImage.createFromPath() and nativeImage.createFromBuffer() functions call a function downstream that is vulnerable to a heap buffer overflow. An…
AplazadaAlta (7.8)0.12%—ElectronAI1/7/202517/6/2026
Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 30.0.0-alpha.1 to before 30.0.5 and 31.0.0-alpha.1 to before 31.0.0-beta.1, Electron is vulnerable to an ASAR Integrity bypass. This only impacts apps that have the…
AplazadaAlta (7.8)0.31%—Delta Electronics DTN SoftAI30/6/202517/6/2026
Delta Electronics DTN Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution
AplazadaAlta (7.8)0.24%—Delta Electronics DTM SoftAI30/6/202517/6/2026
Delta Electronics DTM Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution
AplazadaAlta (8.7)0.91%—Hunt Electronic Hbf-09kdAIHunt Electronic Hbf-16nkAI26/6/202517/6/2026
Certain hybrid DVR models (HBF-09KD and HBF-16NK) from Hunt Electronic have an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary OS commands and execute them on the device.
AplazadaCrítica (9.8)0.55%—Hunt Electronic Hbf-09kdAIHunt Electronic Hbf-16nkAI26/6/202517/6/2026
Certain hybrid DVR models ((HBF-09KD and HBF-16NK)) from Hunt Electronic have an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to directly access a system configuration file and obtain plaintext administrator credentials.