Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

40.022 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.4)0.24%—Accellion Kiteworks30/9/20267/10/2026
Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to. This could allow an attacker to associate a certificate with another user's account, affecting the confidentiality and integrity of that account's encrypted mail and, where certificate-based login is…
AnalizadaCrítica (9.3)0.29%—Accellion Kiteworks30/9/20267/10/2026
A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to store crafted content that later executes arbitrary JavaScript in the authenticated session of an administrator who views the affected page. This could have permitted the attacker to gain full administrative…
AnalizadaCrítica (9.8)0.33%—Accellion Kiteworks30/9/20267/10/2026
Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset that account's password without access to the emailed reset link and then authenticate as that user,…
En análisisCrítica (9.1)0.37%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email Protection Gateway did not consistently enforce administrator authentication, so the required password check could be bypassed. An attacker who referenced a valid administrator account…
En análisisCrítica (9.1)0.34%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise…
En análisisCrítica (9.1)0.23%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise…
En análisisCrítica (9.1)0.23%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise…
En análisisCrítica (9.1)0.27%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise…
En análisisCrítica (9.1)0.27%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery. Kiteworks Email Protection Gateway performed server-side fetches of URLs contained in the message content it processed, without adequately restricting the fetch destination. A remote, unauthenticated sender could…
Pendiente de análisisCrítica (9.2)0.40%—ES Iperf3AI30/9/20261/10/2026
iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker dereferences a freed iperf_stream; fixed in 3.22.
AplazadaCrítica (9.2)0.37%—Openbsd LdapdAI30/9/20261/10/2026
In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication results are correlated only by the LDAP child process client file descriptor and LDAP message ID. After a connection closes, a later connection that reuses the same file descriptor and message ID can receive the earlier…
AplazadaCrítica (9.2)0.43%—PiscinaAI30/9/202630/9/2026
piscina is a node.js worker pool implementation. Prior to 4.9.4, 5.3.2, and 6.0.0-rc.5, Piscina stores ThreadPool.options in src/index.ts as a plain object that inherits from Object.prototype. Applications with a separate prototype-pollution primitive can therefore supply inherited values for security-sensitive…
AplazadaCrítica (10)0.80%—KobakoAI30/9/202630/9/2026
Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted Ruby scripts (LLM-generated code, user formulas, student submissions, third-party plugins) in-process without giving them access to host memory, files, network, or credentials. From version 0.1.0 to…
AplazadaCrítica (9.3)0.40%—Yii2 Starter KIT Yii2-starter-kitAI30/9/202630/9/2026
yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can access the debug endpoint to read sensitive data including session cookies and database queries, or access the Gii…
Pendiente de análisisCrítica (9.2)1.5%—DenoAI30/9/20262/10/2026
Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers can inject OS commands by passing untrusted arguments with the shell option, allowing arbitrary command execution with Deno process…
AplazadaCrítica (9.8)0.33%—Kylephillips Nested PagesAI30/9/202630/9/2026
Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions.
AplazadaCrítica (9.1)0.35%—Ptzoptics Move 4K 12XAIPtzoptics Move 4K 20XAIPtzoptics Move 4K 30XAIPtzoptics Link 4K 12XAI+3530/9/202630/9/2026
Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware update mechanism of affected PTZOptics cameras allows an unauthenticated user to install modified firmware on the device…
AplazadaCrítica (9.1)0.35%—Quenary TugtainerAI30/9/202630/9/2026
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs through the notification test endpoint. The /settings/test_notification endpoint accepts a…
AplazadaCrítica (9.8)0.64%💥 PoCQuenary TugtainerAI30/9/202630/9/2026
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer Agent allows unauthenticated access to Docker management APIs when AGENT_SECRET is not configured. The Agent uses request signatures to protect its API routes. However, in agent/auth.py, the signature…
AplazadaCrítica (9.4)0.60%—Quenary TugtainerAI30/9/202630/9/2026
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authentication can still be initiated even when OIDC_ENABLED=false. The /auth/oidc/enabled endpoint correctly reports that OIDC is disabled. However, a direct request to /auth/oidc/login still starts…
AplazadaCrítica (9)0.20%—Soft MachineAI30/9/20262/10/2026
Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, two authentication helpers in /app/server.js — verifyContainerAuth() and authenticateWorkspaceHttp() — accept the global CONTAINER_SHARED_SECRET as a bearer token without verifying which workspace the…
Pendiente de análisisCrítica (9.2)0.43%💥 PoCPythonAI30/9/20262/10/2026
A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create…
AnalizadaCrítica (9.4)0.63%⚠ Explotación activaZammad30/9/20267/10/2026
All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
AnalizadaCrítica (9.4)1.4%⚠ Explotación activa💥 PoCZammad30/9/20267/10/2026
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The bug is also present in version 7.0.0 to version 7.1.2, but not exploitable due to changes in the underlying framework.
Pendiente de análisisCrítica (9.3)0.26%—Internet2 GrouperAI30/9/202630/9/2026
In Internet2 Grouper before 7.5.1 (in some configurations), a user who is allowed to create or edit rules in the User Interface can escalate privileges.