Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
40.022 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.4) | 0.24% | — | Accellion Kiteworks | 30/9/2026 | 7/10/2026 | Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to. This could allow an attacker to associate a certificate with another user's account, affecting the confidentiality and integrity of that account's encrypted mail and, where certificate-based login is… | |
| Analizada | Crítica (9.3) | 0.29% | — | Accellion Kiteworks | 30/9/2026 | 7/10/2026 | A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to store crafted content that later executes arbitrary JavaScript in the authenticated session of an administrator who views the affected page. This could have permitted the attacker to gain full administrative… | |
| Analizada | Crítica (9.8) | 0.33% | — | Accellion Kiteworks | 30/9/2026 | 7/10/2026 | Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset that account's password without access to the emailed reset link and then authenticate as that user,… | |
| En análisis | Crítica (9.1) | 0.37% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email Protection Gateway did not consistently enforce administrator authentication, so the required password check could be bypassed. An attacker who referenced a valid administrator account… | |
| En análisis | Crítica (9.1) | 0.34% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise… | |
| En análisis | Crítica (9.1) | 0.23% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise… | |
| En análisis | Crítica (9.1) | 0.23% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise… | |
| En análisis | Crítica (9.1) | 0.27% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise… | |
| En análisis | Crítica (9.1) | 0.27% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery. Kiteworks Email Protection Gateway performed server-side fetches of URLs contained in the message content it processed, without adequately restricting the fetch destination. A remote, unauthenticated sender could… | |
| Pendiente de análisis | Crítica (9.2) | 0.40% | — | ES Iperf3AI | 30/9/2026 | 1/10/2026 | iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker dereferences a freed iperf_stream; fixed in 3.22. | |
| Aplazada | Crítica (9.2) | 0.37% | — | Openbsd LdapdAI | 30/9/2026 | 1/10/2026 | In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication results are correlated only by the LDAP child process client file descriptor and LDAP message ID. After a connection closes, a later connection that reuses the same file descriptor and message ID can receive the earlier… | |
| Aplazada | Crítica (9.2) | 0.43% | — | PiscinaAI | 30/9/2026 | 30/9/2026 | piscina is a node.js worker pool implementation. Prior to 4.9.4, 5.3.2, and 6.0.0-rc.5, Piscina stores ThreadPool.options in src/index.ts as a plain object that inherits from Object.prototype. Applications with a separate prototype-pollution primitive can therefore supply inherited values for security-sensitive… | |
| Aplazada | Crítica (10) | 0.80% | — | KobakoAI | 30/9/2026 | 30/9/2026 | Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted Ruby scripts (LLM-generated code, user formulas, student submissions, third-party plugins) in-process without giving them access to host memory, files, network, or credentials. From version 0.1.0 to… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Yii2 Starter KIT Yii2-starter-kitAI | 30/9/2026 | 30/9/2026 | yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can access the debug endpoint to read sensitive data including session cookies and database queries, or access the Gii… | |
| Pendiente de análisis | Crítica (9.2) | 1.5% | — | DenoAI | 30/9/2026 | 2/10/2026 | Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers can inject OS commands by passing untrusted arguments with the shell option, allowing arbitrary command execution with Deno process… | |
| Aplazada | Crítica (9.8) | 0.33% | — | Kylephillips Nested PagesAI | 30/9/2026 | 30/9/2026 | Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions. | |
| Aplazada | Crítica (9.1) | 0.35% | — | Ptzoptics Move 4K 12XAIPtzoptics Move 4K 20XAIPtzoptics Move 4K 30XAIPtzoptics Link 4K 12XAI+35 | 30/9/2026 | 30/9/2026 | Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware update mechanism of affected PTZOptics cameras allows an unauthenticated user to install modified firmware on the device… | |
| Aplazada | Crítica (9.1) | 0.35% | — | Quenary TugtainerAI | 30/9/2026 | 30/9/2026 | Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs through the notification test endpoint. The /settings/test_notification endpoint accepts a… | |
| Aplazada | Crítica (9.8) | 0.64% | 💥 PoC | Quenary TugtainerAI | 30/9/2026 | 30/9/2026 | Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer Agent allows unauthenticated access to Docker management APIs when AGENT_SECRET is not configured. The Agent uses request signatures to protect its API routes. However, in agent/auth.py, the signature… | |
| Aplazada | Crítica (9.4) | 0.60% | — | Quenary TugtainerAI | 30/9/2026 | 30/9/2026 | Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authentication can still be initiated even when OIDC_ENABLED=false. The /auth/oidc/enabled endpoint correctly reports that OIDC is disabled. However, a direct request to /auth/oidc/login still starts… | |
| Aplazada | Crítica (9) | 0.20% | — | Soft MachineAI | 30/9/2026 | 2/10/2026 | Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, two authentication helpers in /app/server.js — verifyContainerAuth() and authenticateWorkspaceHttp() — accept the global CONTAINER_SHARED_SECRET as a bearer token without verifying which workspace the… | |
| Pendiente de análisis | Crítica (9.2) | 0.43% | 💥 PoC | PythonAI | 30/9/2026 | 2/10/2026 | A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create… | |
| Analizada | Crítica (9.4) | 0.63% | ⚠ Explotación activa | Zammad | 30/9/2026 | 7/10/2026 | All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root. | |
| Analizada | Crítica (9.4) | 1.4% | ⚠ Explotación activa💥 PoC | Zammad | 30/9/2026 | 7/10/2026 | Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The bug is also present in version 7.0.0 to version 7.1.2, but not exploitable due to changes in the underlying framework. | |
| Pendiente de análisis | Crítica (9.3) | 0.26% | — | Internet2 GrouperAI | 30/9/2026 | 30/9/2026 | In Internet2 Grouper before 7.5.1 (in some configurations), a user who is allowed to create or edit rules in the User Interface can escalate privileges. |