Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

5400 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
En análisisAlta (8.8)0.42%—Cisco RoomosCisco Roomos Cloud15/7/202614/8/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by…
AnalizadaAlta (8.7)0.57%—F5 Big-ip Next Cloud-native Network FunctionsF5 Big-ip Next FOR KubernetesF5 Big-ip Next Service Proxy FOR Kubernetes15/7/20266/8/2026
When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Impact: System performance can degrade until the TMM process is either forced to restart or is manually restarted. This vulnerability allows a remote, unauthenticated attacker to cause a…
AplazadaAlta (7.1)0.32%—CloudreveAI15/7/202615/7/2026
Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, a Cloudreve WebDAV account rooted at a configured folder can send paths such as /dav/%2e%2e/outside.txt because stripPrefix in pkg/webdav/webdav.go joins the decoded request suffix to the account root with fs.URI.JoinRaw without checking…
AplazadaMedia (6.5)0.40%—CloudreveAI15/7/202615/7/2026
Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, Cloudreve's remote download workflow accepts user-supplied URLs at POST /api/v4/workflow/download and passes them to the configured downloader without blocking loopback, localhost, IPv6 localhost, or redirect-to-loopback targets, allowing…
AplazadaAlta (7.6)0.46%—CloudreveAI15/7/202615/7/2026
Cloudreve is a self-hosted file management and sharing system. From 4.12.0 until 4.16.1, Cloudreve's OAuth access tokens are issued without the OAuth client_id claim, so the JWT verifier does not load token scopes into request context and RequiredScopes treats the request like non-scoped session authentication,…
AnalizadaAlta (7.8)0.17%—Adobe Creative Cloud Desktop Application14/7/202628/8/2026
Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is…
AnalizadaAlta (7.8)0.23%—Adobe Creative Cloud Desktop Application14/7/202628/8/2026
Creative Cloud Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.
AnalizadaMedia (6.5)0.64%—Microsoft Azure Cyclecloud14/7/202622/7/2026
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)0.78%—Microsoft Azure Cyclecloud14/7/202622/7/2026
Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.2)0.52%💥 PoCMicrosoft Azure Spring Cloud14/7/202624/7/2026
Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network.
Pendiente de análisisAlta (8.4)0.53%—Rockwellautomation Factorytalk Datamosaix Private CloudAI14/7/202614/7/2026
A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows configuration. An authenticated attacker with high privileges can inject malicious scripts that are permanently stored on…
Pendiente de análisisAlta (7.5)0.44%—Cloudflare QuicheAI14/7/202614/7/2026
Summary Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to unbounded queuing of post-handshake client migration events. Impact quiche supports the connection migration features described in Section 9 of RFC 9000, which allows a single QUIC connection to survive changes in the…
AnalizadaAlta (7.5)0.53%—Cloudflare Quiche14/7/20266/8/2026
Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by means of specially crafted HTTP/3 frames. Impact HTTP/3 defines multiple frame types to support HTTP message exchanges and connection management. Each frame has a length and a payload whose length depends…
Pendiente de análisisCrítica (9.1)0.50%—SAP Commerce CloudAI14/7/202615/7/2026
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain…
Pendiente de análisisCrítica (9.4)0.35%—Google Cloud BigqueryAIGoogle DataformAIGoogle Colab EnterpriseAI13/7/202613/7/2026
A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Colab Enterprise, in the versions between October 2025 and May 10th, 2026, on Google Cloud Platform, allows an authenticated attacker to escalate privileges and perform cross-tenant repository…
AplazadaAlta (7.1)0.25%—Tagdiv Cloud LibraryAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Cloud Library td-cloud-library allows DOM-Based XSS.This issue affects tagDiv Cloud Library: from n/a through <= 3.9.4.
AplazadaCrítica (9.9)0.48%—Quantumcloud Woowbot PRO MAXAI13/7/202613/7/2026
Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue affects WoowBot Pro Max: from n/a through <= 14.1.7.
AplazadaCrítica (9.3)0.40%—Quantumcloud Simple Business Directory PROAI13/7/202613/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows SQL Injection.This issue affects Simple Business Directory Pro: from n/a through <= 15.9.4.
AplazadaMedia (6.5)0.22%—Quantumcloud Chatbot FOR Ecommerce WoowbotAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot for eCommerce &#8211; WoowBot woowbot-woocommerce-chatbot allows Stored XSS.This issue affects ChatBot for eCommerce &#8211; WoowBot: from n/a through <= 4.6.1.
AplazadaAlta (7.1)0.25%—Quantumcloud ChatbotAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot chatbot allows Stored XSS.This issue affects ChatBot: from n/a through <= 8.3.7.
AplazadaMedia (6.9)0.41%—Ragic Enterprise Cloud DatabaseAI13/7/202614/7/2026
Enterprise Cloud Database developed by Ragic has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload malicious files and make them available for users to download.
AplazadaMedia (5.3)0.34%—Ragic Enterprise Cloud DatabaseAI13/7/202614/7/2026
Enterprise Cloud Database developed by Ragic has a Stored Cross-Site Scripting vulnerability, allowing unauthenticated remote attackers to inject persistent JavaScript code executed in users' browsers upon page load.
AplazadaBaja (2.1)0.39%—Pig4cloud PIGAI13/7/202613/7/2026
A vulnerability was identified in pig-mesh Pig up to 3.9.2. Affected by this issue is some unknown functionality of the file \pig-master\pig-visual\pig-codegen\src\main\java\com\pig4cloud\pig\codegen\service\impl\GeneratorServiceImpl.java of the component pig-codegen. Such manipulation leads to code injection. It is…
AplazadaMedia (5.5)0.67%—Soniccloudorg Sonic-agentAI12/7/202614/7/2026
A vulnerability was determined in SonicCloudOrg sonic-agent up to 2.7.2. This affects an unknown function of the file sonic-server-controller/src/main/java/org/cloud/sonic/controller/controller/ExchangeController.java of the component JWT Authentication Filter. This manipulation causes code injection. The attack may…
AplazadaBaja (2.1)2.0%—Soniccloudorg Sonic-agentAI12/7/202613/7/2026
A vulnerability was found in SonicCloudOrg sonic-agent up to 2.7.2. The impacted element is the function evalIsFailed of the file sonic-agent/src/main/java/org/cloud/sonic/agent/tests/script/GroovyScriptImpl.java of the component Groovy Script Handler. The manipulation results in os command injection. The attack can…