Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
2676 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 1.5% | — | Fortra Core Privileged Access Manager Server | 15/6/2026 | 28/7/2026 | Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing. | |
| Aplazada | Crítica (9.8) | 0.49% | 💥 PoC | Doctreat CoreAI | 10/6/2026 | 7/10/2026 | The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8. This is due to the doctreat_process_registration() function not properly restricting the roles that a user can register with. This makes it possible for unauthenticated attackers to register as an… | |
| Modificada | Alta (7.5) | 2.4% | — | Microsoft Asp.net CoreMicrosoft Visual Studio 2026Microsoft .net | 9/6/2026 | 23/7/2026 | Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |
| Pendiente de análisis | Alta (7.5) | 1.1% | — | Micrometer-coreAIMicrometer-jetty11AIMicrometer-jetty12AI | 9/6/2026 | 14/9/2026 | In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Affected versions: micrometer-core 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18; 1.9.0 through 1.9.17. micrometer-jetty11 1.16.0… | |
| Pendiente de análisis | Alta (8.8) | 0.34% | — | Agentcore CLIAI | 8/6/2026 | 23/7/2026 | Improper neutralization of triple-quote characters during Python code generation in AgentCore CLI before v0.14.2 might allow an authenticated remote threat actor to execute arbitrary code on AWS AgentCore Runtime under the imported agent's IAM execution role and on the local environment of another user in the same AWS… | |
| Analizada | Alta (7.1) | 0.17% | — | Ericsson Packet Core Controller | 5/6/2026 | 7/10/2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degradation. | |
| Analizada | Alta (7.1) | 0.27% | — | Ericsson Packet Core Gateway | 5/6/2026 | 17/6/2026 | Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers from the crashes… | |
| Analizada | Alta (7.1) | 0.27% | — | Ericsson Packet Core Gateway | 5/6/2026 | 17/6/2026 | Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers from the crashes… | |
| Analizada | Alta (7.1) | 0.27% | — | Ericsson Packet Core Gateway | 5/6/2026 | 17/6/2026 | Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Syntactically Invalid Structure (CWE-228) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers… | |
| Pendiente de análisis | Alta (7.8) | 0.22% | — | Ansible-coreAI | 5/6/2026 | 15/9/2026 | A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows… | |
| Aplazada | Alta (8.2) | 0.55% | 💥 PoC | CoreshopAIPimcoreAI | 4/6/2026 | 6/10/2026 | CoreShop is a Pimcore enhanced eCommerce solution. In versions 5.0.1 through 5.1.0-beta.1,, the GitHub Actions workflow (`.github/workflows/static.yml`) uses the `pull_request_target` trigger but dangerously checks out the unverified code from the pull request head (`ref: ${{ github.event.pull_request.head.ref }}`).… | |
| Pendiente de análisis | Alta (8.7) | 0.28% | — | Draeger CoreAIDraeger M540 Converter ServiceAI | 2/6/2026 | 22/7/2026 | Dräger Core 1.0.5 and Dräger M540 Converter Service 1.0.9 contain a denial of service vulnerability that allows network-adjacent attackers to trigger high CPU load by sending specially crafted, unencrypted SDC messages during the discovery process. Attackers with access to the hospital network can send malformed SDC… | |
| Aplazada | Media (4.3) | 0.15% | — | Thimpress Thim CoreAI | 2/6/2026 | 22/7/2026 | Missing Authorization vulnerability in ThimPress Thim Core allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Thim Core: from n/a through 2.3.3. | |
| Aplazada | Alta (8.8) | 0.24% | — | Thimpress Thim CoreAI | 2/6/2026 | 5/10/2026 | Missing Authorization vulnerability in ThimPress Thim Core thim-core.This issue affects Thim Core: from n/a through 2.3.3. | |
| Pendiente de análisis | Alta (7.8) | 0.18% | — | PC Tools Internet SecurityAIPC Tools Pctcore64AI | 1/6/2026 | 22/7/2026 | Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access the PCTCoreDriver WDM device interface and invoke privileged IOCTL handlers. A local attacker with the ability to access or load the affected driver can exploit this vulnerability to… | |
| Rechazada | Sin puntuar | — | — | Quay ClaircoreAIRedhat ClairAI | 1/6/2026 | 27/7/2026 | Rejected reason: Retracted following review by Red Hat Product Security and confirmation from the upstream Clair/Claircore maintainer. This CVE misattributes the described behavior to github.com/quay/claircore: the authentication mechanism in question (optional PSK, HTTP endpoint /indexer/api/v1/index_report) is… | |
| Analizada | Crítica (9.6) | 0.48% | — | Jpettitt Meshcore Card | 28/5/2026 | 17/6/2026 | MeshCore Card provides MeshCore Lovelace card for Home Assistant. Prior to 0.3.3, Meshcore node names are rendered without HTML escaping in meshcore-card, allowing any node within direct or indirect (repeated) radio range to execute arbitrary javascript in the Home Assistant frontend of anyone viewing the card. This… | |
| Aplazada | Baja (2.9) | 0.55% | — | Qos.ch Logback-coreAI | 28/5/2026 | 17/6/2026 | Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted. More precisely, an attacker able to influence serialized data sent to SimpleSocketServer or SimpleSSLSocketServer can instantiate… | |
| Aplazada | Alta (7.3) | 0.49% | — | Smsgate Sms-coreAI | 28/5/2026 | 17/6/2026 | An issue in SMSGate sms-core<=2.1.13.6 allows a remote attacker to execute arbitrary code via the Cmpp7FDeliverRequestMessageCodec.java component | |
| Aplazada | Alta (8.2) | 0.51% | — | RVF SET GETAIRVF CoreAIRemixAIFacebook React RouterAI | 27/5/2026 | 17/6/2026 | RVF (formerly Remix Validated Form) provides easy form validation and state management for React. From 6.0.0 to before 6.0.4 and 7.0.2, setPath in @rvf/set-get (used by @rvf/core to flatten incoming form data into a nested object) does not block the keys __proto__, constructor, or prototype when walking a path.… | |
| Aplazada | Media (6.1) | 0.23% | — | Ella CoreAI | 27/5/2026 | 17/6/2026 | Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core does not verify the UE Security Capabilities received in NGAP PathSwitchRequest messages against its locally stored values. A malicious gNB can overwrite Ella Core's stored UE security capabilities for any UE with arbitrary values by… | |
| Aplazada | Baja (3.7) | 0.20% | — | Ella CoreAI | 27/5/2026 | 17/6/2026 | Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core didn't enforce security rules on concurrent running of security procedures defined in TS 33.501 §6.9.5.1 — it could send a NAS Security Mode Command while an N2 handover was still pending (and vice versa). Concurrent Security Mode Command… | |
| Aplazada | Alta (7.1) | 0.27% | — | Ella CoreAI | 27/5/2026 | 17/6/2026 | Ella Core is a 5G core designed for private networks. Prior to 1.10.0, a radio with a valid NG Setup can send a forged PDUSessionResourceSetupResponse carrying any UE's AMF-UE-NGAP-ID. Ella Core does not verify the message arrived on the SCTP association bound to that UE's logical NG-connection, then creates a GTP… | |
| Aplazada | Crítica (10) | 1.6% | 💥 Exploit | Dotcms CoreAI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish Audit API endpoints (/api/auditPublishing/get and /api/auditPublishing/getAll) in dotCMS Core 25.11.04-1 through 26.04.28-02 allows remote unauthenticated attackers to read, modify, or destroy arbitrary database… | |
| Aplazada | Baja (2.4) | 0.18% | — | Creative Core APP LockAI | 26/5/2026 | 24/7/2026 | Easyelife App lock (aka Fingerprint,Applock or locker.app.safe.applocker) 1.9.2 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interface flows - insecure navigation… |