Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
5113 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.40% | — | Nvidia Nemo Megatron Bridge | 1/9/2026 | 2/9/2026 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | |
| Analizada | Alta (7.8) | 0.40% | — | Nvidia Nemo Megatron Bridge | 1/9/2026 | 2/9/2026 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | |
| Pendiente de análisis | Alta (7) | 0.14% | — | HP ImagediagsAI | 31/8/2026 | 3/9/2026 | A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.0.0.36. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls. | |
| Analizada | Media (6.8) | 0.20% | — | Amazon Diagram-as-code | 27/8/2026 | 4/9/2026 | A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0.10 through 0.23 can allow a third party to write arbitrary files to the local filesystem via crafted zip entry names containing path traversal sequences. This could allow the third party to perform… | |
| Aplazada | Crítica (9.3) | 3.4% | — | Zbtlink We1326AIZbtlink We357AIZbtlink We5926AIZbtlink We5926 WDAI+12 | 27/8/2026 | 24/9/2026 | Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1 firmware 20.0622 contain an unauthenticated… | |
| Aplazada | Alta (7.1) | 0.25% | — | CP Media PlayerAI | 27/8/2026 | 28/8/2026 | Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Super-diamond-serverAI | 26/8/2026 | 31/8/2026 | The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. The module parameter is directly concatenated into the SQL IN clause through StringUtils.split() and string concatenation without being parameterized and bound. | |
| Aplazada | Crítica (9.8) | 0.61% | — | Super-diamond-serverAI | 26/8/2026 | 31/8/2026 | The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project (including database passwords, API keys, etc.) by sending a TCP request without any credential. | |
| Pendiente de análisis | Alta (7.8) | 0.21% | — | DIAAI | 26/8/2026 | 28/8/2026 | A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer. In plug-ins/wpg/wpg-import.c, the WPG import renderer allocates a fixed palette with: When handling a WPG_COLORMAP record, the parser reads a start index (i16) and number of colors (iNum16) from the file and reads… | |
| Aplazada | Crítica (9.8) | 0.64% | — | Diaowen DwsurveyAI | 26/8/2026 | 9/9/2026 | DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters. | |
| Aplazada | Media (6.9) | 0.52% | — | ZlmediakitAI | 26/8/2026 | 23/9/2026 | ZLMediaKit confines the downloadFile API to a configured set of root directories with a prefix comparison that does not account for directory boundaries. The configuration loader in server/WebApi.cpp builds each root with File::absolutePath("", item, true); because the relative-path argument is empty that helper… | |
| Pendiente de análisis | Alta (7.8) | 0.20% | — | DIAAI | 26/8/2026 | 28/8/2026 | A stack-based buffer overflow vulnerability exists in the Dia diagram editor when processing Network Bus objects from Dia XML project files. In objects/network/bus.c, bus_load() reads the number of bus handles from the file attribute "bus_handles" using attribute_num_data() without validating an upper bound: When a… | |
| Pendiente de análisis | Media (6.1) | 0.15% | — | Drupal Media FoldersAI | 25/8/2026 | 28/8/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Media Folders allows Stored XSS. This issue affects Media Folders versions: from 0.0.0 to 1.0.8. | |
| Analizada | Alta (8.1) | 0.49% | — | Nvidia Nemoclaw | 25/8/2026 | 1/9/2026 | NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of service. | |
| Analizada | Alta (7.8) | 1.3% | — | Nvidia Nemoclaw | 25/8/2026 | 1/9/2026 | NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service. | |
| Analizada | Crítica (9.8) | 0.99% | — | Nvidia Nemoclaw | 25/8/2026 | 1/9/2026 | NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering. | |
| Analizada | Alta (8.8) | 0.32% | — | Nvidia Nemoclaw | 25/8/2026 | 1/9/2026 | NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download of code without integrity check. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering. | |
| Analizada | Alta (7.8) | 1.3% | — | Nvidia Nemoclaw | 25/8/2026 | 1/9/2026 | NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering. | |
| Analizada | Crítica (9.9) | 0.80% | — | Nvidia Openshell | 25/8/2026 | 1/9/2026 | NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. | |
| Analizada | Alta (8.5) | 0.63% | — | Nvidia Openshell | 25/8/2026 | 1/9/2026 | NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit of this vulnerability might lead to information disclosure and data tampering. | |
| Analizada | Alta (8.8) | 2.6% | — | Nvidia Openshell | 25/8/2026 | 2/9/2026 | NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | |
| Analizada | Alta (7.8) | 1.3% | — | Nvidia Nemoclaw | 25/8/2026 | 1/9/2026 | NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service. | |
| Analizada | Alta (7.8) | 1.3% | — | Nvidia Nemoclaw | 25/8/2026 | 1/9/2026 | NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service. | |
| Analizada | Media (5.5) | 0.17% | — | Nvidia Nemoclaw | 25/8/2026 | 1/9/2026 | NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive information. A successful exploit of this vulnerability might lead to information disclosure. | |
| Analizada | Media (6.1) | 0.15% | — | Nvidia Nemoclaw | 25/8/2026 | 1/9/2026 | NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successful exploit of this vulnerability might lead to information disclosure and data tampering. |