Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

5113 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.40%—Nvidia Nemo Megatron Bridge1/9/20262/9/2026
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
AnalizadaAlta (7.8)0.40%—Nvidia Nemo Megatron Bridge1/9/20262/9/2026
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
Pendiente de análisisAlta (7)0.14%—HP ImagediagsAI31/8/20263/9/2026
A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.0.0.36. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.
AnalizadaMedia (6.8)0.20%—Amazon Diagram-as-code27/8/20264/9/2026
A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0.10 through 0.23 can allow a third party to write arbitrary files to the local filesystem via crafted zip entry names containing path traversal sequences. This could allow the third party to perform…
AplazadaCrítica (9.3)3.4%—Zbtlink We1326AIZbtlink We357AIZbtlink We5926AIZbtlink We5926 WDAI+1227/8/202624/9/2026
Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1 firmware 20.0622 contain an unauthenticated…
AplazadaAlta (7.1)0.25%—CP Media PlayerAI27/8/202628/8/2026
Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.
AplazadaCrítica (9.8)0.47%—Super-diamond-serverAI26/8/202631/8/2026
The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. The module parameter is directly concatenated into the SQL IN clause through StringUtils.split() and string concatenation without being parameterized and bound.
AplazadaCrítica (9.8)0.61%—Super-diamond-serverAI26/8/202631/8/2026
The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project (including database passwords, API keys, etc.) by sending a TCP request without any credential.
Pendiente de análisisAlta (7.8)0.21%—DIAAI26/8/202628/8/2026
A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer. In plug-ins/wpg/wpg-import.c, the WPG import renderer allocates a fixed palette with: When handling a WPG_COLORMAP record, the parser reads a start index (i16) and number of colors (iNum16) from the file and reads…
AplazadaCrítica (9.8)0.64%—Diaowen DwsurveyAI26/8/20269/9/2026
DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters.
AplazadaMedia (6.9)0.52%—ZlmediakitAI26/8/202623/9/2026
ZLMediaKit confines the downloadFile API to a configured set of root directories with a prefix comparison that does not account for directory boundaries. The configuration loader in server/WebApi.cpp builds each root with File::absolutePath("", item, true); because the relative-path argument is empty that helper…
Pendiente de análisisAlta (7.8)0.20%—DIAAI26/8/202628/8/2026
A stack-based buffer overflow vulnerability exists in the Dia diagram editor when processing Network Bus objects from Dia XML project files. In objects/network/bus.c, bus_load() reads the number of bus handles from the file attribute "bus_handles" using attribute_num_data() without validating an upper bound: When a…
Pendiente de análisisMedia (6.1)0.15%—Drupal Media FoldersAI25/8/202628/8/2026
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Media Folders allows Stored XSS. This issue affects Media Folders versions: from 0.0.0 to 1.0.8.
AnalizadaAlta (8.1)0.49%—Nvidia Nemoclaw25/8/20261/9/2026
NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of service.
AnalizadaAlta (7.8)1.3%—Nvidia Nemoclaw25/8/20261/9/2026
NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
AnalizadaCrítica (9.8)0.99%—Nvidia Nemoclaw25/8/20261/9/2026
NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
AnalizadaAlta (8.8)0.32%—Nvidia Nemoclaw25/8/20261/9/2026
NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download of code without integrity check. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
AnalizadaAlta (7.8)1.3%—Nvidia Nemoclaw25/8/20261/9/2026
NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
AnalizadaCrítica (9.9)0.80%—Nvidia Openshell25/8/20261/9/2026
NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
AnalizadaAlta (8.5)0.63%—Nvidia Openshell25/8/20261/9/2026
NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit of this vulnerability might lead to information disclosure and data tampering.
AnalizadaAlta (8.8)2.6%—Nvidia Openshell25/8/20262/9/2026
NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
AnalizadaAlta (7.8)1.3%—Nvidia Nemoclaw25/8/20261/9/2026
NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
AnalizadaAlta (7.8)1.3%—Nvidia Nemoclaw25/8/20261/9/2026
NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
AnalizadaMedia (5.5)0.17%—Nvidia Nemoclaw25/8/20261/9/2026
NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive information. A successful exploit of this vulnerability might lead to information disclosure.
AnalizadaMedia (6.1)0.15%—Nvidia Nemoclaw25/8/20261/9/2026
NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successful exploit of this vulnerability might lead to information disclosure and data tampering.