Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.1) | 1.6% | — | Zohocorp Manageengine Adselfservice Plus | 13/1/2026 | 17/6/2026 | Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations. | |
| Analizada | Media (5.7) | 0.42% | — | Rustfs | 8/1/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 through 1.0.0-alpha.78, a flawed `deny_only` short-circuit in RustFS IAM allows a restricted service account or STS credential to self-issue an unrestricted service account, inheriting the parent’s full privileges. This enables… | |
| Analizada | Media (5.7) | 0.43% | — | Rustfs | 8/1/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.79, he `ImportIam` admin API validates permissions using `ExportIAMAction` instead of `ImportIAMAction`, allowing a principal with export-only IAM permissions to perform import operations. Since importing IAM data performs… | |
| Aplazada | Crítica (9.3) | 0.33% | — | Wolfssl-pyAI | 7/1/2026 | 7/10/2026 | A vulnerability in the handling of verify_mode = CERT_REQUIRED in the wolfssl Python package (wolfssl-py) causes client certificate requirements to not be fully enforced. Because the WOLFSSL_VERIFY_FAIL_IF_NO_PEER_CERT flag was not included, the behavior effectively matched CERT_OPTIONAL: a peer certificate was… | |
| Analizada | Media (5.5) | 0.34% | — | Rustfs | 7/1/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.77, a malformed gRPC GetMetrics request causes get_metrics to unwrap() failed deserialization of metric_type/opts, panicking the handler thread and enabling remote denial of service of the metrics endpoint. This… | |
| Analizada | Alta (8.8) | 7.3% | 💥 PoC | Rustfs | 7/1/2026 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.78, RustFS contains a path traversal vulnerability in the /rustfs/rpc/read_file_stream endpoint. This issue has been patched in version 1.0.0-alpha.79. | |
| Analizada | Media (6.6) | 0.12% | — | Qualcomm Sa6150p FirmwareQualcomm Sa6155 FirmwareQualcomm Sa6155p FirmwareQualcomm Sa7255p Firmware+235 | 7/1/2026 | 7/10/2026 | Memory corruption while handling buffer mapping operations in the cryptographic driver. | |
| Analizada | Media (6.1) | 0.13% | — | Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Csra6620 Firmware+295 | 7/1/2026 | 7/10/2026 | Information disclosure while processing a firmware event. | |
| Analizada | Media (5.1) | 0.35% | — | Wolfssh | 6/1/2026 | 30/9/2026 | A heap buffer over-read vulnerability exists in the wolfSSH_CleanPath() function in wolfSSH. An authenticated remote attacker can trigger the issue via crafted SCP path input containing '/./' sequences, resulting in a heap over read by 1 byte. | |
| Analizada | Crítica (9.4) | 0.47% | — | Wolfssh | 6/1/2026 | 7/10/2026 | wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to send a bogus signature, or trick the client into skipping user authentication. This affects client applications with wolfSSH version 1.4.21 and earlier. Users of wolfSSH must update or apply the fix… | |
| Aplazada | Crítica (9.8) | 0.43% | 💥 PoC | FS Registration PasswordAI | 6/1/2026 | 7/10/2026 | The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.1. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change… | |
| Analizada | Crítica (9.8) | 32% | 💥 PoC | Rustfs | 30/12/2025 | 17/6/2026 | RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC authentication using a hardcoded static token `"rustfs rpc"` that is publicly exposed in the source code repository, hardcoded on both client and server sides, non-configurable with no mechanism for… | |
| Analizada | Media (6.8) | 0.33% | — | Pdfsam Enhanced | 23/12/2025 | 17/6/2026 | PDFsam Enhanced Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows phyiscally-present attackers to escalate privileges on affected installations of PDFsam Enhanced. An attacker must first obtain the ability to mount a malicious drive onto the target system in order to… | |
| Analizada | Alta (7) | 0.26% | — | Pdfsam Enhanced | 23/12/2025 | 17/6/2026 | PDFsam Enhanced XLS File Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDFsam Enhanced. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a… | |
| Analizada | Alta (7.8) | 0.31% | — | Pdfsam Enhanced | 23/12/2025 | 17/6/2026 | PDFsam Enhanced Launch Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDFsam Enhanced. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a… | |
| Analizada | Alta (7) | 0.26% | — | Pdfsam Enhanced | 23/12/2025 | 17/6/2026 | PDFsam Enhanced DOC File Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDFsam Enhanced. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a… | |
| Analizada | Alta (7.8) | 0.30% | — | Pdfsam Enhanced | 23/12/2025 | 17/6/2026 | PDFsam Enhanced App Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDFsam Enhanced. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious… | |
| Aplazada | Media (5.4) | 0.20% | — | Sparklewpthemes Sparkle FSEAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in sparklewpthemes Sparkle FSE sparkle-fse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sparkle FSE: from n/a through <= 1.0.9. | |
| Modificada | Alta (8.5) | 0.21% | — | Drbuho Buhontfs | 12/12/2025 | 7/10/2026 | BuhoNTFS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via insecure functions.This issue affects BuhoNTFS: 1.3.2. | |
| Aplazada | Baja (1) | 0.15% | — | WolfsslAI | 11/12/2025 | 17/6/2026 | Multiple constant-time implementations in wolfSSL before version 5.8.4 may be transformed into non-constant-time binary by LLVM optimizations, which can potentially result in observable timing discrepancies and lead to information disclosure through timing side-channel attacks. | |
| Analizada | Baja (2.3) | 0.13% | — | Wolfssl | 22/11/2025 | 17/6/2026 | With TLS 1.2 connections a client can use any digest, specifically a weaker digest that is supported, rather than those in the CertificateRequest. | |
| Analizada | Baja (1) | 0.29% | — | Wolfssl | 21/11/2025 | 17/6/2026 | Vulnerability in X25519 constant-time cryptographic implementations due to timing side channels introduced by compiler optimizations and CPU architecture limitations, specifically with the Xtensa-based ESP32 chips. If targeting Xtensa it is recommended to use the low memory implementations of X25519, which is now… | |
| Analizada | Media (6.3) | 0.43% | — | Wolfssl | 21/11/2025 | 17/6/2026 | Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to cause a denial-of-service by sending a crafted ClientHello message containing duplicate KeyShareEntry values for the same supported group, leading to excessive CPU and… | |
| Analizada | Baja (2.1) | 0.15% | — | Wolfssl | 21/11/2025 | 17/6/2026 | Improper input validation in the TLS 1.3 CertificateVerify signature algorithm negotiation in wolfSSL 5.8.2 and earlier on multiple platforms allows for downgrading the signature algorithm used. For example when a client sends ECDSA P521 as the supported signature algorithm the server previously could respond as ECDSA… | |
| Analizada | Baja (2.3) | 0.42% | — | Wolfssl | 21/11/2025 | 17/6/2026 | Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows a remote unauthenticated attacker to potentially cause a denial-of-service via a crafted ClientHello message with duplicate CKS extensions. |