Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

1804 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.1)1.6%—Zohocorp Manageengine Adselfservice Plus13/1/202617/6/2026
Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations.
AnalizadaMedia (5.7)0.42%—Rustfs8/1/202617/6/2026
RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 through 1.0.0-alpha.78, a flawed `deny_only` short-circuit in RustFS IAM allows a restricted service account or STS credential to self-issue an unrestricted service account, inheriting the parent’s full privileges. This enables…
AnalizadaMedia (5.7)0.43%—Rustfs8/1/202617/6/2026
RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.79, he `ImportIam` admin API validates permissions using `ExportIAMAction` instead of `ImportIAMAction`, allowing a principal with export-only IAM permissions to perform import operations. Since importing IAM data performs…
AplazadaCrítica (9.3)0.33%—Wolfssl-pyAI7/1/20267/10/2026
A vulnerability in the handling of verify_mode = CERT_REQUIRED in the wolfssl Python package (wolfssl-py) causes client certificate requirements to not be fully enforced. Because the WOLFSSL_VERIFY_FAIL_IF_NO_PEER_CERT flag was not included, the behavior effectively matched CERT_OPTIONAL: a peer certificate was…
AnalizadaMedia (5.5)0.34%—Rustfs7/1/202617/6/2026
RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.77, a malformed gRPC GetMetrics request causes get_metrics to unwrap() failed deserialization of metric_type/opts, panicking the handler thread and enabling remote denial of service of the metrics endpoint. This…
AnalizadaAlta (8.8)7.3%💥 PoCRustfs7/1/202617/6/2026
RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.78, RustFS contains a path traversal vulnerability in the /rustfs/rpc/read_file_stream endpoint. This issue has been patched in version 1.0.0-alpha.79.
AnalizadaMedia (6.6)0.12%—Qualcomm Sa6150p FirmwareQualcomm Sa6155 FirmwareQualcomm Sa6155p FirmwareQualcomm Sa7255p Firmware+2357/1/20267/10/2026
Memory corruption while handling buffer mapping operations in the cryptographic driver.
AnalizadaMedia (6.1)0.13%—Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Csr8811 FirmwareQualcomm Csra6620 Firmware+2957/1/20267/10/2026
Information disclosure while processing a firmware event.
AnalizadaMedia (5.1)0.35%—Wolfssh6/1/202630/9/2026
A heap buffer over-read vulnerability exists in the wolfSSH_CleanPath() function in wolfSSH. An authenticated remote attacker can trigger the issue via crafted SCP path input containing '/./' sequences, resulting in a heap over read by 1 byte.
AnalizadaCrítica (9.4)0.47%—Wolfssh6/1/20267/10/2026
wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to send a bogus signature, or trick the client into skipping user authentication. This affects client applications with wolfSSH version 1.4.21 and earlier. Users of wolfSSH must update or apply the fix…
AplazadaCrítica (9.8)0.43%💥 PoCFS Registration PasswordAI6/1/20267/10/2026
The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.1. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change…
AnalizadaCrítica (9.8)32%💥 PoCRustfs30/12/202517/6/2026
RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC authentication using a hardcoded static token `"rustfs rpc"` that is publicly exposed in the source code repository, hardcoded on both client and server sides, non-configurable with no mechanism for…
AnalizadaMedia (6.8)0.33%—Pdfsam Enhanced23/12/202517/6/2026
PDFsam Enhanced Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows phyiscally-present attackers to escalate privileges on affected installations of PDFsam Enhanced. An attacker must first obtain the ability to mount a malicious drive onto the target system in order to…
AnalizadaAlta (7)0.26%—Pdfsam Enhanced23/12/202517/6/2026
PDFsam Enhanced XLS File Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDFsam Enhanced. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a…
AnalizadaAlta (7.8)0.31%—Pdfsam Enhanced23/12/202517/6/2026
PDFsam Enhanced Launch Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDFsam Enhanced. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a…
AnalizadaAlta (7)0.26%—Pdfsam Enhanced23/12/202517/6/2026
PDFsam Enhanced DOC File Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDFsam Enhanced. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a…
AnalizadaAlta (7.8)0.30%—Pdfsam Enhanced23/12/202517/6/2026
PDFsam Enhanced App Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDFsam Enhanced. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious…
AplazadaMedia (5.4)0.20%—Sparklewpthemes Sparkle FSEAI18/12/202517/6/2026
Missing Authorization vulnerability in sparklewpthemes Sparkle FSE sparkle-fse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sparkle FSE: from n/a through <= 1.0.9.
ModificadaAlta (8.5)0.21%—Drbuho Buhontfs12/12/20257/10/2026
BuhoNTFS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via insecure functions.This issue affects BuhoNTFS: 1.3.2.
AplazadaBaja (1)0.15%—WolfsslAI11/12/202517/6/2026
Multiple constant-time implementations in wolfSSL before version 5.8.4 may be transformed into non-constant-time binary by LLVM optimizations, which can potentially result in observable timing discrepancies and lead to information disclosure through timing side-channel attacks.
AnalizadaBaja (2.3)0.13%—Wolfssl22/11/202517/6/2026
With TLS 1.2 connections a client can use any digest, specifically a weaker digest that is supported, rather than those in the CertificateRequest.
AnalizadaBaja (1)0.29%—Wolfssl21/11/202517/6/2026
Vulnerability in X25519 constant-time cryptographic implementations due to timing side channels introduced by compiler optimizations and CPU architecture limitations, specifically with the Xtensa-based ESP32 chips. If targeting Xtensa it is recommended to use the low memory implementations of X25519, which is now…
AnalizadaMedia (6.3)0.43%—Wolfssl21/11/202517/6/2026
Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to cause a denial-of-service by sending a crafted ClientHello message containing duplicate KeyShareEntry values for the same supported group, leading to excessive CPU and…
AnalizadaBaja (2.1)0.15%—Wolfssl21/11/202517/6/2026
Improper input validation in the TLS 1.3 CertificateVerify signature algorithm negotiation in wolfSSL 5.8.2 and earlier on multiple platforms allows for downgrading the signature algorithm used. For example when a client sends ECDSA P521 as the supported signature algorithm the server previously could respond as ECDSA…
AnalizadaBaja (2.3)0.42%—Wolfssl21/11/202517/6/2026
Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows a remote unauthenticated attacker to potentially cause a denial-of-service via a crafted ClientHello message with duplicate CKS extensions.