Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
8451 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.43% | — | ISC BindAI | 25/6/2026 | 25/6/2026 | Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of DNSSEC records served by that server to fail. | |
| Aplazada | Media (5.3) | 0.45% | — | ISC BindAI | 25/6/2026 | 25/6/2026 | — | |
| Aplazada | Media (5.3) | 0.70% | — | ISC BindAI | 25/6/2026 | 25/6/2026 | An attacker can send crafted DNS over HTTP/3 queries, triggering an exception that prevents some buffer from being freed right away. The buffer will be freed at the end of the QUIC connection, but on some setups it might be possible to open enough concurrent DoH3 streams to trigger an out-of-memory condition,… | |
| Aplazada | Baja (3.7) | 0.40% | — | ISC BindAI | 25/6/2026 | 25/6/2026 | An attacker might be able to delay the processing of DoH3 queries by sending DoH3 GET queries with an invalid DATA frame. | |
| Aplazada | Alta (8.1) | 0.45% | — | PiscinaAI | 22/6/2026 | 23/6/2026 | piscina is a node.js worker pool implementation. Prior to 6.0.0-rc.2, 5.2.0, and 4.9.3, piscina's constructor and run() paths read the filename option via plain member access. Both reads fall through the prototype chain when the caller's options object doesn't have filename as an own property. When… | |
| Aplazada | Alta (7.5) | 0.61% | — | Steeltoe Discovery EurekaAI | 17/6/2026 | 22/6/2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Discovery.Eureka prior to versions 4.2.0 and 3.4.0, `DataCenterInfo.FromJson` throws `ArgumentException` for any `name` value other than `"MyOwn"` or `"Amazon"`, despite the Java… | |
| Analizada | Media (4.3) | 0.20% | — | Cisco Webex WEB APP | 17/6/2026 | 22/6/2026 | A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker to redirect users to a malicious webpage. Cisco has addressed this vulnerability in the Cisco Webex App, and no customer action is needed. This vulnerability existed due to improper input validation… | |
| Analizada | Media (6) | 0.10% | — | Cisco Umbrella Virtual Appliance | 17/6/2026 | 22/6/2026 | A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied commands. An attacker with vmadmin privileges could exploit this vulnerability by using… | |
| Analizada | Media (6.3) | 0.25% | — | Cisco Crosswork Network Controller | 17/6/2026 | 22/6/2026 | A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. | |
| Modificada | Crítica (9.2) | 6.5% | 💥 PoC | F5 DOSF5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance Manager+7 | 17/6/2026 | 14/9/2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the… | |
| Analizada | Alta (7.5) | 0.50% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 17/6/2026 | 25/9/2026 | A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected… | |
| Analizada | Crítica (9.1) | 8.9% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 17/6/2026 | 25/9/2026 | A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Outsourced Manufacturing FOR Discrete Industries | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Outsourced Mfg for Discrete Industries product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Outsourced… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Outsourced Manufacturing FOR Discrete Industries | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Outsourced Mfg for Discrete Industries product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Outsourced… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle In-memory Cost Management FOR Discrete Industries | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle In-Memory Cost Management for Discrete Industries product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.12-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise… | |
| Pendiente de análisis | Alta (8.8) | 0.49% | — | WickedAIISC DhcpAI | 16/6/2026 | 18/6/2026 | Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious DHCP server to execute code on the local machine. | |
| Aplazada | Media (5.4) | 0.13% | — | Sony Optical Disc ArchiveAI | 16/6/2026 | 17/6/2026 | Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and earlier. If this vulnerability is exploited, arbitrary code may be executed with SYSTEM privileges. | |
| Aplazada | Alta (8.1) | 1.9% | — | Kanishka-linux ReminiscenceAI | 15/6/2026 | 17/6/2026 | An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying a crafted input. | |
| Aplazada | Crítica (9.8) | 2.8% | — | Kanishka-linux ReminiscenceAI | 15/6/2026 | 17/6/2026 | An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying a crafted input. | |
| Aplazada | Alta (8.6) | 0.74% | — | Discuz X5AI | 15/6/2026 | 17/6/2026 | Discuz! X5.0 releases 20260320 through 20260610 contain a local file inclusion vulnerability that allows authenticated administrators to execute arbitrary code by importing a specially crafted plugin configuration containing path traversal sequences in the directory attribute. Attackers can trigger an exception during… | |
| Aplazada | Media (6.9) | 0.48% | — | Discuz X5AI | 15/6/2026 | 17/6/2026 | Discuz! X5.0 releases 20260320 through 20260610 contains a CAPTCHA bypass vulnerability that allows unauthenticated remote attackers to defeat challenge controls by exploiting limited complexity and predictable character sets in generated CAPTCHA images. Attackers can train a custom optical character recognition model… | |
| Aplazada | Crítica (9.3) | 3.7% | 💥 Exploit | Discuz X5AI | 15/6/2026 | 17/6/2026 | Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain unauthorized access to database backup and restore functionality by exploiting a shared cryptographic key between UCenter integration and the database backup API exposed… | |
| Analizada | Media (6.5) | 28% | ⚠ Explotación activa💥 PoC | Cisco Catalyst Sd-wan Manager | 15/6/2026 | 24/7/2026 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate user-supplied input… | |
| Analizada | Media (5.3) | 0.36% | — | Discourse | 12/6/2026 | 17/6/2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, DetailedTagSerializer#tag_group_names returned every tag group a tag belonged to without filtering against the requesting user's visibility.… | |
| Analizada | Media (4.3) | 0.36% | — | Discourse | 12/6/2026 | 17/6/2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, the MessageBus.publish call for /web_hook_events/<id> in Jobs::RedeliverWebHookEvents did not pass group_ids, leaving the channel readable by… |