Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
40.025 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.4) | 0.63% | ⚠ Explotación activa | Zammad | 30/9/2026 | 7/10/2026 | All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root. | |
| Analizada | Crítica (9.4) | 1.4% | ⚠ Explotación activa💥 PoC | Zammad | 30/9/2026 | 7/10/2026 | Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The bug is also present in version 7.0.0 to version 7.1.2, but not exploitable due to changes in the underlying framework. | |
| Pendiente de análisis | Crítica (9.3) | 0.26% | — | Internet2 GrouperAI | 30/9/2026 | 30/9/2026 | In Internet2 Grouper before 7.5.1 (in some configurations), a user who is allowed to create or edit rules in the User Interface can escalate privileges. | |
| Analizada | Crítica (10) | 0.79% | 💥 PoC | Ordasoft Joomla CCK | 30/9/2026 | 1/10/2026 | Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s… | |
| Analizada | Crítica (9.8) | 0.28% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature | |
| Analizada | Crítica (9.8) | 0.30% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution | |
| Analizada | Crítica (9.8) | 0.35% | — | Jetbrains Teamcity | 30/9/2026 | 2/10/2026 | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset | |
| Analizada | Crítica (10) | 0.45% | 💥 PoC | Joomcode JC Tables | 30/9/2026 | 6/10/2026 | Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The front-end CRUD API controller performs no Joomla token validation and no authentication check on any task. Table names, column names, and values are taken directly from request parameters and concatenated… | |
| Aplazada | Crítica (9.8) | 0.48% | 💥 PoC | Trex Digital Smart Manufacturing Systems Trex MESAI | 30/9/2026 | 30/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection. This issue affects Trex MES: through 2026-09-29. | |
| Aplazada | Crítica (9.3) | 0.62% | — | LightllmAI | 30/9/2026 | 30/9/2026 | LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserializes attacker-supplied arguments in the remote_infer_images method. Attackers can reach the visual RPyC port and pass objects with __reduce__ methods to execute arbitrary code with service… | |
| Pendiente de análisis | Crítica (9.4) | 0.26% | — | Litespeed WEB ServerAI | 30/9/2026 | 30/9/2026 | LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain "corner case." | |
| Aplazada | Crítica (9.8) | 0.26% | — | Dolusoft Software Technologies SoplogAI | 30/9/2026 | 30/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection. This issue affects SOPLOG: before Soplog 2026.9.4.1. | |
| Aplazada | Crítica (9.8) | 0.30% | — | Oauth Single Sign ON SSOAI | 30/9/2026 | 30/9/2026 | Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions. | |
| Aplazada | Crítica (9.8) | 0.39% | — | Booking ActivitiesAI | 30/9/2026 | 30/9/2026 | Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions. | |
| Aplazada | Crítica (9.3) | 0.29% | — | Books GalleryAI | 30/9/2026 | 30/9/2026 | Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions. | |
| Aplazada | Crítica (9.8) | 0.45% | — | EstatikAI | 30/9/2026 | 30/9/2026 | Subscriber Privilege Escalation in Estatik <= 4.3.5 versions. | |
| Aplazada | Crítica (10) | 0.60% | 💥 PoC | SiteskiteAI | 30/9/2026 | 30/9/2026 | Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions. | |
| Aplazada | Crítica (9) | 0.46% | — | Acymailing Smtp NewsletterAI | 30/9/2026 | 30/9/2026 | Unauthenticated Remote Code Execution (RCE) in AcyMailing SMTP Newsletter <= 11.0.5 versions. | |
| Analizada | Crítica (9.1) | 0.27% | — | Apache Wss4j | 30/9/2026 | 6/10/2026 | WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue. | |
| Analizada | Crítica (9.8) | 1.8% | ⚠ Explotación activa💥 PoC | Cisco Catalyst Sd-wan Manager | 30/9/2026 | 2/10/2026 | A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request… | |
| Aplazada | Crítica (9.2) | 0.38% | — | SogoAI | 30/9/2026 | 30/9/2026 | sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account. This issue was… | |
| Aplazada | Crítica (9.3) | 0.41% | — | Sogo YHNAI | 30/9/2026 | 30/9/2026 | sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user" to be treated as sent by a verified user without performing password validation. Since Nginx does not strip this header, any client can supply it arbitrarily and gain access as any user, including a privileged… | |
| Analizada | Crítica (9.8) | 0.57% | — | Apache Wss4j | 30/9/2026 | 2/10/2026 | An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix… | |
| Analizada | Crítica (9.1) | 0.21% | — | Apache Wss4j | 30/9/2026 | 6/10/2026 | In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the actual XML element path. A remote SOAP peer may therefore send a required element without the expected signature or encryption. Users are recommended to upgrade to… | |
| Pendiente de análisis | Crítica (9.1) | 0.38% | — | Apache Mina SshdAI | 30/9/2026 | 30/9/2026 | Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the… |