Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

40.025 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.4)0.63%⚠ Explotación activaZammad30/9/20267/10/2026
All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
AnalizadaCrítica (9.4)1.4%⚠ Explotación activa💥 PoCZammad30/9/20267/10/2026
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The bug is also present in version 7.0.0 to version 7.1.2, but not exploitable due to changes in the underlying framework.
Pendiente de análisisCrítica (9.3)0.26%—Internet2 GrouperAI30/9/202630/9/2026
In Internet2 Grouper before 7.5.1 (in some configurations), a user who is allowed to create or edit rules in the User Interface can escalate privileges.
AnalizadaCrítica (10)0.79%💥 PoCOrdasoft Joomla CCK30/9/20261/10/2026
Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s…
AnalizadaCrítica (9.8)0.28%—Jetbrains Youtrack30/9/20262/10/2026
In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature
AnalizadaCrítica (9.8)0.30%—Jetbrains Youtrack30/9/20262/10/2026
In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution
AnalizadaCrítica (9.8)0.35%—Jetbrains Teamcity30/9/20262/10/2026
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset
AnalizadaCrítica (10)0.45%💥 PoCJoomcode JC Tables30/9/20266/10/2026
Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The front-end CRUD API controller performs no Joomla token validation and no authentication check on any task. Table names, column names, and values are taken directly from request parameters and concatenated…
AplazadaCrítica (9.8)0.48%💥 PoCTrex Digital Smart Manufacturing Systems Trex MESAI30/9/202630/9/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection. This issue affects Trex MES: through 2026-09-29.
AplazadaCrítica (9.3)0.62%—LightllmAI30/9/202630/9/2026
LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserializes attacker-supplied arguments in the remote_infer_images method. Attackers can reach the visual RPyC port and pass objects with __reduce__ methods to execute arbitrary code with service…
Pendiente de análisisCrítica (9.4)0.26%—Litespeed WEB ServerAI30/9/202630/9/2026
LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain "corner case."
AplazadaCrítica (9.8)0.26%—Dolusoft Software Technologies SoplogAI30/9/202630/9/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection. This issue affects SOPLOG: before Soplog 2026.9.4.1.
AplazadaCrítica (9.8)0.30%—Oauth Single Sign ON SSOAI30/9/202630/9/2026
Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions.
AplazadaCrítica (9.8)0.39%—Booking ActivitiesAI30/9/202630/9/2026
Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions.
AplazadaCrítica (9.3)0.29%—Books GalleryAI30/9/202630/9/2026
Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions.
AplazadaCrítica (9.8)0.45%—EstatikAI30/9/202630/9/2026
Subscriber Privilege Escalation in Estatik <= 4.3.5 versions.
AplazadaCrítica (10)0.60%💥 PoCSiteskiteAI30/9/202630/9/2026
Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions.
AplazadaCrítica (9)0.46%—Acymailing Smtp NewsletterAI30/9/202630/9/2026
Unauthenticated Remote Code Execution (RCE) in AcyMailing SMTP Newsletter <= 11.0.5 versions.
AnalizadaCrítica (9.1)0.27%—Apache Wss4j30/9/20266/10/2026
WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
AnalizadaCrítica (9.8)1.8%⚠ Explotación activa💥 PoCCisco Catalyst Sd-wan Manager30/9/20262/10/2026
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request…
AplazadaCrítica (9.2)0.38%—SogoAI30/9/202630/9/2026
sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account. This issue was…
AplazadaCrítica (9.3)0.41%—Sogo YHNAI30/9/202630/9/2026
sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user" to be treated as sent by a verified user without performing password validation. Since Nginx does not strip this header, any client can supply it arbitrarily and gain access as any user, including a privileged…
AnalizadaCrítica (9.8)0.57%—Apache Wss4j30/9/20262/10/2026
An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix…
AnalizadaCrítica (9.1)0.21%—Apache Wss4j30/9/20266/10/2026
In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the actual XML element path. A remote SOAP peer may therefore send a required element without the expected signature or encryption. Users are recommended to upgrade to…
Pendiente de análisisCrítica (9.1)0.38%—Apache Mina SshdAI30/9/202630/9/2026
Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the…