Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
4530 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.18% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+241 | 4/5/2026 | 7/10/2026 | Transient DOS when processing target power rate tables during channel configuration. | |
| Pendiente de análisis | Alta (8.3) | 0.57% | — | Redhat Ansible Automation PlatformAI | 4/5/2026 | 26/8/2026 | A flaw was found in the AAP gateway. The user auto-link strategy, introduced in AAP 2.6, automatically links an external Identity Provider (IDP) identity to an existing AAP user account based on email matching without verifying email ownership. This allows a remote attacker to potentially hijack a victim's account or… | |
| Aplazada | Media (5.5) | 0.79% | — | Crocodilestick Calibre-web-automatedAI | 4/5/2026 | 17/6/2026 | A flaw has been found in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this issue is some unknown functionality of the file cps/cwa_functions.py of the component Admin Endpoint. This manipulation causes missing authentication. It is possible to initiate the attack remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.46% | — | Crocodilestick Calibre-web-automatedAI | 4/5/2026 | 17/6/2026 | A vulnerability was detected in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this vulnerability is the function generate_auth_token of the file cps/kobo_auth.py of the component Kobo auth-token Route. The manipulation results in improper authorization. The attack may be performed from remote. The… | |
| Analizada | Alta (7.1) | 0.30% | — | Linuxfoundation Automotive Grade Linux | 1/5/2026 | 17/6/2026 | AGL agl-service-can-low-level thru 17.1.12 contains a heap buffer over-read in the isotp-c library. In isotp_continue_receive (receive.c:87-89), the payload_length for a Single Frame is extracted from a 4-bit nibble in the CAN frame data, yielding values 0-15. However, a standard CAN frame is only 8 bytes, with… | |
| Analizada | Crítica (9.8) | 0.85% | — | Linuxfoundation Automotive Grade Linux | 1/5/2026 | 17/6/2026 | AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367) in the widget installation flow. The is_valid_filename function in wgtpkg-zip.c validates ZIP entry names but does not check for dot notation directory traversal sequences it… | |
| Analizada | Alta (7.5) | 0.53% | — | Linuxfoundation Automotive Grade Linux | 1/5/2026 | 17/6/2026 | AGL agl-service-can-low-level thru 17.1.12 contains a stack buffer overflow in the uds-c library. The send_diagnostic_request function in uds.c allocates a 6-byte stack buffer (MAX_DIAGNOSTIC_PAYLOAD_SIZE=6) but copies up to 7 bytes (MAX_UDS_REQUEST_PAYLOAD_LENGTH=7) via memcpy at an offset of 1+pid_length (2-3… | |
| Analizada | Alta (7.8) | 0.18% | — | Linuxfoundation Automotive Grade Linux | 1/5/2026 | 17/6/2026 | AGL app-framework-binder (afb-daemon) through v19.90.0 allows any local process to execute privileged supervision commands (Exit, Do, Sclose, Config, Trace, Debug, Token, slist) without authentication via the abstract Unix socket @urn:AGL:afs:supervision:socket. The on_supervision_call function in… | |
| Analizada | Alta (7.8) | 0.16% | — | Linuxfoundation Automotive Grade Linux | 1/5/2026 | 17/6/2026 | AGL app-framework-binder (afb-daemon) through v19.90.0 contains a privilege escalation vulnerability in the supervision Do command. The on_supervision_call function in src/afb-supervision.c explicitly nullifies the request credentials by calling afb_context_change_cred(&xreq->context, NULL) before dispatching an… | |
| Analizada | Alta (8.8) | 0.50% | — | Progress Moveit Automation | 30/4/2026 | 17/6/2026 | Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue affects MOVEit Automation: from 2025.1.0 before 2025.1.5, from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0. | |
| Analizada | Crítica (9.8) | 0.61% | — | Progress Moveit Automation | 30/4/2026 | 17/6/2026 | Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass. This issue affects MOVEit Automation: from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0. | |
| Aplazada | Baja (2.1) | 0.45% | 💥 PoC | Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI | 29/4/2026 | 17/6/2026 | A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=register of the component Registration. The manipulation of the argument student_id/full_name/section/username results in cross site… | |
| Aplazada | Baja (2.1) | 0.35% | — | Dh1011 Auto-faviconAI | 27/4/2026 | 17/6/2026 | A vulnerability was found in dh1011 auto-favicon up to f189116a9259950c2393f114dbcb94dde0ad864b. This issue affects the function generate_favicon_from_url of the file src/auto_favicon/server.py of the component MCP Tool. The manipulation of the argument image_url results in server-side request forgery. The attack may… | |
| Aplazada | Crítica (9.8) | 0.93% | — | Leonvanzyl AutocoderAI | 27/4/2026 | 5/7/2026 | A remote code execution (RCE) vulnerability in the /devserver/start endpoint of leonvanzyl autocoder commit 79d02a allows attackers to execute arbitrary code via providing a crafted command parameter. | |
| Aplazada | Alta (7.5) | 0.52% | — | Leonvanzyl AutocoderAI | 27/4/2026 | 17/6/2026 | A path traversal vulnerability in the UI/static component of leonvanzyl autocoder commit 79d02a allows attackers to read arbitrary files via sending crafted URL path containing traversal sequences. | |
| Analizada | Alta (7.1) | 0.13% | — | Connectwise Automate | 20/4/2026 | 17/6/2026 | ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where certain client-to-server communications could occur without transport-layer encryption. This could allow network‑based interception of Solution Center traffic in Automate… | |
| Pendiente de análisis | Media (5.3) | 0.41% | — | Redhat Ansible Automation PlatformAI | 17/4/2026 | 17/6/2026 | A flaw was found in the AAP MCP server. An unauthenticated remote attacker can exploit a log injection vulnerability by sending specially crafted input to the `toolsetroute` parameter. This parameter is not properly sanitized before being written to logs, allowing the attacker to inject control characters such as… | |
| Analizada | Alta (7.1) | 0.29% | — | Autodesk Fusion | 14/4/2026 | 17/6/2026 | A maliciously crafted HTML payload in an assembly variant name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or… | |
| Analizada | Alta (7.1) | 0.29% | — | Autodesk Fusion | 14/4/2026 | 17/6/2026 | A maliciously crafted HTML payload, stored in a design name and exported to CSV, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current… | |
| Analizada | Alta (7.1) | 0.29% | — | Autodesk Fusion | 14/4/2026 | 17/6/2026 | A maliciously crafted HTML payload in a component name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute… | |
| Analizada | Baja (2) | 0.18% | — | Paloaltonetworks Autonomous Digital Experience Manager | 13/4/2026 | 7/7/2026 | A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. | |
| Analizada | Media (6.4) | 0.14% | — | Redhat Process Automation Manager | 8/4/2026 | 24/7/2026 | A container privilege escalation flaw was found in certain Red Hat Process Automation Manager images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root… | |
| Modificada | Media (6.4) | 0.18% | — | Redhat Ansible Automation Platform | 8/4/2026 | 24/9/2026 | A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root… | |
| Aplazada | Media (5.3) | 0.26% | — | Nfusionsolutions Precious Metals Automated Product Pricing PROAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in nfusionsolutions Precious Metals Automated Product Pricing – Pro precious-metals-automated-product-pricing-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Precious Metals Automated Product Pricing – Pro: from n/a through <= 4.0.5. | |
| Aplazada | Media (5.3) | 0.29% | — | Massiveshift AI Workflow Automation LiteAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in massiveshift AI Workflow Automation ai-workflow-automation-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Workflow Automation: from n/a through <= 1.4.2. |