Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
5113 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.8) | 2.4% | — | Nvidia Openshell | 25/8/2026 | 3/9/2026 | NVIDIA OpenShell for Linux contains a vulnerability in its sandbox exec handler, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering. | |
| Analizada | Media (5.2) | 0.17% | — | Nvidia Openshell | 25/8/2026 | 3/9/2026 | NVIDIA OpenShell for Linux contains a vulnerability in its inference proxy, where an attacker could cause an improper encoding or escaping of output. A successful exploit of this vulnerability might lead to information disclosure and data tampering. | |
| Analizada | Crítica (9.8) | 0.51% | — | Nvidia Nemoclaw | 25/8/2026 | 1/9/2026 | NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, code execution, and escalation of privileges. | |
| Analizada | Crítica (9.9) | 0.86% | — | Nvidia Openshell | 25/8/2026 | 3/9/2026 | NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, data tampering, and denial of service. | |
| Analizada | Alta (7.8) | 0.22% | — | Nvidia Nemoclaw | 25/8/2026 | 1/9/2026 | NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service. | |
| Analizada | Crítica (9.8) | 0.41% | — | Nvidia Nemoclaw | 25/8/2026 | 1/9/2026 | NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, information disclosure, and denial of service. | |
| Aplazada | Media (5.6) | 0.19% | — | MediasoupAI | 25/8/2026 | 9/9/2026 | mediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm package and from 0.22.0 until 0.22.5 for the Rust crate, mediasoup's built-in SCTP stack authenticates state cookies using only the hardcoded msworker and 0xAD81 magic values instead of a per-instance secret and HMAC,… | |
| Analizada | Alta (8.2) | 0.20% | — | Nvidia DGX Spark Uefi | 25/8/2026 | 9/9/2026 | NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering. | |
| Analizada | Media (6) | 0.18% | — | Nvidia DGX Spark Uefi | 25/8/2026 | 9/9/2026 | NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privileged local user. A successful exploit of this vulnerability may allow an attacker to bypass administrator password protection in UEFi. | |
| Analizada | Alta (8.2) | 0.15% | — | Nvidia DGX Spark Uefi | 25/8/2026 | 9/9/2026 | NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause a NULL pointer dereference. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering. | |
| Analizada | Alta (8.2) | 0.15% | — | Nvidia DGX Spark Uefi | 25/8/2026 | 9/9/2026 | NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering. | |
| Analizada | Media (6) | 0.13% | — | Nvidia DGX Spark Uefi | 25/8/2026 | 9/9/2026 | NVIDIA DGX Spark contains a vulnerability in the standalone MM firmware where an attacker could be able to cause an out-of-bounds read. A successful exploit of this vulnerability might lead to information disclosure. | |
| En análisis | Alta (8.8) | 0.32% | — | Nvidia UFM EnterpriseAI | 25/8/2026 | 28/8/2026 | NVIDIA UFM Enterprise contains a vulnerability in the web interface authorization component, where an authenticated user could cause improper authentication by sending specially crafted HTTP requests. A successful exploit of this vulnerability might lead to code execution and escalation of privileges. | |
| En análisis | Alta (8) | 0.37% | — | Nvidia UFM EnterpriseAI | 25/8/2026 | 28/8/2026 | NVIDIA UFM Enterprise contains a vulnerability in the plugin management API, where an authenticated user with low privileges could inject code by sending a specially crafted API request. A successful exploit of this vulnerability might lead to code execution, escalation of privileges and information disclosure. | |
| En análisis | Media (6.8) | 0.97% | — | Nvidia UFM EnterpriseAI | 25/8/2026 | 28/8/2026 | NVIDIA UFM Enterprise contains a vulnerability in the IBDiagnet API where an authenticated attacker with administrative privileges may cause command injection by sending crafted API requests. A successful exploit of this vulnerability may lead to code execution, escalation of privileges and information disclosure. | |
| En análisis | Media (6.8) | 0.28% | — | Nvidia UFM EnterpriseAI | 25/8/2026 | 28/8/2026 | NVIDIA UFM Enterprise contains a vulnerability in the user management component, where an authenticated administrator could inject commands by sending a crafted API request. A successful exploit of this vulnerability might lead to code execution, escalation of privileges and information disclosure. | |
| En análisis | Media (5.1) | 0.13% | — | Nvidia UFM EnterpriseAI | 25/8/2026 | 28/8/2026 | NVIDIA UFM Enterprise contains a vulnerability in the session management component, where an attacker could use a hard-coded cryptographic key to extract information. A successful exploit of this vulnerability might lead to information disclosure and escalation of privileges. | |
| Aplazada | Media (4.9) | 0.51% | — | Media SweepAI | 25/8/2026 | 28/9/2026 | The Media Sweep – WordPress Media Cleaner plugin for WordPress is vulnerable to generic SQL Injection via the 'fields' parameter in all versions up to, and including, 1.1.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible… | |
| Aplazada | Alta (7.1) | 0.25% | — | Social Media AND Share IconsAI | 24/8/2026 | 24/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions. | |
| Aplazada | Alta (8.8) | 0.66% | — | Deltaww DiaenergieAI | 24/8/2026 | 1/9/2026 | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | |
| Aplazada | Alta (8.8) | 0.66% | — | Deltaww DiaenergieAI | 24/8/2026 | 1/9/2026 | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | |
| Aplazada | Alta (8.8) | 0.66% | — | Deltaww DiaenergieAI | 24/8/2026 | 1/9/2026 | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | |
| Aplazada | Alta (8.8) | 0.66% | — | Deltaww DiaenergieAI | 24/8/2026 | 1/9/2026 | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | |
| Aplazada | Crítica (9.8) | 0.50% | — | WP Social Media LoginAI | 22/8/2026 | 26/8/2026 | The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, including administrators, by supplying that user's email address. | |
| Aplazada | Media (6.8) | 0.39% | — | Media Library AssistantAI | 21/8/2026 | 26/8/2026 | The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its media-library query handlers, allowing users with the Author role to perform SQL injection. |