Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
8750 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1) | 0.20% | — | Indian Motorcycle Scout Bobber Infotainment Digital Round DisplayAIIndian Motorcycle Wireless Control ModuleAI | 29/5/2026 | 21/7/2026 | Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. The Infotainment uses presence of Wireless Control Module (WCM) traffic during its boot window as a proxy for whether an… | |
| Aplazada | Baja (1) | 0.20% | — | Indian Motorcycle Scout Bobber Infotainment Digital Round DisplayAI | 29/5/2026 | 21/7/2026 | Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. The Infotainment uses presence of Wireless Control Module (WCM) traffic during its boot window as a proxy for whether an… | |
| Aplazada | Media (4.1) | 0.27% | — | Indian Motorcycle Scout Bobber Tech 2025AI | 29/5/2026 | 21/7/2026 | Expected behavior violation in the in-vehicle network of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the motorcycle's anti-theft shutdown by forcing the Wireless Control Module (WCM) into the CAN bus-off state. Using a well-known CAN error-frame injection… | |
| Aplazada | Media (4.1) | 0.25% | — | Indian Motorcycle Scout Bobber WCMAI | 29/5/2026 | 21/7/2026 | Uncontrolled resource consumption in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with write access to the in-vehicle network to permanently immobilize the motorcycle. The WCM enforces a brute-force lockout on the immobilizer… | |
| Aplazada | Media (4.1) | 0.14% | — | Indian Motorcycle Scout Bobber Tech 2025AI | 29/5/2026 | 21/7/2026 | Weak authentication between the Wireless Control Module (WCM) and the Engine Control Module (ECM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to recover the per-vehicle ECM immobilizer secret by passively observing a single… | |
| Aplazada | Media (4.1) | 0.14% | — | Indian Motorcycle Scout Bobber Tech 2025AI | 29/5/2026 | 21/7/2026 | Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to recover the user-set unlock PIN by passively observing a single PIN authentication exchange. The Infotainment Digital… | |
| Aplazada | Media (5.3) | 0.23% | — | Flamescorpion Auto Affiliate LinksAI | 25/5/2026 | 24/7/2026 | Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Auto Affiliate Links: from n/a through 6.8.8.3. | |
| Modificada | Crítica (9.2) | 2.7% | 💥 PoC | F5 Nginx Open SourceF5 Nginx PlusF5 DOSF5 Nginx Gateway Fabric+8 | 22/5/2026 | 25/8/2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple… | |
| Analizada | Crítica (10) | 0.83% | 💥 PoC | Cisco Secure Workload | 20/5/2026 | 23/7/2026 | A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role. | |
| Pendiente de análisis | Media (6.3) | 0.42% | — | Cisco Thousandeyes Enterprise AgentAI | 20/5/2026 | 23/7/2026 | A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, remote attacker to execute arbitrary commands on Agents on behalf of the BrowserBot synthetics orchestration process. Cisco has addressed this vulnerability in the Cisco ThousandEyes Enterprise… | |
| Analizada | Alta (7.2) | 0.44% | — | Cisco Thousandeyes Virtual Appliance | 20/5/2026 | 23/7/2026 | A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating system as the root user. This vulnerability is due to insufficient validation of user-supplied input. An authenticated attacker could… | |
| Pendiente de análisis | Media (6.8) | 0.47% | — | Cisco Nexus 3000 Series SwitchesAICisco Nexus 9000 Series SwitchesAI | 20/5/2026 | 23/7/2026 | A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to trigger BGP peer flaps, resulting in a denial of service (DoS) condition. This… | |
| Analizada | Baja (2.1) | 0.27% | — | Discourse | 19/5/2026 | 24/7/2026 | Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, a vulnerability in the discourse-subscriptions plugin allows users to gain access to subscription-gated groups without completing payment. This issue has been fixed in versions 2026.1.4, 2026.3.1,… | |
| Aplazada | Alta (7.3) | 0.52% | — | ModelscopeAI | 19/5/2026 | 24/7/2026 | An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module']. | |
| Analizada | Media (6) | 0.30% | — | Discourse | 19/5/2026 | 24/7/2026 | Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, an authenticated user on a Discourse instance with the form templates feature enabled can read the name and structured content of form templates that are intended exclusively for categories they… | |
| Analizada | Media (5.3) | 0.38% | — | Discourse | 19/5/2026 | 24/7/2026 | Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, outdated cached AI summaries can leak removed content to anonymous and unprivileged users who cannot regenerate summaries. This issue has been fixed in versions 2026.1.4, 2026.3.1, 2026.4.1 and… | |
| Analizada | Alta (8.6) | 1.0% | 💥 PoC | Cisco Catalyst Sd-wan Manager | 14/5/2026 | 29/6/2026 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system. The attacker does not need to have valid user credentials. This vulnerability is due to improper handling of XML… | |
| Analizada | Media (5.4) | 0.19% | — | Cisco Catalyst Sd-wan Manager | 14/5/2026 | 29/6/2026 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to modify configurations and perform unauthorized actions on an affected system. This vulnerability exists because of a failure to redact sensitive… | |
| Analizada | Media (5.4) | 0.19% | — | Cisco Catalyst Sd-wan Manager | 14/5/2026 | 29/6/2026 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to elevate their privileges from low to high and perform actions as a high-privileged user. This vulnerability exists because sensitive session information… | |
| Analizada | Crítica (10) | 92% | ⚠ Explotación activa💥 PoC | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond OrchestratorCisco Sd-wan Vsmart Controller | 14/5/2026 | 17/6/2026 | A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain… | |
| Aplazada | Alta (7.5) | 0.41% | — | HoppscotchAI | 13/5/2026 | 17/6/2026 | hoppscotch is an open source API development ecosystem. The fix for CVE-2026-28215 in version 2026.2.0 addresses the unauthenticated POST /v1/onboarding/config endpoint by checking onboardingCompleted and canReRunOnboarding before allowing config overwrites. However, GET /v1/onboarding/config still leaks all… | |
| Aplazada | Media (6.7) | 0.43% | — | Erudika ScooldAI | 8/5/2026 | 17/6/2026 | Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.67.0, Scoold allows the admins configuration value to be modified through /api/config/set/admins with a forged Bearer token that is accepted as an admin API token. Once that setting is changed, the target email address is written to the… | |
| Pendiente de análisis | Crítica (9.8) | 3.0% | — | Universal-robots PolyscopeAI | 8/5/2026 | 17/6/2026 | OS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows unauthenticated attacker to craft commands that will execute code on the robot's OS. | |
| Aplazada | Alta (7.2) | 0.51% | — | Flamescorpion Auto Affiliate LinksAI | 8/5/2026 | 17/6/2026 | The Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.8.8 This is due to insufficient input sanitization on the 'url' POST parameter in the aal_url_stats_save_action() function and a complete absence of output escaping in aal_display_clicks(),… | |
| Analizada | Media (5.5) | 0.16% | — | Projectdiscovery Nuclei | 8/5/2026 | 17/6/2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's JavaScript protocol runtime allows JavaScript templates to read local .js and .json files through the require() function, bypassing the default local file access restriction. This… |