Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
40.025 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.1) | 0.38% | — | Apache Mina SshdAI | 30/9/2026 | 30/9/2026 | A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks. Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and… | |
| Pendiente de análisis | Crítica (9.1) | 0.51% | — | Apache Mina SshdAI | 30/9/2026 | 30/9/2026 | Authentication bypass in sshd-core in Apache MINA SSHD versions 2.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 for a certain (presumed rare) way to implement an SSH server. Apache MINA SSHD is a Java library for client- and server-side SSH. In the server part of the library, a mechanism to perform "asynchronous… | |
| Aplazada | Crítica (9.3) | 0.43% | — | Digiwin Easyflow DOT NETAI | 30/9/2026 | 30/9/2026 | EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain other users' plaintext passwords through a specific API. | |
| Aplazada | Crítica (9.3) | 0.51% | — | Digiwin EasyflowAI | 30/9/2026 | 30/9/2026 | EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content. | |
| Pendiente de análisis | Crítica (9.2) | 0.13% | — | Apache Plc4xAI | 30/9/2026 | 30/9/2026 | Improper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of Apache PLC4X (PLC4J) allows an attacker in a network position between client and server to impersonate the OPC UA server and to read, forge or modify secure-channel traffic, including user credential ssent by… | |
| Aplazada | Crítica (9.1) | 0.30% | — | Stellarwp GivewpAI | 30/9/2026 | 30/9/2026 | Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass. This issue affects GiveWP: from n/a through 4.16.9. | |
| Aplazada | Crítica (9.8) | 0.57% | — | Zella ThemeAI | 30/9/2026 | 30/9/2026 | The Zella Theme WordPress theme before 2.6.3 does not perform any capability or nonce check on one of its font upload actions, which is available to unauthenticated users, allowing them to upload arbitrary files, including PHP ones, and achieve remote code execution. | |
| Analizada | Crítica (9.8) | 0.61% | — | Pexip Infinity | 30/9/2026 | 5/10/2026 | Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as an unprivileged user on a Pexip Infinity Conferencing Node. | |
| Analizada | Crítica (9.4) | 0.25% | — | Pexip Infinity | 30/9/2026 | 5/10/2026 | Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation that allows a remote attacker to trigger memory corruption or a software abort resulting in a denial of service. A crafted media stream may result in a controlled abort during processing, and has… | |
| Aplazada | Crítica (9.4) | 1.5% | — | AisocAI | 29/9/2026 | 30/9/2026 | AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions service that builds CrowdStrike Real Time Response command strings by interpolating unescaped action parameters in crowdstrike_rtr.py and endpoint.py. Authenticated users can inject single quotes into file_path, path,… | |
| Analizada | Crítica (9.2) | 0.42% | — | Watchguard Fireware | 29/9/2026 | 6/10/2026 | A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox. | |
| Pendiente de análisis | Crítica (9.8) | 0.44% | — | Wikimedia EasytimelineAI | 29/9/2026 | 1/10/2026 | XML injection (aka blind XPath injection) vulnerability in The Wikimedia Foundation Mediawiki - EasyTimeline extension allows XML Injection. This issue affects Mediawiki - EasyTimeline extension: before 1.46.1, 1.45.5, 1.43.10. | |
| Aplazada | Crítica (9.3) | 0.62% | — | LightllmAI | 29/9/2026 | 30/9/2026 | LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code with service privileges. | |
| Aplazada | Crítica (9.3) | 0.78% | — | LightllmAI | 29/9/2026 | 30/9/2026 | LightLLM through 1.2.0 contains a remote code execution vulnerability in the router profiler service when started with --enable_profiling flag. The service exposes an unauthenticated RPyC server with pickle deserialization enabled, allowing attackers to execute arbitrary code by sending crafted serialized objects to… | |
| Pendiente de análisis | Crítica (10) | 0.44% | — | — | 29/9/2026 | 30/9/2026 | The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST request. | |
| Pendiente de análisis | Crítica (9.4) | 0.40% | — | — | 29/9/2026 | 30/9/2026 | The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attacker to upload and execute arbitrary PHP files on the web server. | |
| Pendiente de análisis | Crítica (10) | 0.34% | — | ViidureAI | 29/9/2026 | 29/9/2026 | The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries. | |
| Aplazada | Crítica (9.8) | 0.29% | — | Totolink N150rtAI | 29/9/2026 | 30/9/2026 | A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formPortFw (port-forwarding configuration handler) and is triggered by the ip_subnet and fw_ip request parameters during the rule-addition… | |
| Aplazada | Crítica (9.8) | 0.43% | — | Metatool AI MetamcpAI | 29/9/2026 | 29/9/2026 | metatool-ai MetaMCP up to and including 2.4.22 is vulnerable to Code Execution in the internal MCP inspector proxy endpoint GET /mcp-proxy/server/stdio (createTransport, STDIO branch, routers/mcp-proxy/server.ts). | |
| Aplazada | Crítica (9.1) | 0.31% | — | Metatool AI MetamcpAI | 29/9/2026 | 30/9/2026 | metatool-ai MetaMCP through 2.4.22 contains an insecure direct object reference (IDOR) in the MCP transport session dispatch. The session store (getSession in session-lifetime-manager.ts) is keyed only by the client-supplied mcp-session-id header with no owner, namespace, or endpoint binding, and the per-endpoint… | |
| Aplazada | Crítica (9.1) | 0.24% | — | Bytebase DbhubAI | 29/9/2026 | 30/9/2026 | bytebase dbhub v1.2.0 was discovered to contain a SQL injection vulnerability in the /utils/sql-parser.ts component. This vulnerability allows attackers to access sensitive databse information via a crafted SQL statement. | |
| Pendiente de análisis | Crítica (9.6) | 0.32% | — | HPE Instant ONAI | 29/9/2026 | 1/10/2026 | A vulnerability has been identified in a management protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could result in a complete bypass of security restrictions, potentially leading to remote code… | |
| Pendiente de análisis | Crítica (9.6) | 1.0% | — | HPE Instant ONAI | 29/9/2026 | 1/10/2026 | A command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to perform command injection by sending specially crafted packets. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on… | |
| Pendiente de análisis | Crítica (9.6) | 0.31% | — | HPE Networking Instant ON APSAI | 29/9/2026 | 1/10/2026 | Buffer overflow vulnerabilities exist in the affected interface of HPE Networking Instant ON APS that could allow an unauthenticated adjacent attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. | |
| Pendiente de análisis | Crítica (9.8) | 0.54% | — | HPE Networking Instant ONAI | 29/9/2026 | 1/10/2026 | Uncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant ON APs that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation could result in a Denial-of-service or potential remote code execution. |