Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
11.348 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.8) | 0.52% | — | Openstack DesignateAI | 12/8/2026 | 9/9/2026 | In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with a deterministic error, causing the handler to return REFUSED for all DNS queries through that path.… | |
| Pendiente de análisis | Crítica (9.6) | 0.53% | — | Openstack DesignateAI | 12/8/2026 | 9/9/2026 | In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter scheduler, creating an overlapping zone that… | |
| Pendiente de análisis | Alta (8.6) | 0.58% | — | Amazon OpensearchAIAmazon Opensearch AlertingAI | 12/8/2026 | 13/8/2026 | Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters. | |
| Pendiente de análisis | Alta (8.6) | 0.52% | — | Opensearch Security AnalyticsAI | 12/8/2026 | 21/8/2026 | Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the threat intel source configuration endpoint. | |
| Analizada | Media (5.5) | 0.15% | — | Redhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 12/8/2026 | 1/9/2026 | Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the… | |
| Analizada | Baja (2.5) | 0.09% | — | Openbsd Openssh | 11/8/2026 | 4/9/2026 | In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not. | |
| Analizada | Media (4.8) | 0.16% | — | Openbsd Openssh | 11/8/2026 | 4/9/2026 | In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent. | |
| Analizada | Baja (3.5) | 0.16% | — | Openbsd Openssh | 11/8/2026 | 4/9/2026 | In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension. | |
| Analizada | Media (4.6) | 0.30% | — | Intel Trust Domain Extensions Guest | 11/8/2026 | 18/8/2026 | Incorrect comparison for some Intel(R) TDX Guest software before version 0.3.1 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local… | |
| Analizada | Media (4.6) | 0.15% | — | Intel Trust Domain Extensions Guest | 11/8/2026 | 18/8/2026 | Incorrect calculation for some Intel(R) TDX Guest software before version 0.3.1 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local… | |
| En análisis | Media (5.4) | 0.16% | — | Intel Extension FOR TensorflowAI | 11/8/2026 | 12/8/2026 | Protection mechanism failure for some Intel Extension for TensorFlow software before version 2.15.0.3 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may… | |
| Analizada | Alta (8.6) | 1.0% | ⚠ Explotación activa | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 11/8/2026 | 16/9/2026 | This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload,… | |
| Analizada | Media (4.6) | 0.26% | — | Intel Extension FOR Pytorch | 11/8/2026 | 30/9/2026 | Deserialization of untrusted data for some Intel(R) Extension for PyTorch before version 2.8.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable escalation of privilege. This result may… | |
| En análisis | Media (4.3) | 0.13% | — | Intel Software Guard Extensions Data Center Attestation PrimitivesAI | 11/8/2026 | 29/9/2026 | Omission of security-relevant information for some Intel(R) Software Guard Extensions Data Center Attestation Primitives within Ring 0: Kernel may allow a denial of service. Authorized adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur… | |
| Pendiente de análisis | Media (5.7) | 0.07% | — | Intel Trust Domain ExtensionsAI | 11/8/2026 | 29/9/2026 | Insufficient verification of data authenticity for some Intel(R) Trust Domain Extensions (Intel(R) TDX) within Ring 0: Hypervisor may allow an information disclosure. A system software adversary with a privileged user access combined with a high complexity attack may enable data exposure. This result may potentially… | |
| Pendiente de análisis | Alta (8.7) | 0.62% | — | Siemens License ServerAI | 11/8/2026 | 28/8/2026 | A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The affected application is vulnerable to a path traversal vulnerability due to lack of sanitization of user input. This could allow a remote attacker to access arbitrary files on the application. | |
| Pendiente de análisis | Alta (8.3) | 0.17% | — | Siemens License ServerAI | 11/8/2026 | 28/8/2026 | A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The affected application is vulnerable to a local privilege escalation due to an insecure sudoers policy. This could allow an attacker to execute arbitrary commands and plant malicious files as root, leading to full system… | |
| Pendiente de análisis | Alta (7.3) | 0.15% | — | Siemens ParasolidAI | 11/8/2026 | 28/8/2026 | A vulnerability has been identified in Parasolid V38.0 (All versions < V38.0.235), Parasolid V38.1 (All versions < V38.1.230). The affected applications contains an out of bounds read vulnerability while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current… | |
| Pendiente de análisis | Alta (7.3) | 0.15% | — | Siemens Simcenter FemapAI | 11/8/2026 | 28/8/2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process. | |
| Pendiente de análisis | Alta (7.3) | 0.15% | — | Siemens Simcenter FemapAI | 11/8/2026 | 28/8/2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process. | |
| Pendiente de análisis | Media (5.3) | 0.24% | — | Siemens Desigo Dxr2AISiemens Desigo Pxc3AISiemens Desigo Pxc4AISiemens Desigo Pxc5.e003AI+2 | 11/8/2026 | 28/8/2026 | A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3 (All versions < V01.21.233.16-7862), Desigo PXC4 (All versions < V02.21.194.36-2715), Desigo PXC5.E003 (All versions < V02.21.194.36-2715), Desigo PXC5.E24 (All versions < V02.21.194.36-2715), Desigo PXC7 (All versions… | |
| Pendiente de análisis | Alta (7.3) | 0.15% | — | Siemens Simcenter FemapAISiemens Simcenter NastranAI | 11/8/2026 | 28/8/2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2606), Simcenter Nastran (All versions < V2606). The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the… | |
| Pendiente de análisis | Crítica (10) | 0.95% | — | Siemens Simatic Iot2050 AdvancedAINodered Node-redAI | 11/8/2026 | 28/8/2026 | A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing… | |
| Pendiente de análisis | Alta (7) | 0.11% | — | Siemens Logo Soft ComfortAI | 11/8/2026 | 28/8/2026 | A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). The project password feature in the affected products stores the password as an unsalted SHA-256 hash. This could allow an attacker who has obtained the project file to perform efficient offline dictionary or brute-force attacks against the… | |
| Pendiente de análisis | Alta (7) | 0.15% | — | Siemens Logo Soft ComfortAI | 11/8/2026 | 28/8/2026 | A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). Affected products use a static, hardcoded AES master key to encrypt project files. This could allow a local attacker to extract the master key from the application files or memory and use it to decrypt project files or remove project… |