Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

5089 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.8)0.31%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense4/3/202611/8/2026
A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device that may also impact the availability of services to devices elsewhere in the network. This vulnerability is due to…
AnalizadaMedia (5.3)0.40%—Cisco Adaptive Security Appliance Software4/3/202617/6/2026
A vulnerability in the implementation of the proprietary SSH stack with SSH key-based authentication in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to log in to a Cisco Secure Firewall ASA device and execute commands as a specific user. This…
AnalizadaMedia (6)0.14%—Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense4/3/202611/8/2026
A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to craft Lua code that could be used on the underlying operating system as root.…
AnalizadaCrítica (9.8)0.41%—Renren-security3/3/202617/6/2026
renren-secuity before v5.5.0 is vulnerable to SQL Injection in the BaseServiceImpl.java component
En análisisMedia (6.2)0.10%—Trellix Endpoint Security24/2/202617/6/2026
A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the ability to gain elevated system privileges. Utilization of a Bring Your Own Vulnerable Driver (BYOVD) was leveraged to gain access to the critical Windows process memory lsass.exe (Local Security…
AnalizadaMedia (5.7)0.37%—Tenable Security Center23/2/202617/6/2026
An improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.
AnalizadaBaja (2.1)0.38%—Tenable Security Center23/2/202617/6/2026
An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter.
AplazadaMedia (6.5)0.41%—Getshieldsecurity Shield SecurityAI19/2/202617/6/2026
The Shield Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 21.0.8. This is due to the plugin allowing nonce verification to be bypassed via user-supplied parameter in the 'isNonceVerifyRequired' function. This makes it possible for unauthenticated…
AplazadaMedia (6.1)0.58%💥 ExploitGetshieldsecurity Shield SecurityAI19/2/202617/6/2026
The Shield Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in all versions up to, and including, 21.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
AplazadaMedia (4.3)0.21%—Getshieldsecurity Shield SecurityAI19/2/202617/6/2026
The Shield Security: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `MfaEmailDisable` action in all versions up to, and including, 21.0.9. This makes it possible for authenticated attackers,…
AnalizadaAlta (8.8)0.20%—IBM Security Qradar EDR17/2/202617/6/2026
IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate another user on the system.
AplazadaAlta (7.4)1.8%—Tenable Security CenterAI17/2/202617/6/2026
A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable Security Center is hosted.
AplazadaMedia (6.5)0.28%—Shield Security Custom Content BY CountryAI17/2/202617/6/2026
Missing Authorization vulnerability in Paul Custom Content by Country (by Shield Security) custom-content-by-country.This issue affects Custom Content by Country (by Shield Security): from n/a through 3.1.2.
AplazadaMedia (5.6)0.10%—Intel Converged Security AND Management Engine FirmwareAI10/2/202617/6/2026
Out-of-bounds read in the firmware for some Intel(R) Converged Security and Management Engine (CSME) Firmware (FW) within Ring 0: Kernel may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially…
AplazadaAlta (8.8)0.27%—Ergosis Security Systems Computer Industry AND Trade INC Zeus PdksAI10/2/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ergosis Security Systems Computer Industry and Trade Inc. ZEUS PDKS allows SQL Injection. This issue affects ZEUS PDKS: from <1.0.5.10 through 10022026. NOTE: The vendor was contacted early about this disclosure but…
AnalizadaMedia (4.3)0.21%—SAP S/4hana Defense & Security10/2/202617/6/2026
Due to a missing authorization check in the Disconnected Operations of the SAP S/4HANA Defense & Security, an attacker with user privileges could call remote-enabled function modules to do direct update on standard SAP database table . This results in low impact on integrity, with no impact on confidentiality or…
AnalizadaMedia (6.3)0.39%—Stepsecurity Harden-runner9/2/202617/6/2026
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Prior to 2.14.2, a security vulnerability has been identified in the Harden-Runner GitHub Action (Community Tier) that allows outbound network connections to evade audit logging. Specifically, outbound traffic using the sendto,…
AplazadaAlta (8.7)0.47%—ACE Security Wip-90113 HD CameraAI7/2/202617/6/2026
ACE Security WiP-90113 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration files. Attackers can access the camera's configuration backup by sending a GET request to the /config_backup.bin endpoint, exposing credentials and system…
AnalizadaAlta (8.2)0.21%—F5 Big-ip Advanced WEB Application FirewallF5 Big-ip Application Security Manager4/2/202617/6/2026
When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with conditions beyond the attacker's control can cause the bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaBaja (2.3)0.18%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+174/2/202617/6/2026
A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AplazadaBaja (2.7)0.35%—Hillstone Networks Operation AND Maintenance Security GatewayAI4/2/202617/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Hillstone Networks Operation and Maintenance Security Gateway on Linux allows Upload a Web Shell to a Web Server.This issue affects Operation and Maintenance Security Gateway: V5.5ST00001B113.
AnalizadaAlta (7.8)0.12%—Quickheal Total Security3/2/202617/6/2026
A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore paths and improper permission handling allow a low-privileged local user to restore quarantined files into protected system directories. This behavior can be abused by a local…
AplazadaCrítica (9.6)0.92%💥 PoCAliasrobotics Cybersecurity AIAI30/1/202617/6/2026
Cybersecurity AI (CAI) is a framework for AI Security. In versions up to and including 0.5.10, the CAI (Cybersecurity AI) framework contains multiple argument injection vulnerabilities in its function tools. User-controlled input is passed directly to shell commands via `subprocess.Popen()` with `shell=True`, allowing…
AnalizadaAlta (7.5)0.52%—Redhat Open Security Issue Management29/1/202617/6/2026
The $uri$args concatenation in nginx configuration file present in Open Security Issue Management (OSIM) prior v2025.9.0 allows path traversal attacks via query parameters.
AnalizadaMedia (4.8)0.35%—Opensecurity Mobile Security Framework27/1/202617/6/2026
MobSF is a mobile application security testing tool used. Prior to version 4.4.5, a Stored Cross-site Scripting (XSS) vulnerability in MobSF's Android manifest analysis allows an attacker to execute arbitrary JavaScript in the context of a victim's browser session by uploading a malicious APK. The `android:host`…