Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

5113 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.8)0.34%—Wso2 Class MediatorAI6/8/202631/8/2026
The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should be isolated. This weakness can lead to the disclosure of sensitive…
AplazadaAlta (7.1)0.25%—Media Library AssistantAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions.
AnalizadaAlta (8.2)0.69%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering.
AnalizadaMedia (5.3)0.46%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that contain sensitive information. A successful exploit of this vulnerability might lead to information disclosure.
AnalizadaMedia (6.5)0.41%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to denial of service and data tampering.
AnalizadaMedia (6.5)0.41%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to data tampering and denial of service.
AnalizadaAlta (8.1)0.77%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
AnalizadaAlta (7.5)0.56%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
AnalizadaAlta (7.5)0.56%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery via DNS rebinding. A successful exploit of this vulnerability might lead to information disclosure.
AnalizadaAlta (7.5)0.56%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
AnalizadaAlta (7.5)0.56%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a crafted URL in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.
AnalizadaAlta (7.5)0.56%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
AnalizadaAlta (7.5)0.56%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.
AnalizadaAlta (7.5)0.82%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory. A successful exploit of this vulnerability might lead to information disclosure.
AnalizadaAlta (7.1)0.23%—Nvidia Triton Inference Server4/8/202617/8/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to, or modified by providing a path in the model name to the Triton MLflow plugin. A successful exploit of this vulnerability might lead to denial of service and information…
AnalizadaAlta (7.5)0.55%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successful exploit of this vulnerability might lead to data tampering.
AnalizadaCrítica (9.8)0.89%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
AnalizadaAlta (8.2)0.64%—Nvidia Dynamo4/8/20267/8/2026
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service and data tampering.
AplazadaBaja (2.1)0.35%—Diaowen DwsurveyAI4/8/202612/8/2026
A vulnerability was determined in diaowen DWSurvey up to 6.14.0. The affected element is an unknown function of the file /api/dwsurvey/app/survey/up-survey-status.do of the component Survey Status Handler. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been…
AplazadaBaja (2.1)0.36%—Diaowen DwsurveyAI4/8/202612/8/2026
A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurvey. of the file /api/dwsurvey/app/v6/dw-design-survey/dev-survey.do of the component Survey Handler. The manipulation results in authorization bypass. The attack can be launched remotely. The exploit…
AplazadaCrítica (9.8)2.9%💥 PoCOpenmediavault-mdAI3/8/20269/9/2026
An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as root via injecting shell metacharacters.
AnalizadaMedia (6)0.17%—Mediatek Mt6991 FirmwareMediatek Mt8768 FirmwareMediatek Mt8791t FirmwareMediatek Mt8792 Firmware+63/8/202619/8/2026
In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900493; Issue ID: MSV-6765.
AnalizadaMedia (6)0.17%—Mediatek Mt6989 FirmwareMediatek Mt8755 FirmwareMediatek Mt8768 FirmwareMediatek Mt8771 Firmware+73/8/202619/8/2026
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965550 / ALPS11393405; Issue ID: MSV-6941.
AnalizadaMedia (4.4)0.15%—Mediatek Mt6983 FirmwareMediatek Mt8676 FirmwareMediatek Mt8678 FirmwareMediatek Mt8755 Firmware+133/8/202619/8/2026
In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11036877; Issue ID: MSV-7132.
AnalizadaAlta (7.8)0.15%—Mediatek Mt7925 FirmwareMediatek Mt7927 FirmwareMediatek Mt7902 FirmwareMediatek Mt7920 Firmware+23/8/202619/8/2026
In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00488300; Issue ID: MSV-7296.