Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
8451 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.26% | — | Shiptime Discounted Shipping RatesAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in shiptime ShipTime: Discounted Shipping Rates shiptime-discount-shipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShipTime: Discounted Shipping Rates: from n/a through <= 1.1.1. | |
| Analizada | Media (5.9) | 0.39% | — | Dafoster Rdiscount | 6/4/2026 | 24/7/2026 | Discount is an implementation of John Gruber's Markdown markup language in C. From 1.3.1.1 to before 2.2.7.4, a signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than INT_MAX are truncated to a signed int before entering the native parser, allowing the parser… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Simple IT Discussion ForumAI | 6/4/2026 | 24/7/2026 | A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. Affected by this issue is some unknown functionality of the file /edit-category.php of the component Parameter Handler. The manipulation of the argument cat_id leads to sql injection. It is possible to initiate the attack remotely. The… | |
| Aplazada | Baja (1.9) | 1.4% | — | Chrischinchilla Vale-mcpAI | 6/4/2026 | 24/7/2026 | A vulnerability was found in ChrisChinchilla Vale-MCP up to 0.1.0. Affected by this vulnerability is an unknown functionality of the file src/index.ts of the component HTTP Interface. The manipulation of the argument config_path results in os command injection. Attacking locally is a requirement. The exploit has been… | |
| Analizada | Baja (2.7) | 0.35% | — | Discourse | 3/4/2026 | 24/7/2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, staged user custom fields and username are exposed on public invite pages without email verification. This issue has been patched in versions… | |
| Analizada | Media (6.3) | 0.39% | — | Discourse | 3/4/2026 | 24/7/2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authorization bypass vulnerability allows unauthenticated or unauthorized users to view hidden (staff-only) tags and its associated data. All… | |
| Analizada | Media (4.9) | 0.49% | — | Cisco Nexus Dashboard InsightsCisco Nexus Dashboard | 1/4/2026 | 1/7/2026 | A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights could allow an authenticated, remote attacker to write arbitrary files to an affected system. This vulnerability is due to insufficient validation of the metadata update file. An attacker could exploit this vulnerability by crafting a… | |
| Analizada | Crítica (9.8) | 0.91% | — | Cisco Smart Software Manager On-prem | 1/4/2026 | 1/7/2026 | A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host. This vulnerability is due to the unintentional exposure of an internal service. An attacker could… | |
| Analizada | Alta (8) | 0.27% | — | Cisco Evolved Programmable Network Manager | 1/4/2026 | 2/7/2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to access. This vulnerability is due to improper authorization checks on a REST API… | |
| Analizada | Alta (7.3) | 0.27% | — | Cisco Smart Software Manager On-prem | 1/4/2026 | 8/7/2026 | A vulnerability in the web interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges on an affected system. This vulnerability is due to the improper transmission of sensitive user information. An attacker could exploit this vulnerability by… | |
| Analizada | Media (6.5) | 0.39% | — | Cisco Unified Computing System | 1/4/2026 | 28/8/2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to execute arbitrary code as the root user. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could… | |
| Analizada | Media (6.5) | 0.72% | — | Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software | 1/4/2026 | 28/8/2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to improper validation of user-supplied… | |
| Analizada | Media (6.5) | 0.93% | — | Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software | 1/4/2026 | 28/8/2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to improper validation of user-supplied… | |
| Analizada | Alta (8.8) | 1.1% | — | Cisco Unified Computing SystemCisco Unified Computing System E-series Software | 1/4/2026 | 28/8/2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to improper validation of user-supplied input.… | |
| Pendiente de análisis | Crítica (9.8) | 0.99% | — | Cisco Integrated Management ControllerAI | 1/4/2026 | 17/6/2026 | A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin. This vulnerability is due to incorrect handling of password change requests. An attacker could… | |
| Analizada | Media (4.8) | 0.24% | — | Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software | 1/4/2026 | 28/8/2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this… | |
| Analizada | Media (4.8) | 0.24% | — | Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software | 1/4/2026 | 28/8/2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this… | |
| Analizada | Media (4.8) | 0.22% | — | Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software | 1/4/2026 | 28/8/2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this… | |
| Analizada | Media (4.8) | 0.17% | — | Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software | 1/4/2026 | 28/8/2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this… | |
| Analizada | Media (6.1) | 0.18% | — | Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software | 1/4/2026 | 28/8/2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of… | |
| Analizada | Media (6.5) | 0.29% | — | Cisco Nexus Dashboard | 1/4/2026 | 8/7/2026 | A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Full or Config-only backup files to access sensitive information. This vulnerability exists because authentication details are included in the encrypted backup files. An… | |
| En análisis | Media (6.1) | 0.24% | — | Cisco Nexus DashboardAICisco Nexus Dashboard InsightsAI | 1/4/2026 | 17/6/2026 | A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit… | |
| Analizada | Media (5.1) | 0.32% | — | Discourse | 31/3/2026 | 24/7/2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authenticated moderator-level user could retrieve post content, topic titles, and usernames from categories they were not authorized to view.… | |
| Analizada | Media (5.3) | 0.40% | — | Discourse | 31/3/2026 | 24/7/2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authorization bypass in the Category Chatables Controller show action allowed moderators to get information on hidden groups names and user… | |
| Analizada | Media (5.3) | 0.32% | — | Discourse | 31/3/2026 | 24/7/2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, the group email settings test endpoint could be used to make the server initiate outbound connections to arbitrary hosts and ports. This could… |