Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

3953 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.88%💥 PoCXwiki PlatformAI20/5/202623/7/2026
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform is a generic wiki platform. In versions starting with 15.10.6 and prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17, the POST /wikis/{wikiName} API executes a XAR import without performing any…
AplazadaCrítica (9.3)20%—Xwiki PlatformAI20/5/202623/7/2026
XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=/../../WEB-INF/xwiki.cfg&minify=false, leading to Path Traversal. The vulnerability is can be…
AnalizadaMedia (6.5)0.40%—SplunkSplunk Cloud Platform20/5/202623/7/2026
In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.2603.1, 10.3.2512.9, 10.2.2510.11, 10.1.2507.21, 10.0.2503.13, and 9.3.2411.129, a low-privileged user that does not hold the ‘admin’ or ‘power’ Splunk roles could cause a Denial of Service by…
AnalizadaMedia (6.5)0.48%—SplunkSplunk Cloud Platform20/5/202623/7/2026
In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the `_internal` index could view session cookies and response bodies that contain sensitive data.
AnalizadaAlta (7.5)1.3%⚠ Explotación activa💥 PoCMicrosoft Defender Antimalware Platform20/5/202623/7/2026
Microsoft Defender Denial of Service Vulnerability
AplazadaMedia (5)0.37%💥 PoCAgpt Autogpt PlatformAI19/5/202624/7/2026
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions 0.1.0 through 0.6.51, SendEmailBlock in autogpt_platform/backend/backend/blocks/email_block.py accepts a user-supplied smtp_server (string) and smtp_port (integer) as per-execution…
ModificadaAlta (7.5)1.1%—GnutlsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux+1018/5/20262/10/2026
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable…
Pendiente de análisisMedia (6.9)0.10%—AMD Platform Management FrameworkAI15/5/202617/6/2026
Use of uninitialized resource within the AMD Platform Management Framework (PMF) could allow an attacker to read a uninitialized kernel memory resulting in loss of confidentiality or availability.
Pendiente de análisisAlta (7.1)0.11%—AMD Platform Management FrameworkAI15/5/202617/6/2026
An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to write to an arbitrary memory address resulting in denial of service or arbitrary code execution.
Pendiente de análisisMedia (5.8)0.10%—AMD Platform Management FrameworkAI15/5/202617/6/2026
An out of bounds read within the AMD Platform Management Framework (PMF) could allow an attacker to trigger a read of an arbitrary memory location potentially resulting in loss of availability or confidentiality.
Pendiente de análisisAlta (8.4)0.10%—AMD Platform Management FrameworkAI15/5/202617/6/2026
Improper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary memory pages potentially impacting integrity and availability, or allowing privilege escalation resulting in loss of confidentiality.
Pendiente de análisisAlta (8.4)0.11%—AMD Platform Management FrameworkAI15/5/202617/6/2026
An out of bounds write within the AMD Platform Management Framework (PMF) could allow an attacker to execute arbitrary code at an elevated privilege level potentially leading to loss of confidentiality integrity, or availability.
Pendiente de análisisAlta (8.3)0.10%—AMD Platform Management FrameworkAI15/5/202617/6/2026
An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify an arbitrary address potentially resulting in loss of confidentiality, integrity, or availability.
Pendiente de análisisAlta (8.5)0.10%—AMD Platform Management FrameworkAI15/5/202617/6/2026
An improper input validation vulnerability within the AMD Platform Management Framework (PMF) Driver can allow a local attacker to write Out-of-Bounds, potentially resulting in privilege escalation.
Pendiente de análisisMedia (6.9)0.10%—AMD Platform Management FrameworkAI15/5/202617/6/2026
An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read Out-of-Bounds potentially resulting in information disclosure or a crash
Pendiente de análisisAlta (8.5)0.10%—AMD Platform Management FrameworkAI15/5/202617/6/2026
An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read or write Out-of-Bounds, potentially resulting in privilege escalation
AplazadaCrítica (9)0.54%—Vcluster PlatformAI14/5/202617/6/2026
vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to 4.4.3, 4.5.5, 4.6.2, 4.7.1, and 4.8.0, there is a Stored XSS attack vulnerability via the name field of a templateRef. This can lead to the execution of arbitrary external scripts within the…
AnalizadaMedia (5.3)0.21%—Verint Verba Collaboration Compliance AND Quality Management Platform14/5/202617/6/2026
Verba is affected by a Stored Cross-Site Scripting (XSS) vulnerability within its login logging mechanism. When an unauthenticated remote attacker attempts to log in using an incorrect username and password combination, the supplied username value is recorded in the application logs. Due to lack of input sanitization,…
AplazadaBaja (3.8)0.14%—Arqit Symmetric KEY Agreement PlatformAI13/5/202617/6/2026
Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user via an unexpired browser session. This issue affects Symmetric Key Agreement Platform: before 26.03.
AplazadaMedia (5.3)0.33%—Arqit Symmetric KEY Agreement PlatformAIKeycloakAI13/5/202617/6/2026
Exposed Keycloak management service in the Arqit Symmetric Key Agreement Platform enables unauthorized access to sensitive debug information such as metrics and health data. This issue affects Symmetric Key Agreement Platform: before 26.03.
AplazadaAlta (8.7)0.34%—Arqit Symmetric KEY Agreement PlatformAI13/5/202617/6/2026
Exposure of the QKEY (used as input into the ‘OTA-Quantum’ device registration process) and internal system keys via an unauthenticated and unencrypted HTTP GET method in the Arqit Symmetric Key Agreement Platform. This issue affects Symmetric Key Agreement Platform: before 26.03.
Pendiente de análisisMedia (6.3)0.34%—Teamviewer DEX Platform On-premisesAI13/5/202617/6/2026
A command injection vulnerability was discovered in TeamViewer DEX Platform On-Premises (former 1E DEX Platform On-Premises) prior to version 9.2. Improper input validation allows authenticated users with at least questioner privileges to inject commands in specific instructions. Exploitation could lead to execution…
AnalizadaMedia (5.1)0.18%—Agpt Autogpt Platform13/5/20267/10/2026
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. In AutoGPT, the execution process is recorded to the console (stdout/stderr), and deployed in container mode, which is automatically captured by Docker and stored as…
AnalizadaBaja (2.1)0.30%—Parseplatform Parse-server12/5/202617/6/2026
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.76 and 9.9.0-alpha.2, a race condition in the MFA SMS one-time password (OTP) login path allows two concurrent /login requests carrying the same OTP to both succeed and both receive valid session…
Pendiente de análisisMedia (4.3)0.34%—SAP Application Server AbapAISAP NetweaverAISAP Abap PlatformAI12/5/202617/6/2026
Due to a Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform, an authenticated attacker could send specially crafted inputs to the application. If processed by the application, this input could be delivered to users subscribed to the channel and result in execution.…