Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
3953 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.88% | 💥 PoC | Xwiki PlatformAI | 20/5/2026 | 23/7/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform is a generic wiki platform. In versions starting with 15.10.6 and prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17, the POST /wikis/{wikiName} API executes a XAR import without performing any… | |
| Aplazada | Crítica (9.3) | 20% | — | Xwiki PlatformAI | 20/5/2026 | 23/7/2026 | XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=/../../WEB-INF/xwiki.cfg&minify=false, leading to Path Traversal. The vulnerability is can be… | |
| Analizada | Media (6.5) | 0.40% | — | SplunkSplunk Cloud Platform | 20/5/2026 | 23/7/2026 | In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.2603.1, 10.3.2512.9, 10.2.2510.11, 10.1.2507.21, 10.0.2503.13, and 9.3.2411.129, a low-privileged user that does not hold the ‘admin’ or ‘power’ Splunk roles could cause a Denial of Service by… | |
| Analizada | Media (6.5) | 0.48% | — | SplunkSplunk Cloud Platform | 20/5/2026 | 23/7/2026 | In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the `_internal` index could view session cookies and response bodies that contain sensitive data. | |
| Analizada | Alta (7.5) | 1.3% | ⚠ Explotación activa💥 PoC | Microsoft Defender Antimalware Platform | 20/5/2026 | 23/7/2026 | Microsoft Defender Denial of Service Vulnerability | |
| Aplazada | Media (5) | 0.37% | 💥 PoC | Agpt Autogpt PlatformAI | 19/5/2026 | 24/7/2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions 0.1.0 through 0.6.51, SendEmailBlock in autogpt_platform/backend/backend/blocks/email_block.py accepts a user-supplied smtp_server (string) and smtp_port (integer) as per-execution… | |
| Modificada | Alta (7.5) | 1.1% | — | GnutlsRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux+10 | 18/5/2026 | 2/10/2026 | A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable… | |
| Pendiente de análisis | Media (6.9) | 0.10% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | Use of uninitialized resource within the AMD Platform Management Framework (PMF) could allow an attacker to read a uninitialized kernel memory resulting in loss of confidentiality or availability. | |
| Pendiente de análisis | Alta (7.1) | 0.11% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to write to an arbitrary memory address resulting in denial of service or arbitrary code execution. | |
| Pendiente de análisis | Media (5.8) | 0.10% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | An out of bounds read within the AMD Platform Management Framework (PMF) could allow an attacker to trigger a read of an arbitrary memory location potentially resulting in loss of availability or confidentiality. | |
| Pendiente de análisis | Alta (8.4) | 0.10% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | Improper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary memory pages potentially impacting integrity and availability, or allowing privilege escalation resulting in loss of confidentiality. | |
| Pendiente de análisis | Alta (8.4) | 0.11% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | An out of bounds write within the AMD Platform Management Framework (PMF) could allow an attacker to execute arbitrary code at an elevated privilege level potentially leading to loss of confidentiality integrity, or availability. | |
| Pendiente de análisis | Alta (8.3) | 0.10% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify an arbitrary address potentially resulting in loss of confidentiality, integrity, or availability. | |
| Pendiente de análisis | Alta (8.5) | 0.10% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | An improper input validation vulnerability within the AMD Platform Management Framework (PMF) Driver can allow a local attacker to write Out-of-Bounds, potentially resulting in privilege escalation. | |
| Pendiente de análisis | Media (6.9) | 0.10% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read Out-of-Bounds potentially resulting in information disclosure or a crash | |
| Pendiente de análisis | Alta (8.5) | 0.10% | — | AMD Platform Management FrameworkAI | 15/5/2026 | 17/6/2026 | An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read or write Out-of-Bounds, potentially resulting in privilege escalation | |
| Aplazada | Crítica (9) | 0.54% | — | Vcluster PlatformAI | 14/5/2026 | 17/6/2026 | vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to 4.4.3, 4.5.5, 4.6.2, 4.7.1, and 4.8.0, there is a Stored XSS attack vulnerability via the name field of a templateRef. This can lead to the execution of arbitrary external scripts within the… | |
| Analizada | Media (5.3) | 0.21% | — | Verint Verba Collaboration Compliance AND Quality Management Platform | 14/5/2026 | 17/6/2026 | Verba is affected by a Stored Cross-Site Scripting (XSS) vulnerability within its login logging mechanism. When an unauthenticated remote attacker attempts to log in using an incorrect username and password combination, the supplied username value is recorded in the application logs. Due to lack of input sanitization,… | |
| Aplazada | Baja (3.8) | 0.14% | — | Arqit Symmetric KEY Agreement PlatformAI | 13/5/2026 | 17/6/2026 | Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user via an unexpired browser session. This issue affects Symmetric Key Agreement Platform: before 26.03. | |
| Aplazada | Media (5.3) | 0.33% | — | Arqit Symmetric KEY Agreement PlatformAIKeycloakAI | 13/5/2026 | 17/6/2026 | Exposed Keycloak management service in the Arqit Symmetric Key Agreement Platform enables unauthorized access to sensitive debug information such as metrics and health data. This issue affects Symmetric Key Agreement Platform: before 26.03. | |
| Aplazada | Alta (8.7) | 0.34% | — | Arqit Symmetric KEY Agreement PlatformAI | 13/5/2026 | 17/6/2026 | Exposure of the QKEY (used as input into the ‘OTA-Quantum’ device registration process) and internal system keys via an unauthenticated and unencrypted HTTP GET method in the Arqit Symmetric Key Agreement Platform. This issue affects Symmetric Key Agreement Platform: before 26.03. | |
| Pendiente de análisis | Media (6.3) | 0.34% | — | Teamviewer DEX Platform On-premisesAI | 13/5/2026 | 17/6/2026 | A command injection vulnerability was discovered in TeamViewer DEX Platform On-Premises (former 1E DEX Platform On-Premises) prior to version 9.2. Improper input validation allows authenticated users with at least questioner privileges to inject commands in specific instructions. Exploitation could lead to execution… | |
| Analizada | Media (5.1) | 0.18% | — | Agpt Autogpt Platform | 13/5/2026 | 7/10/2026 | AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. In AutoGPT, the execution process is recorded to the console (stdout/stderr), and deployed in container mode, which is automatically captured by Docker and stored as… | |
| Analizada | Baja (2.1) | 0.30% | — | Parseplatform Parse-server | 12/5/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.76 and 9.9.0-alpha.2, a race condition in the MFA SMS one-time password (OTP) login path allows two concurrent /login requests carrying the same OTP to both succeed and both receive valid session… | |
| Pendiente de análisis | Media (4.3) | 0.34% | — | SAP Application Server AbapAISAP NetweaverAISAP Abap PlatformAI | 12/5/2026 | 17/6/2026 | Due to a Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform, an authenticated attacker could send specially crafted inputs to the application. If processed by the application, this input could be delivered to users subscribed to the channel and result in execution.… |