Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

1654 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.8)0.16%—Assaabloy Visionline10/3/202617/6/2026
Incorrect Default Permissions, : Execution with Unnecessary Privileges, : Incorrect Permission Assignment for Critical Resource vulnerability in ASSA ABLOY Visionline on Windows allows Configuration/Environment Manipulation.This issue affects Visionline: from 1.0 before 1.33.
AnalizadaMedia (5.8)0.43%—Cisco SnortCisco Cyber VisionCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System Engine4/3/202618/8/2026
Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection. This vulnerability is due to incomplete error checking when parsing remote…
AnalizadaMedia (5.8)0.47%—Cisco SnortCisco Cyber VisionCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System Engine4/3/202619/8/2026
This vulnerability is due to incomplete error checking when parsing the Multicast DNS fields of the HTTP header. An attacker could exploit this vulnerability by sending crafted HTTP packets through an established connection to be parsed by Snort 3. A successful exploit could allow the attacker to cause a DoS condition…
AnalizadaMedia (5.8)0.45%—Cisco SnortCisco Cyber VisionCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System Engine4/3/202620/8/2026
—
AnalizadaMedia (5.8)0.45%—Cisco SnortCisco Cyber VisionCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System Engine4/3/202620/8/2026
This vulnerability is due to improper error checking when decompressing VBA data. An attacker could exploit this vulnerability by sending crafted VBA data to the Snort 3 Detection Engine on the targeted device. A successful exploit could allow the attacker to cause the Snort 3 Detection Engine to enter an infinite…
AnalizadaMedia (5.8)0.43%—Cisco SnortCisco Cyber VisionCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System Engine4/3/202620/8/2026
Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. This vulnerability is due to improper range checking when decompressing VBA data, which is user controlled. An attacker could exploit…
AnalizadaMedia (5.8)0.51%—Cisco Cyber VisionCisco Secure Firewall Threat DefenseCisco Unified Threat Defense Snort Intrusion Prevention System EngineCisco Snort4/3/20261/9/2026
Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection. This vulnerability is due to incomplete parsing of the SSL handshake ingress…
AnalizadaAlta (7.8)1.3%⚠ Explotación activa💥 PoCQualcomm Sm7675p FirmwareQualcomm Sm8475p FirmwareQualcomm Sm8550p FirmwareQualcomm Sm8635 Firmware+2332/3/202617/6/2026
Memory corruption while using alignments for memory allocation.
AnalizadaAlta (7.2)0.14%—Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Apq8098 Firmware+2022/3/202617/6/2026
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
AplazadaMedia (6.4)0.16%—Eaglevisionit Rise BlocksAI25/2/202617/6/2026
The Rise Blocks – A Complete Gutenberg Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘logoTag’ Site Identity block attribute in all versions up to, and including, 3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
AnalizadaCrítica (9.1)0.39%💥 PoCSoftvision Webpdf19/2/202617/6/2026
SoftVision webPDF before 10.0.2 is vulnerable to Server-Side Request Forgery (SSRF). The PDF converter function does not check if internal or external resources are requested in the uploaded files and allows for protocols such as http:// and file:///. This allows an attacker to upload an XML or HTML file in the…
AplazadaMedia (4.3)0.11%—Themastercut Revision-manager-tmcAI19/2/202617/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in themastercut Revision Manager TMC revision-manager-tmc allows Cross Site Request Forgery.This issue affects Revision Manager TMC: from n/a through <= 2.8.22.
AplazadaMedia (5.4)0.11%—Publishpress RevisionsAI19/2/202617/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in PublishPress PublishPress Revisions revisionary allows Cross Site Request Forgery.This issue affects PublishPress Revisions: from n/a through <= 3.7.22.
AnalizadaAlta (7.8)1.4%⚠ Explotación activa💥 PoCApple IpadosApple Iphone OSApple MacosApple Tvos+211/2/202617/6/2026
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been…
ModificadaCrítica (9)0.29%—Apple IpadosApple Iphone OSApple MacosApple Visionos11/2/202621/8/2026
A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A shortcut may be able to bypass sandbox restrictions.
ModificadaMedia (5.3)0.24%—Apple SafariApple IpadosApple Iphone OSApple Macos+111/2/202617/6/2026
This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. A website may be able to track users through Safari web extensions.
ModificadaMedia (5.5)0.27%—Apple IpadosApple Iphone OSApple MacosApple Tvos+211/2/202617/6/2026
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing a maliciously crafted image may lead to disclosure of user information.
ModificadaBaja (3.1)0.34%—Apple IpadosApple Iphone OSApple MacosApple Tvos+211/2/202617/6/2026
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker in a privileged network position may be able to intercept network traffic.
ModificadaAlta (7.5)0.81%💥 PoCApple SafariApple IpadosApple Iphone OSApple Macos+111/2/202617/6/2026
A path handling issue was addressed with improved logic. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.5, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A remote user may be able to write arbitrary files.
ModificadaMedia (5.5)0.14%—Apple IpadosApple Iphone OSApple MacosApple Tvos+211/2/202617/6/2026
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to cause unexpected system termination.
ModificadaMedia (5.5)0.16%—Apple IpadosApple Iphone OSApple MacosApple Visionos11/2/202617/6/2026
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. An app may be able to access sensitive user data.
ModificadaAlta (7.5)0.63%—Apple SafariApple IpadosApple Iphone OSApple Macos+111/2/202615/7/2026
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. A remote attacker may be able to cause a denial-of-service.
ModificadaAlta (7.5)0.50%—Apple IpadosApple Iphone OSApple MacosApple Tvos+211/2/202617/6/2026
A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker in a privileged network position may be able to perform denial-of-service attack using crafted Bluetooth packets.
ModificadaMedia (6.5)0.31%—Apple SafariApple IpadosApple Iphone OSApple Macos+111/2/202615/7/2026
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may lead to an unexpected process crash.
ModificadaAlta (7.1)0.14%—Apple IpadosApple Iphone OSApple MacosApple Tvos+211/2/202617/6/2026
A privacy issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to identify what other apps a user has installed.