Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
40.026 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Crítica (9.6) | 0.34% | — | Mozilla FirefoxAIMozilla Firefox ESRAI | 29/9/2026 | 1/10/2026 | Sandbox escape due to incorrect boundary conditions in the Internationalization component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17. | |
| En análisis | Crítica (9.8) | 0.44% | — | Mozilla FirefoxAI | 29/9/2026 | 1/10/2026 | Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17. | |
| Analizada | Crítica (9.6) | 0.30% | — | Mozilla FirefoxMozilla Thunderbird | 29/9/2026 | 5/10/2026 | Sandbox escape in the XUL component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | |
| Analizada | Crítica (9.6) | 0.32% | — | Mozilla FirefoxMozilla Thunderbird | 29/9/2026 | 5/10/2026 | Sandbox escape due to use-after-free in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | |
| Analizada | Crítica (9.6) | 0.33% | — | Mozilla FirefoxMozilla Thunderbird | 29/9/2026 | 5/10/2026 | Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | |
| Analizada | Crítica (9.6) | 0.32% | — | Mozilla FirefoxMozilla Thunderbird | 29/9/2026 | 5/10/2026 | Sandbox escape due to use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | |
| Analizada | Crítica (9.6) | 0.33% | — | Mozilla FirefoxMozilla Thunderbird | 29/9/2026 | 6/10/2026 | Sandbox escape in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | |
| Analizada | Crítica (9.6) | 0.32% | — | Mozilla FirefoxMozilla Thunderbird | 29/9/2026 | 6/10/2026 | Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | |
| En análisis | Crítica (9.1) | 0.40% | — | Mozilla FirefoxAI | 29/9/2026 | 1/10/2026 | Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. | |
| En análisis | Crítica (9.6) | 0.34% | — | Mozilla FirefoxAIMozilla Firefox ESRAI | 29/9/2026 | 30/9/2026 | Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | |
| En análisis | Crítica (9.6) | 0.32% | — | Mozilla FirefoxAI | 29/9/2026 | 1/10/2026 | Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | |
| En análisis | Crítica (9.6) | 0.32% | — | Mozilla FirefoxAI | 29/9/2026 | 30/9/2026 | Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | |
| Aplazada | Crítica (9.3) | 0.99% | 💥 PoC | GmfeedAI | 29/9/2026 | 30/9/2026 | Google Merchant Center Feed (gmfeed) module for PrestaShop is vulnerable to unauthenticated arbitrary file write in the feed.php endpoint. An unauthenticated attacker can send a crafted request that controls the output file name, path, extension, and content through request parameters. Due to the lack of… | |
| Pendiente de análisis | Crítica (9.1) | 0.74% | — | Hitachienergy Rtu500AI | 29/9/2026 | 29/9/2026 | A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system. Depending on the files affected, successful exploitation could result in unauthorized modification of… | |
| Pendiente de análisis | Crítica (9.1) | 0.58% | 💥 PoC | Hitachienergy Rtu500AI | 29/9/2026 | 29/9/2026 | An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to upload arbitrary firmware through a crafted POST request. Successful exploitation could allow the attacker to modify device functionality or compromise the… | |
| Pendiente de análisis | Crítica (9) | 0.29% | — | Denx U-bootAI | 29/9/2026 | 30/9/2026 | Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment IP packets. This issue was fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa in… | |
| Aplazada | Crítica (9.3) | 0.27% | — | Flowring AgentflowAI | 29/9/2026 | 29/9/2026 | Unrestricted Upload of File with Dangerous Type in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to execute arbitrary system commands via a malicious file. | |
| Aplazada | Crítica (9.3) | 0.28% | — | Flowring AgentflowAI | 29/9/2026 | 29/9/2026 | SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Aplazada | Crítica (9.3) | 0.34% | — | Flowring AgentflowAI | 29/9/2026 | 29/9/2026 | SQL Injection in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the words parameter. | |
| Analizada | Crítica (9.8) | 0.44% | — | Apache Karaf | 29/9/2026 | 7/10/2026 | The jdbc shell command scope shipped no org.apache.karaf.command.acl.jdbc.cfg. Karaf's command guard (SecuredSessionFactoryImpl) treats a command with no matching ACL rule as allowed, so any authenticated shell session (including one holding only the viewer role) could run every jdbc:* command. jdbc:ds-create stores a… | |
| Analizada | Crítica (9.8) | 0.45% | — | Apache Karaf | 29/9/2026 | 7/10/2026 | org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties), which backs the "config" MBean and the config:* shell commands, derives the file it writes a configuration to from caller-supplied input without checking that the result stays inside ${karaf.etc}: Both code paths are reachable by any… | |
| Aplazada | Crítica (9.9) | 0.36% | — | 3DS Geovia Geospatial Data ManagerAI | 29/9/2026 | 30/9/2026 | A Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary code on the server. | |
| Aplazada | Crítica (9.2) | 0.38% | 💥 PoC | Shell-quoteAI | 29/9/2026 | 30/9/2026 | shell-quote's `quote()` function emits a `{ comment }` token as `#` followed by its text, which comments out the rest of the shell line, including the opening quote of any later string token. A line terminator (\n, \r, U+2028, U+2029) in that later string therefore ends the comment, and the rest of the string is… | |
| Aplazada | Crítica (9.3) | 2.0% | — | Netcore Nap930AI | 29/9/2026 | 29/9/2026 | A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file /www/cgi-bin/network_tools of the component Network Tools CGI. The manipulation of the argument sid results in os command injection. The attack may be performed from remote. The exploit has been made public and… | |
| Aplazada | Crítica (9.3) | 0.37% | — | Mall4jAI | 28/9/2026 | 1/10/2026 | mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request body to overwrite passwords without verification, enabling account takeover and… |