Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
11.348 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.13% | — | Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux | 4/8/2026 | 31/8/2026 | A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process… | |
| Analizada | Baja (3.3) | 0.13% | — | Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux | 4/8/2026 | 31/8/2026 | A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. A local attacker can exploit this to disclose cached… | |
| Pendiente de análisis | Crítica (9.3) | 0.72% | — | Tenable Sensor ProxyAI | 3/8/2026 | 18/8/2026 | A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sensor to an attacker-controlled host. | |
| Pendiente de análisis | Alta (8.2) | 0.27% | — | OpensslAIGoogle BoringsslAICryptography.io CryptographyAIOpenbsd LibresslAI | 3/8/2026 | 10/9/2026 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the… | |
| Pendiente de análisis | Media (5.1) | 0.18% | — | OpnsenseAI | 3/8/2026 | 16/9/2026 | OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary HTML or JavaScript by embedding payloads in the certificate description field via the trust certificate API. The unsanitized description value is persisted and later rendered in the… | |
| Pendiente de análisis | Media (5.1) | 0.29% | — | OpnsenseAI | 3/8/2026 | 16/9/2026 | OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with firewall rule management privileges to inject arbitrary HTML or JavaScript by embedding payloads in the firewall rule description field via the filter API endpoint. The unsanitized description value is… | |
| Aplazada | Media (6) | 0.51% | — | Duckdb AWS ExtensionAIDuckdbAIPostgres PG DuckdbAI | 3/8/2026 | 9/9/2026 | The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any database user with SQL execution permissions to extract plaintext AWS credentials by calling the load_aws_credentials function with the redact_secret parameter set to false, circumventing the database-wide… | |
| Aplazada | Alta (8.5) | 0.17% | — | FirmacheckAIOpensslAI | 3/8/2026 | 24/9/2026 | FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafted openssl.cnf file in the unvalidated C:\Program Files (x86)\Common Files\SSL\ directory path. Attackers can write a malicious OpenSSL configuration file referencing an… | |
| Modificada | Media (4.4) | 0.08% | — | GNU TARRedhat Openshift Container PlatformRedhat Enterprise Linux | 3/8/2026 | 22/9/2026 | A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or… | |
| Modificada | Media (4.4) | 0.14% | — | GNU TARRedhat Openshift Container PlatformRedhat Enterprise Linux | 3/8/2026 | 22/9/2026 | A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with… | |
| Analizada | Media (5.5) | 0.13% | — | Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux | 3/8/2026 | 31/8/2026 | A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. A local attacker can exploit this via a crafted GETHOSTBYADDR request to the NSS responder socket, causing an out-of-bounds read and process crash,… | |
| Aplazada | Alta (7.1) | 0.19% | — | Mitsubishielectric Melsec MX Controller Mx-rAIMitsubishielectric Melsec MX Controller Mx-fAIMitsubishielectric Cc-link IE TSN Interface BoardAIMitsubishielectric Motion ModuleAI+25 | 30/7/2026 | 18/9/2026 | Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, MELSEC iQ-L Series Motion Module, Motion Control Board,… | |
| Aplazada | Media (4.3) | 0.27% | — | Wensolutions WP TravelAI | 30/7/2026 | 30/7/2026 | The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its customer account dashboard belongs to the current user, allowing any logged-in user to read another customer's booking details, including billing address information, by supplying an arbitrary booking identifier. | |
| Aplazada | Media (5.3) | 0.30% | — | Wensolutions WP TravelAI | 30/7/2026 | 30/7/2026 | The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal post-back handshake before marking a booking paid, allowing unauthenticated attackers to forge a notification that flips an arbitrary pending booking to a paid and booked state at an attacker-chosen… | |
| Pendiente de análisis | Alta (7.5) | 0.48% | — | Opensuse PCPAI | 30/7/2026 | 1/10/2026 | A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads. | |
| Aplazada | Media (5.1) | 0.41% | — | Opensolution Quick.cmsAI | 29/7/2026 | 30/7/2026 | A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a high-privileged user into multiple fields in administration panel allows for Blind SQL Injection attacks. The vendor states that this administration panel already allows for significant modification… | |
| Analizada | Crítica (10) | 0.81% | 💥 PoC | Aimy-extensions Aimy Captcha-less Form Guard | 29/7/2026 | 5/8/2026 | Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution. | |
| Pendiente de análisis | Alta (8.5) | 0.53% | — | Openshift Oauth-proxyAI | 28/7/2026 | 21/9/2026 | A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated… | |
| Aplazada | Media (5.1) | 0.57% | — | Opensolution Quick.cmsAI | 28/7/2026 | 30/7/2026 | A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash (../) sequences before resolving and serving the requested file. An authenticated attacker with admin privileges can use this vulnerability to read contents of files… | |
| Aplazada | Media (5.1) | 0.53% | — | Opensolution Quick.cmsAI | 28/7/2026 | 30/7/2026 | Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated attacker with admin privileges can include arbitrary files located within the application's directory structure via a crafted HTTP request. Successful exploitation allows disclosure of the server's… | |
| Aplazada | Alta (7) | 0.57% | — | Opensolution Quick CMSAI | 28/7/2026 | 30/7/2026 | In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding option from the interface; however, the underlying language-deletion API endpoint does not enforce an equivalent server-side authorization check. As a result, an authenticated administrator can… | |
| Aplazada | Alta (7.5) | 0.46% | — | OpensbiAI | 27/7/2026 | 5/10/2026 | An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and configure a matching counter' function of SBI PMU extension. | |
| Aplazada | Media (6.1) | 0.27% | — | Sina ExtensionAI | 27/7/2026 | 27/7/2026 | The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input in one of its unauthenticated AJAX handlers before reflecting it into the HTML response, allowing unauthenticated attackers to execute arbitrary JavaScript in the browser of anyone who triggers a… | |
| Aplazada | Media (4.8) | 0.48% | — | Openstack ZaqarAI | 24/7/2026 | 30/7/2026 | OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known. | |
| Aplazada | Alta (7.2) | 0.78% | — | Openstack Ironic Python AgentAI | 24/7/2026 | 30/7/2026 | In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell. |