Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
8750 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.5) | 0.43% | — | Hoppscotch | 2/4/2026 | 24/7/2026 | hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is an open redirect vulnerability that leads to token exfiltration. With these tokens, the attacker can sign in as the victim to takeover their account. This issue has been patched in version 2026.3.0. | |
| Analizada | Media (5.4) | 0.24% | — | Hoppscotch | 2/4/2026 | 24/7/2026 | hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability in the team member overflow tooltip via display name. This issue has been patched in version 2026.3.0. | |
| Analizada | Media (6.1) | 0.46% | 💥 Exploit | Hoppscotch | 2/4/2026 | 24/7/2026 | hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, the /enter page contains a DOM-based open redirect vulnerability. The redirect query parameter is directly used to construct a URL and redirect the user without proper validation. This issue has been patched in version 2026.3.0. | |
| Analizada | Media (6.5) | 0.48% | — | Erudika Scoold | 2/4/2026 | 24/7/2026 | Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.66.1, Scoold contains an authenticated authorization flaw in feedback deletion that allows any logged-in, low-privilege user to delete another user's feedback post by submitting its ID to POST /feedback/{id}/delete. The handler enforces… | |
| Analizada | Media (4.9) | 0.49% | — | Cisco Nexus Dashboard InsightsCisco Nexus Dashboard | 1/4/2026 | 1/7/2026 | A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights could allow an authenticated, remote attacker to write arbitrary files to an affected system. This vulnerability is due to insufficient validation of the metadata update file. An attacker could exploit this vulnerability by crafting a… | |
| Analizada | Crítica (9.8) | 0.91% | — | Cisco Smart Software Manager On-prem | 1/4/2026 | 1/7/2026 | A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host. This vulnerability is due to the unintentional exposure of an internal service. An attacker could… | |
| Analizada | Alta (8) | 0.27% | — | Cisco Evolved Programmable Network Manager | 1/4/2026 | 2/7/2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to access. This vulnerability is due to improper authorization checks on a REST API… | |
| Analizada | Alta (7.3) | 0.27% | — | Cisco Smart Software Manager On-prem | 1/4/2026 | 8/7/2026 | A vulnerability in the web interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges on an affected system. This vulnerability is due to the improper transmission of sensitive user information. An attacker could exploit this vulnerability by… | |
| Analizada | Media (6.5) | 0.39% | — | Cisco Unified Computing System | 1/4/2026 | 28/8/2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to execute arbitrary code as the root user. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could… | |
| Analizada | Media (6.5) | 0.72% | — | Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software | 1/4/2026 | 28/8/2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to improper validation of user-supplied… | |
| Analizada | Media (6.5) | 0.93% | — | Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software | 1/4/2026 | 28/8/2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to improper validation of user-supplied… | |
| Analizada | Alta (8.8) | 1.1% | — | Cisco Unified Computing SystemCisco Unified Computing System E-series Software | 1/4/2026 | 28/8/2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to improper validation of user-supplied input.… | |
| Pendiente de análisis | Crítica (9.8) | 0.99% | — | Cisco Integrated Management ControllerAI | 1/4/2026 | 17/6/2026 | A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin. This vulnerability is due to incorrect handling of password change requests. An attacker could… | |
| Analizada | Media (4.8) | 0.24% | — | Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software | 1/4/2026 | 28/8/2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this… | |
| Analizada | Media (4.8) | 0.24% | — | Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software | 1/4/2026 | 28/8/2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this… | |
| Analizada | Media (4.8) | 0.22% | — | Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software | 1/4/2026 | 28/8/2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this… | |
| Analizada | Media (4.8) | 0.17% | — | Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software | 1/4/2026 | 28/8/2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this… | |
| Analizada | Media (6.1) | 0.18% | — | Cisco Enterprise NFV Infrastructure SoftwareCisco Unified Computing SystemCisco Unified Computing System E-series Software | 1/4/2026 | 28/8/2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of… | |
| Analizada | Media (6.5) | 0.29% | — | Cisco Nexus Dashboard | 1/4/2026 | 8/7/2026 | A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Full or Config-only backup files to access sensitive information. This vulnerability exists because authentication details are included in the encrypted backup files. An… | |
| En análisis | Media (6.1) | 0.24% | — | Cisco Nexus DashboardAICisco Nexus Dashboard InsightsAI | 1/4/2026 | 17/6/2026 | A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit… | |
| Analizada | Media (6.9) | 0.40% | — | Freescout | 31/3/2026 | 24/7/2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, checkIpByMask() in app/Misc/Helper.php checks whether the input IP contains a / character. Plain IP addresses never contain /, so the function always returns false without checking any CIDR ranges. The entire… | |
| Analizada | Media (6.1) | 0.32% | — | Freescout | 31/3/2026 | 24/7/2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, host header manipulation in FreeScout version (http://localhost:8080/system/status) allows an attacker to inject an arbitrary domain into generated absolute URLs. This leads to External Resource Loading and… | |
| Analizada | Media (5.1) | 0.32% | — | Discourse | 31/3/2026 | 24/7/2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authenticated moderator-level user could retrieve post content, topic titles, and usernames from categories they were not authorized to view.… | |
| Analizada | Media (5.3) | 0.40% | — | Discourse | 31/3/2026 | 24/7/2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authorization bypass in the Category Chatables Controller show action allowed moderators to get information on hidden groups names and user… | |
| Analizada | Media (5.3) | 0.32% | — | Discourse | 31/3/2026 | 24/7/2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, the group email settings test endpoint could be used to make the server initiate outbound connections to arbitrary hosts and ports. This could… |