Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
9650 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.32% | — | Vmware Spring Advanced Message Queuing Protocol | 27/8/2026 | 1/9/2026 | When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier | |
| Aplazada | Media (4.3) | 0.15% | — | Shopapper Mobile APP BuilderAI | 27/8/2026 | 28/8/2026 | The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not check the user's capabilities before allowing a stock-update operation through one of its REST endpoints, allowing any authenticated user, such as a customer or subscriber, to change the stock… | |
| Analizada | Media (6.5) | 0.42% | — | Vmware Spring Advanced Message Queuing Protocol | 27/8/2026 | 2/9/2026 | An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the consumer JVM with a single ~1 MB message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier | |
| Aplazada | Crítica (9.8) | 0.55% | — | UI Unifi Protect AI KEYAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect AI Key to escalate privileges on the device. | |
| Aplazada | Crítica (10) | 1.6% | — | UI Unifi TalkAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the host device. | |
| Aplazada | Crítica (9.9) | 0.47% | — | UI Unifi AccessAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device. | |
| Aplazada | Crítica (9.8) | 1.6% | — | UI Unifi Enterprise Audio Video BridgeAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Enterprise Audio/Video Bridge to execute a Command Injection on the device. | |
| Aplazada | Crítica (9) | 0.37% | — | UI Unifi Connect Display Cast PROAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Connect Display Cast Pro to escalate privileges on the device. | |
| Aplazada | Crítica (10) | 0.80% | — | UI Unifi OSAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances. | |
| Aplazada | Crítica (9) | 0.51% | — | UI Unifi OSAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances. | |
| Aplazada | Crítica (9.9) | 1.4% | — | UI Unifi ProtectAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device. | |
| Aplazada | Crítica (9.9) | 1.4% | — | UI Unifi AccessAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. | |
| Aplazada | Crítica (9.9) | 1.4% | — | UI Unifi AccessAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. | |
| Aplazada | Crítica (9.6) | 0.41% | — | UI Edgemax EdgeswitchAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to an adjacent network could exploit a Buffer Overflow vulnerability found in a DHCPv6-enabled EdgeMAX EdgeSwitch to initiate a Remote Code Execution on such device. | |
| Aplazada | Media (6.4) | 0.36% | — | Greenshift Animation AND Page Builder BlocksAI | 26/8/2026 | 26/8/2026 | The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customapi action handler in versions up to, and including, 12.8.9. This is due to insufficient sanitization of API responses before output via innerHTML. This makes it possible for authenticated… | |
| Aplazada | Crítica (9) | 0.39% | — | UI Unifi OSAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances. | |
| Aplazada | Crítica (9.9) | 1.4% | — | UI Unifi AccessAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. | |
| Aplazada | Crítica (9.1) | 1.3% | 💥 PoC | UID Enterprise AgentAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute a Command Injection on the host device. | |
| Aplazada | Crítica (9.1) | 0.46% | — | UI Unifi Network ApplicationAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application. | |
| Aplazada | Crítica (9.1) | 1.3% | — | UI Unifi OSAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device. | |
| Aplazada | Crítica (9.1) | 1.3% | — | UI Unifi OS ServerAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device. | |
| Aplazada | Alta (8.2) | 0.39% | — | UI Unifi ConnectAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to escalate privileges within the UniFi Connect Application. | |
| Aplazada | Crítica (10) | 1.6% | — | UI Unifi ProtectAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device. | |
| Aplazada | Crítica (9.9) | 0.42% | — | UI Unifi OSAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances. | |
| Aplazada | Crítica (9.1) | 1.3% | — | UI Unifi Network ApplicationAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Command Injection on an adopted device. |