Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
40.026 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.1) | 0.45% | — | Nginxproxymanager Nginx Proxy ManagerAI | 28/9/2026 | 29/9/2026 | Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa to gain full session… | |
| Analizada | Crítica (9.1) | 0.20% | 💥 PoC | Pyjwt Project Pyjwt | 28/9/2026 | 7/10/2026 | PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/utils.py is affected because is_pem_format does not recognize every PEM representation accepted by the cryptography loader. This occurs when an application mixes HMAC and asymmetric algorithms and supplies a mutated… | |
| Analizada | Crítica (9.1) | 0.16% | — | Pyjwt Project Pyjwt | 28/9/2026 | 7/10/2026 | PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT PyJWKClient is affected because redirect destinations are not revalidated against the JWKS trust boundary. This occurs when a configured trusted JWKS endpoint returns an attacker-influenced redirect. As a result, PyJWKClient follows… | |
| Analizada | Crítica (9.1) | 0.18% | — | Pyjwt Project Pyjwt | 28/9/2026 | 7/10/2026 | PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.from_jwk is affected because PyJWK verification path used the decoded key without applying prepare_key validation. This occurs when a trusted JWK Set contains an oct entry with an empty k value. As a result, an… | |
| Pendiente de análisis | Crítica (9.8) | 0.28% | 💥 PoC | AuthlibAI | 28/9/2026 | 1/10/2026 | Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signature and without requiring a cryptographic key. | |
| Analizada | Crítica (9.3) | 0.28% | 💥 PoC | Ordasoft Book Library | 28/9/2026 | 7/10/2026 | Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 - site/booklibrary.php’s books() function reads the field and direction request parameters and passes each through a function called protectInjectionWithoutQuote(), whose only real protection is a keyword blacklist that, on… | |
| Pendiente de análisis | Crítica (9.3) | 0.28% | 💥 PoC | Ordasoft Vehicle ManagerAI | 28/9/2026 | 30/9/2026 | Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 - site/vehiclemanager.php reads the order_field and order_direction sort parameters at three separate anonymous-reachable frontend entry points (category listing, search, and the all-vehicles listing) through a sanitizing… | |
| Pendiente de análisis | Crítica (9.3) | 0.28% | 💥 PoC | Ordasoft Real Estate ManagerAI | 28/9/2026 | 30/9/2026 | Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of three separate frontend property-listing queries (category browsing, search results, and the full property listing) from a request-controlled order_field… | |
| Aplazada | Crítica (9.1) | 0.28% | — | BluehoodAI | 28/9/2026 | 30/9/2026 | Bluehood monitors local bluetooth activity. Prior to version 0.7.1, when auth_enabled is set in Bluehood, only the HTML page handlers enforced session validation. The /api/* handlers (settings, devices, groups, per-device endpoints including /api/device/{mac}/notes) called no auth check at all. A network attacker… | |
| Aplazada | Crítica (9.3) | 2.0% | — | Watchguard APAI | 28/9/2026 | 28/9/2026 | An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system. | |
| Pendiente de análisis | Crítica (9.1) | 0.81% | 💥 PoC | Xhmikosr DecompressAI | 28/9/2026 | 30/9/2026 | The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An attacker can supply a crafted archive containing chained symlink entries so that a… | |
| Aplazada | Crítica (9.3) | 0.27% | — | Watchguard Access PointAI | 28/9/2026 | 28/9/2026 | An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session. | |
| Pendiente de análisis | Crítica (9.6) | 0.54% | — | Suse RancherAI | 28/9/2026 | 29/9/2026 | An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before 2.12.14 and 2.11 before 2.11.18. | |
| Pendiente de análisis | Crítica (9.6) | 0.19% | — | Sailpoint IdentityiqAI | 28/9/2026 | 30/9/2026 | This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution on the IdentityIQ server due to improper input validation of submitted web service API content. | |
| Aplazada | Crítica (9.3) | 0.71% | — | Netcore Nr289 GEAI | 28/9/2026 | 28/9/2026 | A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This manipulation causes missing authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this… | |
| Aplazada | Crítica (9.3) | 2.0% | — | Netcore Nr289 GEAI | 28/9/2026 | 1/10/2026 | A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file /set_ntp_server_ip.cgi of the component CGI Handler. The manipulation of the argument ntp_ip results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. The… | |
| Aplazada | Crítica (9.3) | 2.5% | — | Netcore Nr289-geAI | 28/9/2026 | 28/9/2026 | A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of the file /location_time.cgi of the component Location Time Handler. The manipulation of the argument mac leads to os command injection. Remote exploitation of the attack is possible. The exploit has… | |
| Aplazada | Crítica (9.8) | 0.27% | — | Innotim Software Telecommunications AND Consultancy Trade Logsign SiemAI | 28/9/2026 | 28/9/2026 | Use of default credentials vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Try Common or Default Usernames and Passwords. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117. | |
| Aplazada | Crítica (9.9) | 0.41% | — | Canonical LXDAI | 28/9/2026 | 29/9/2026 | Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes in a project, or a malicious migration source server, to write attacker-controlled files… | |
| Aplazada | Crítica (9.9) | 0.52% | — | Canonical LXDAI | 28/9/2026 | 29/9/2026 | Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a crafted subvolumes[].path entry in backup/optimized_header.yaml during a btrfs… | |
| Aplazada | Crítica (9.6) | 0.36% | — | Canonical LXDAI | 28/9/2026 | 28/9/2026 | Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary files on the host as root. On hosts whose root filesystem is btrfs, the client can… | |
| Aplazada | Crítica (9.2) | 0.42% | — | Dayforce PayrollAI | 28/9/2026 | 28/9/2026 | Dayforce Payroll is vulnerable to Path Traversal in file download functionality. An unauthenticated attacker can sent GET request with file path parameter set to any path including an absolute local file path. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version… | |
| Aplazada | Crítica (9.3) | 0.29% | — | Dayforce PayrollAI | 28/9/2026 | 28/9/2026 | Dayforce Payroll is vulnerable to Time Based-Blind SQL Injection in password recovery functionality. The unauthenticated attacker can prepare GET request with one of the parameters filled in with an arbitrary SQL query. The parameter is interpreted as part of SQL predicate resulting in Time-Based Blind SQL Injection.… | |
| Aplazada | Crítica (9.3) | 2.0% | — | Netcore Nr289 GEAI | 28/9/2026 | 28/9/2026 | A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such manipulation of the argument ip leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The… | |
| Pendiente de análisis | Crítica (9.4) | 0.36% | — | Google Cloud Application IntegrationAI | 28/9/2026 | 30/9/2026 | A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user with standard permissions to run arbitrary code on the shared production servers using a specially crafted script bypassing… |