Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
8750 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 0.29% | — | Discourse | 31/3/2026 | 24/7/2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, a user may be able to purchase a lower tier subscription but grant themselves the benefits that comes along with a higher tier subscription.… | |
| Analizada | Baja (2) | 0.29% | — | Discourse | 31/3/2026 | 24/7/2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, the discourse-subscriptions plugin leaks stripe API keys across sites in a multisite cluster resulting in the potential for stripe related… | |
| Analizada | Media (4.3) | 0.34% | — | Discourse | 31/3/2026 | 24/7/2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authenticated user can obtain shared draft topic titles by sending an inline onebox request with a category_id parameter matching the shared… | |
| Analizada | Media (5.3) | 0.34% | — | Discourse | 31/3/2026 | 24/7/2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, non-staff users could access read receipt information for staff-only posts they weren't supposed to see. No post content was exposed, only… | |
| Analizada | Media (6.3) | 0.27% | — | Discourse | 31/3/2026 | 24/7/2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, users who lost access to a topic (e.g., removed from a private category group) could still interact with polls in that topic, including voting… | |
| Analizada | Media (4.3) | 0.34% | — | Discourse | 31/3/2026 | 24/7/2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, there is possible channel membership inference from chat user search without authorization. This issue has been patched in versions 2026.1.3,… | |
| Analizada | Media (5.3) | 0.26% | — | Discourse | 31/3/2026 | 24/7/2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, category group moderators could perform privileged actions on topics inside private categories they did not have read access to. This issue has… | |
| Analizada | Baja (2.1) | 0.28% | — | Discourse | 31/3/2026 | 24/7/2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, when the hidden prioritize_full_name_in_ux site setting is enabled (defaults to false, requires console access to change), user and group… | |
| Analizada | Media (5.4) | 0.28% | — | Discourse | 31/3/2026 | 24/7/2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, updating a category description via API is not sanitizing the description string, which can lead to XSS attacks. This issue has been patched in… | |
| Analizada | Media (5.3) | 0.29% | — | Discourse | 31/3/2026 | 24/7/2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an attacker with the ability to create shared AI conversations could inject arbitrary HTML and JavaScript via crafted conversation titles. This… | |
| Analizada | Media (5.3) | 0.40% | — | Discourse | 31/3/2026 | 24/7/2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, moderators could export CSV data for admin-restricted reports, bypassing the report visibility restrictions. This could expose sensitive… | |
| Analizada | Media (5.1) | 0.34% | — | Discourse | 31/3/2026 | 24/7/2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, the enter action in StaticController reads the sso_destination_url cookie and redirects to it with allow_other_host: true without validating the… | |
| Aplazada | Baja (1.9) | 0.16% | — | ORC DiscountAI | 26/3/2026 | 17/6/2026 | A weakness has been identified in Orc discount up to 3.0.1.2. This issue affects the function compile of the file markdown.c of the component Markdown Handler. This manipulation causes uncontrolled recursion. The attack is restricted to local execution. The exploit has been made available to the public and could be… | |
| Pendiente de análisis | Alta (7.7) | 0.28% | — | Cisco IOSAICisco IOS XEAI | 25/3/2026 | 17/6/2026 | A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E could allow an authenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper validation of user-supplied… | |
| Pendiente de análisis | Media (6.1) | 0.15% | — | Cisco IOS XEAICisco MerakiAI | 25/3/2026 | 17/6/2026 | A vulnerability in Cisco IOS XE Software for Cisco Meraki could allow a remote, unauthenticated attacker to view confidential device information. This vulnerability is due to a device configuration upload being performed over an insecure tunnel. An attacker could exploit this vulnerability by conducting an on-path… | |
| Pendiente de análisis | Media (5.4) | 0.28% | — | Cisco IOS XEAI | 25/3/2026 | 17/6/2026 | A vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate their privileges and access management APIs that would not normally be available for Lobby Ambassador users. This vulnerability exists because parameters that are received… | |
| Pendiente de análisis | Media (5.3) | 0.29% | — | Cisco IOS XEAICisco IOXAI | 25/3/2026 | 17/6/2026 | A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user. This vulnerability is due to insufficient validation of user input. An… | |
| Pendiente de análisis | Media (4.8) | 0.19% | — | Cisco IOS XEAICisco IOXAI | 25/3/2026 | 17/6/2026 | A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is… | |
| Pendiente de análisis | Media (6.5) | 0.09% | — | Cisco IOS XEAI | 25/3/2026 | 17/6/2026 | A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because incorrect privileges are associated with the start maintenance command. An attacker could exploit this vulnerability by… | |
| Analizada | Media (5.4) | 0.16% | — | Cisco Catalyst Sd-wan Manager | 25/3/2026 | 29/6/2026 | A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user input. An attacker… | |
| Pendiente de análisis | Alta (8.6) | 0.35% | — | Cisco IOS XE Wireless Controller SoftwareAI | 25/3/2026 | 17/6/2026 | A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) packets of Cisco IOS XE Wireless Controller Software for the Catalyst CW9800 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is… | |
| Pendiente de análisis | Media (6.5) | 0.09% | — | Cisco IOS XEAI | 25/3/2026 | 17/6/2026 | A vulnerability in the Secure Copy Protocol (SCP) server feature of Cisco IOS XE Software could allow an authenticated, local attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of a malformed SCP request. An attacker could… | |
| Analizada | Alta (8.6) | 0.35% | — | Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance SoftwareCisco IOSCisco IOS XE | 25/3/2026 | 17/9/2026 | A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak,… | |
| Analizada | Media (6.1) | 0.15% | — | Cisco IOS XE | 25/3/2026 | 28/9/2026 | A vulnerability in the bootloader of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches, Cisco Catalyst ESS9300 Embedded Series Switches, Cisco Catalyst IE9310 and IE9320 Rugged Series Switches, and Cisco IE3500 and IE3505 Rugged Series Switches could allow an authenticated, local attacker with level-15… | |
| Analizada | Alta (8.6) | 0.35% | — | Cisco IOS XE | 25/3/2026 | 28/9/2026 | A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause BOOTP packets to be forwarded between VLANs, resulting in a denial of service (DoS) condition. This vulnerability is due to improper handling of BOOTP packets on Cisco Catalyst 9000 Series… |