Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

3320 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.32%—Trusteddomain OpendmarcAI28/9/202629/9/2026
A security vulnerability has been detected in Trusted Domain Project OpenDMARC up to 1.4.2. This impacts an unknown function of the file libopendmarc/opendmarc_policy.c of the component DMARC Parser. The manipulation of the argument pct leads to integer overflow. Remote exploitation of the attack is possible. The…
AplazadaBaja (2.1)0.13%—Trusteddomain OpendmarcAI28/9/20261/10/2026
A weakness has been identified in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_get_tld of the file libopendmarc/opendmarc_tld.c : of the component PSL Wildcard Handler. Executing a manipulation can lead to origin validation error. The attack may be launched remotely. The exploit…
Pendiente de análisisMedia (6.9)0.39%—Marcos Camara01 Ecommerce TemplateAI28/9/202629/9/2026
Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.ts, revalidateProducts) in MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote, unauthenticated attacker to force expiration of the entire storefront product cache at will. The…
AplazadaAlta (8.8)0.24%—Iron Mountain Archiving Services EnvisionAI28/9/202628/9/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows SQL Injection. This issue affects enVision: before 260655.
Pendiente de análisisMedia (5.5)0.32%—Trusteddomain OpendmarcAI28/9/202628/9/2026
A vulnerability was found in Trusted Domain Project OpenDMARC up to 1.4.2. This vulnerability affects the function strcasecmp in the library libopendmarc/opendmarc_policy.c. The manipulation results in handling of exceptional conditions. The attack can be executed remotely. The exploit has been made public and could…
Pendiente de análisisMedia (5.5)0.32%—Trusteddomain OpendmarcAI28/9/202628/9/2026
A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_policy_parse_dmarc in the library libopendmarc/opendmarc_policy.c. The manipulation of the argument fo/rf/ri/pct/sp/adkim/aspf/rua/ruf leads to handling of exceptional conditions. Remote exploitation of…
Pendiente de análisisMedia (5.5)0.29%—Trusteddomain OpendmarcAI28/9/20261/10/2026
A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is some unknown functionality of the file policy.c of the component Domain Handler. Executing a manipulation can lead to improper validation of unsafe equivalence in input. The attack may be launched remotely. The exploit has…
Pendiente de análisisMedia (5.5)0.31%—Trusteddomain OpendmarcAI28/9/202628/9/2026
A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_util_cleanup in the library libopendmarc/opendmarc_util.c of the component DMARC Record Parser. Performing a manipulation results in off-by-one. The attack may be initiated remotely.…
Pendiente de análisisMedia (5.4)0.11%—Google Fuse-archiveAI28/9/202629/9/2026
In Google fuse-archive versions prior to 1.24, an attacker who can prepend a directory to PATH or write a malicious binary to an attacker-controlled or writable directory appearing in PATH can hijack the execution pathway. This allows the attacker to execute arbitrary local code under the security context of the user…
AplazadaMedia (5.7)0.33%—Barco Clickshare Cx-20 Gen2AI28/9/202628/9/2026
A vulnerability was determined in Barco ClickShare CX-20 Gen2 up to 02.26.00.0007. Affected by this issue is some unknown functionality of the file /wallpaper of the component Wallpaper Upload. This manipulation of the argument wallpaper causes improper validation of syntactic correctness of input. The attack can be…
AplazadaMedia (5.5)0.67%—Trusted Domain Project OpenarcAI28/9/202628/9/2026
A security flaw has been discovered in Trusted Domain Project OpenARC up to 1.0.0.Beta1. Impacted is the function arc_parse_canon_t in the library libopenarc/arc-canon.c of the component libopenarc. The manipulation results in null pointer dereference. The attack may be launched remotely. The exploit has been released…
Pendiente de análisisMedia (5.5)0.29%—Trusteddomain OpendmarcAI27/9/20261/10/2026
A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is the function opendmarc_policy_query_dmarc in the library libopendmarc/opendmarc_policy.c of the component Internationalized Domain Name Handler. Such manipulation leads to encoding error. It is possible to launch…
Pendiente de análisisMedia (5.5)0.37%—Trusteddomain OpendmarcAI27/9/202628/9/2026
A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_spf_ipv6_explode in the library libopendmarc/opendmarc_spf.c of the component SPF Parser. This manipulation of the argument cp causes null pointer dereference. It is possible to initiate the…
AnalizadaMedia (4.9)0.44%—Elasticsearch26/9/20266/10/2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
AnalizadaMedia (6.5)0.42%—Elasticsearch26/9/202629/9/2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
AnalizadaMedia (6.5)0.42%—Elasticsearch26/9/202629/9/2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
AnalizadaMedia (6.5)0.42%—Elasticsearch26/9/202629/9/2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
AnalizadaMedia (6.5)0.42%—Elasticsearch26/9/202629/9/2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
AnalizadaMedia (6.5)0.42%—Elasticsearch26/9/20261/10/2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130).
AnalizadaMedia (6.5)0.42%—Elasticsearch26/9/202629/9/2026
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130).
Pendiente de análisisMedia (5.5)0.27%—Wikimedia CirrussearchAI24/9/202624/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - CirrusSearch extension allows Reflected XSS. This issue affects Mediawiki - CirrusSearch extension through 1.46.0.
Pendiente de análisisAlta (7.4)0.20%—Thebrowser ARC SearchAI23/9/202624/9/2026
Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker can exploit this via a specially crafted website to render fake UI elements, such as a spoofed address bar, misleading the user about…
AplazadaAlta (8.4)0.27%—Klever-goAIElasticsearchAI23/9/202624/9/2026
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, indexer/common.go serializedDataForUpdateAccounts places the attacker-controlled acc.Name value into an Elasticsearch _bulk JSON and NDJSON request without escaping it. The SetAccountName transaction accepts valid UTF-8 account…
Pendiente de análisisAlta (7.4)0.26%—ARCAI23/9/202624/9/2026
An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a <select> element that triggers requestFullscreen without displaying the fullscreen notification.
Pendiente de análisisAlta (8.6)0.43%—Dani-garcia VaultwardenAI22/9/202624/9/2026
Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries, allowing revoked and not-yet-confirmed members to retain read, write, delete, and attachment access to organization ciphers. Attackers with revoked or pending membership can exploit missing status…