Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
3320 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.32% | — | Trusteddomain OpendmarcAI | 28/9/2026 | 29/9/2026 | A security vulnerability has been detected in Trusted Domain Project OpenDMARC up to 1.4.2. This impacts an unknown function of the file libopendmarc/opendmarc_policy.c of the component DMARC Parser. The manipulation of the argument pct leads to integer overflow. Remote exploitation of the attack is possible. The… | |
| Aplazada | Baja (2.1) | 0.13% | — | Trusteddomain OpendmarcAI | 28/9/2026 | 1/10/2026 | A weakness has been identified in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_get_tld of the file libopendmarc/opendmarc_tld.c : of the component PSL Wildcard Handler. Executing a manipulation can lead to origin validation error. The attack may be launched remotely. The exploit… | |
| Pendiente de análisis | Media (6.9) | 0.39% | — | Marcos Camara01 Ecommerce TemplateAI | 28/9/2026 | 29/9/2026 | Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.ts, revalidateProducts) in MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote, unauthenticated attacker to force expiration of the entire storefront product cache at will. The… | |
| Aplazada | Alta (8.8) | 0.24% | — | Iron Mountain Archiving Services EnvisionAI | 28/9/2026 | 28/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows SQL Injection. This issue affects enVision: before 260655. | |
| Pendiente de análisis | Media (5.5) | 0.32% | — | Trusteddomain OpendmarcAI | 28/9/2026 | 28/9/2026 | A vulnerability was found in Trusted Domain Project OpenDMARC up to 1.4.2. This vulnerability affects the function strcasecmp in the library libopendmarc/opendmarc_policy.c. The manipulation results in handling of exceptional conditions. The attack can be executed remotely. The exploit has been made public and could… | |
| Pendiente de análisis | Media (5.5) | 0.32% | — | Trusteddomain OpendmarcAI | 28/9/2026 | 28/9/2026 | A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_policy_parse_dmarc in the library libopendmarc/opendmarc_policy.c. The manipulation of the argument fo/rf/ri/pct/sp/adkim/aspf/rua/ruf leads to handling of exceptional conditions. Remote exploitation of… | |
| Pendiente de análisis | Media (5.5) | 0.29% | — | Trusteddomain OpendmarcAI | 28/9/2026 | 1/10/2026 | A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is some unknown functionality of the file policy.c of the component Domain Handler. Executing a manipulation can lead to improper validation of unsafe equivalence in input. The attack may be launched remotely. The exploit has… | |
| Pendiente de análisis | Media (5.5) | 0.31% | — | Trusteddomain OpendmarcAI | 28/9/2026 | 28/9/2026 | A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_util_cleanup in the library libopendmarc/opendmarc_util.c of the component DMARC Record Parser. Performing a manipulation results in off-by-one. The attack may be initiated remotely.… | |
| Pendiente de análisis | Media (5.4) | 0.11% | — | Google Fuse-archiveAI | 28/9/2026 | 29/9/2026 | In Google fuse-archive versions prior to 1.24, an attacker who can prepend a directory to PATH or write a malicious binary to an attacker-controlled or writable directory appearing in PATH can hijack the execution pathway. This allows the attacker to execute arbitrary local code under the security context of the user… | |
| Aplazada | Media (5.7) | 0.33% | — | Barco Clickshare Cx-20 Gen2AI | 28/9/2026 | 28/9/2026 | A vulnerability was determined in Barco ClickShare CX-20 Gen2 up to 02.26.00.0007. Affected by this issue is some unknown functionality of the file /wallpaper of the component Wallpaper Upload. This manipulation of the argument wallpaper causes improper validation of syntactic correctness of input. The attack can be… | |
| Aplazada | Media (5.5) | 0.67% | — | Trusted Domain Project OpenarcAI | 28/9/2026 | 28/9/2026 | A security flaw has been discovered in Trusted Domain Project OpenARC up to 1.0.0.Beta1. Impacted is the function arc_parse_canon_t in the library libopenarc/arc-canon.c of the component libopenarc. The manipulation results in null pointer dereference. The attack may be launched remotely. The exploit has been released… | |
| Pendiente de análisis | Media (5.5) | 0.29% | — | Trusteddomain OpendmarcAI | 27/9/2026 | 1/10/2026 | A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is the function opendmarc_policy_query_dmarc in the library libopendmarc/opendmarc_policy.c of the component Internationalized Domain Name Handler. Such manipulation leads to encoding error. It is possible to launch… | |
| Pendiente de análisis | Media (5.5) | 0.37% | — | Trusteddomain OpendmarcAI | 27/9/2026 | 28/9/2026 | A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_spf_ipv6_explode in the library libopendmarc/opendmarc_spf.c of the component SPF Parser. This manipulation of the argument cp causes null pointer dereference. It is possible to initiate the… | |
| Analizada | Media (4.9) | 0.44% | — | Elasticsearch | 26/9/2026 | 6/10/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 26/9/2026 | 29/9/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 26/9/2026 | 29/9/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 26/9/2026 | 29/9/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 26/9/2026 | 29/9/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 26/9/2026 | 1/10/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 26/9/2026 | 29/9/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). | |
| Pendiente de análisis | Media (5.5) | 0.27% | — | Wikimedia CirrussearchAI | 24/9/2026 | 24/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - CirrusSearch extension allows Reflected XSS. This issue affects Mediawiki - CirrusSearch extension through 1.46.0. | |
| Pendiente de análisis | Alta (7.4) | 0.20% | — | Thebrowser ARC SearchAI | 23/9/2026 | 24/9/2026 | Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker can exploit this via a specially crafted website to render fake UI elements, such as a spoofed address bar, misleading the user about… | |
| Aplazada | Alta (8.4) | 0.27% | — | Klever-goAIElasticsearchAI | 23/9/2026 | 24/9/2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, indexer/common.go serializedDataForUpdateAccounts places the attacker-controlled acc.Name value into an Elasticsearch _bulk JSON and NDJSON request without escaping it. The SetAccountName transaction accepts valid UTF-8 account… | |
| Pendiente de análisis | Alta (7.4) | 0.26% | — | ARCAI | 23/9/2026 | 24/9/2026 | An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a <select> element that triggers requestFullscreen without displaying the fullscreen notification. | |
| Pendiente de análisis | Alta (8.6) | 0.43% | — | Dani-garcia VaultwardenAI | 22/9/2026 | 24/9/2026 | Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries, allowing revoked and not-yet-confirmed members to retain read, write, delete, and attachment access to organization ciphers. Attackers with revoked or pending membership can exploit missing status… |