Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
900 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 0.46% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 5/8/2026 | 31/8/2026 | A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Buddyboss PlatformAI | 23/7/2026 | 23/7/2026 | Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions. | |
| Pendiente de análisis | Alta (7.5) | 0.50% | — | Bosch Cpp13 IP CameraAIBosch Cpp14 IP CameraAI | 23/7/2026 | 1/10/2026 | A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data. | |
| Pendiente de análisis | Alta (8.4) | 0.11% | — | Bosch Configuration ManagerAI | 23/7/2026 | 1/10/2026 | Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information. | |
| Modificada | Media (5.4) | 0.39% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 17/7/2026 | 16/9/2026 | Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that… | |
| Modificada | Baja (2.7) | 0.35% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 16/7/2026 | 16/9/2026 | A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to… | |
| Pendiente de análisis | Alta (7.7) | 0.32% | — | Bosh Windows Stemcell BuilderAI | 9/7/2026 | 9/7/2026 | Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemcell-builder allows a remote attacker to brute-force the resulting SSH login via TCP/22. Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98. | |
| Pendiente de análisis | Alta (8.5) | 0.15% | — | Bosh-ecosystem Bosh-windows-stemcell-builderAI | 9/7/2026 | 9/7/2026 | Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege authenticated users to overwrite C:\bosh\service_wrapper.exe or C:\bosh\bosh-agent.exe and gain NT AUTHORITY\SYSTEM on the next service restart or reboot. This can lead to full host control. Affected… | |
| Analizada | Alta (7.7) | 0.42% | — | Cloudfoundry Bosh CLI | 9/7/2026 | 13/7/2026 | Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to local command execution on the operator's workstation. Affected versions: bosh-cli… | |
| Analizada | Alta (8.9) | 0.29% | — | Cloudfoundry Bosh CLI | 9/7/2026 | 13/7/2026 | During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new VM's DAV blobstore over HTTPS without verifying the server certificate, even though a CA certificate for that endpoint is available in the installation manifest. A network attacker can terminate the… | |
| Analizada | Alta (8.5) | 0.55% | — | Cloudfoundry Bosh CLI | 9/7/2026 | 13/7/2026 | The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4. | |
| Analizada | Alta (7.1) | 0.23% | — | Cloudfoundry Bosh CLI | 9/7/2026 | 13/7/2026 | A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator runs bosh ssh (or bosh scp/bosh logs -f) with default flags. Affected versions: BOSH CLI versions prior to 7.10.5. | |
| Modificada | Media (4.3) | 0.39% | — | Redhat Build OF KeycloakRedhat Jboss Enterprise Application Platform Expansion Pack | 30/6/2026 | 5/8/2026 | A vulnerability was discovered in Keycloak's Admin UI extension that allows certain administrative users to bypass security restrictions. When Fine-Grained Admin Permissions (FGAPv2) are enabled, an administrator who should only be able to search for users (but not view their full details) can use a specific… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Buddyboss PlatformAIPHPAI | 26/6/2026 | 26/6/2026 | Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions. | |
| Aplazada | Alta (7.6) | 0.15% | — | Xibosignage XiboAI | 10/6/2026 | 23/7/2026 | Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.2, a vulnerability chain consisting of Stored XSS and Iframe Sandbox escape in the Xibo CMS allows users with DataSet permissions to use the Data Connector functionality to craft… | |
| Analizada | Alta (8.1) | 0.65% | — | Vmware Spring FOR Apache KafkaRedhat FuseRedhat Jboss Enterprise Application Platform Expansion Pack | 10/6/2026 | 5/8/2026 | JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Combined with Jackson's default bean deserialization, a producer could supply crafted header values that… | |
| Pendiente de análisis | Alta (8.7) | 0.17% | — | Cloudfoundry BoshAI | 4/6/2026 | 22/7/2026 | ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "#{name}.tgz") where name returns @job_meta['name'], a value taken verbatim from the jobs: array of the attacker-supplied release.MF inside the uploaded tarball. These paths are then interpolated into… | |
| Pendiente de análisis | Alta (7.1) | 0.10% | — | Cloudfoundry BoshAI | 4/6/2026 | 22/7/2026 | CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_async_endpoint and #send_http_get_request_synchronous hard-code OpenSSL::SSL::VERIFY_NONE, enabling an attacker to intercept traffic between bosh-monitor and the BOSH director or… | |
| Pendiente de análisis | Alta (7.1) | 0.14% | — | Cloudfoundry BoshAI | 4/6/2026 | 22/7/2026 | A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth header or UAA client secret) and can tamper with the VM list that is written into the NATS authorization file. Stolen credentials grant administrative director access. UsersSync#bosh_api_response_body… | |
| Pendiente de análisis | Alta (7.5) | 0.42% | — | Bosh-ecosystem Windows Utilities ReleaseAI | 4/6/2026 | 22/7/2026 | Weak Randomness / Insecure Cryptographic Primitive (CWE-338) in Get-RandomPassword in BOSH-Ecosystem / windows-utilities-release allows a network attacker to estimate VM boot time and reconstruct a small candidate list to recover the Administrator password. The randomize_password job exists solely to lock the local… | |
| Pendiente de análisis | Alta (8.7) | 0.16% | — | Cloudfoundry BoshAI | 4/6/2026 | 22/7/2026 | PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz") and name = package_meta['name'] comes directly from release.MF inside the uploaded tarball. The string is passed to Bosh::Common::Exec.sh, which executes via %x{} — i.e., /bin/sh -c. No… | |
| Analizada | Media (6.8) | 0.11% | — | Cloud Foundry Bosh | 27/5/2026 | 17/6/2026 | AgentClient#handle_method (lines 264-303) processes every NATS reply. It calls inject_compile_log (line 273) on every response, which reads response['value']['result']['compile_log_id'] (line 332-338) and passes it to download_and_delete_blob. Separately, any response containing 'exception' goes through… | |
| Analizada | Media (4.3) | 0.13% | — | Cloud Foundry Bosh | 27/5/2026 | 17/6/2026 | When the director sends a long-running request (e.g. compile_package), the agent's reply JSON is consumed by AgentClient. inject_compile_log (line 332-339) reads response['value']['result']['compile_log_id'] and format_exception (line 318-325) reads exception['blobstore_id']; both pass the agent-supplied string… | |
| Aplazada | Alta (7.7) | 0.42% | — | Xibosignage XiboAI | 12/5/2026 | 17/6/2026 | Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.1, an authenticated Server-Side Request Forgery (SSRF) vulnerability in the Xibo CMS allows users with Library upload permissions to make arbitrary HTTP requests from the CMS server to… | |
| Aplazada | Media (5.5) | 0.59% | — | Fujian Apex LivebosAI | 1/5/2026 | 17/6/2026 | A vulnerability has been found in Fujian Apex LiveBOS up to 2.0. Impacted is an unknown function of the file /feed/UploadImage.do of the component Endpoint. Such manipulation of the argument filename leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be… |