Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
2691 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Alta (8.7) | 0.21% | — | Kiteworks CoreAI | 30/9/2026 | 1/10/2026 | Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-site Scripting (XSS) that could allow an authenticated user to store crafted content that executes arbitrary JavaScript in another user's authenticated session when they preview shared content. This could potentially lead to session compromise and… | |
| En análisis | Media (4.3) | 0.20% | — | Kiteworks CoreAI | 30/9/2026 | 1/10/2026 | Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. A URL parameter in the PDF viewer was insufficiently validated, allowing an attacker-controlled document to be loaded and displayed under the trust of the legitimate application domain. This could increase the credibility of phishing attempts… | |
| Pendiente de análisis | Media (6.3) | 0.47% | — | VaadinAIVaadin CoreAIVaadin Charts FlowAIVaadin ChartsAI+1 | 30/9/2026 | 30/9/2026 | A prototype pollution vulnerability exists in the deep merge helpers of Vaadin Charts and Vaadin Component Base. Merging an object the application does not control into a chart configuration or into a component's i18n property writes onto Object.prototype, making the injected properties visible to every object in the… | |
| Aplazada | Media (5.4) | 0.16% | — | Pixfort CoreAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in pixfort Core < 4.3.3 versions. | |
| Pendiente de análisis | Alta (8.1) | 0.20% | — | JupyterlabAIJupyter NotebookAIJupyterlite CoreAI | 29/9/2026 | 2/10/2026 | JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.5.0 until 4.5.11 and 4.6.4, from Notebook 7.5.0 until 7.6.3, and from JupyterLite Core 0.7.0 until 0.8.4, the system clipboard cell-paste path accepts attacker-controlled… | |
| Pendiente de análisis | Media (6.8) | 0.26% | — | JupyterlabAIJupyterlite CoreAI | 29/9/2026 | 29/9/2026 | JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 3.0.0 until 4.5.11 and 4.6.4, and in JupyterLite Core 0.8.3 and earlier, the Plural-Forms header in a selected third-party language pack can append JavaScript after a valid… | |
| Aplazada | Baja (2) | 0.22% | — | Netcore Nap930AI | 29/9/2026 | 1/10/2026 | A vulnerability was determined in Netcore NAP930 0.1.241010.141410. This vulnerability affects unknown code of the file /lib/functions/backup_common.sh of the component Backup/Restore. This manipulation of the argument aes_pass causes use of hard-coded cryptographic key . It is possible to initiate the attack… | |
| Aplazada | Crítica (9.3) | 2.0% | — | Netcore Nap930AI | 29/9/2026 | 29/9/2026 | A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file /www/cgi-bin/network_tools of the component Network Tools CGI. The manipulation of the argument sid results in os command injection. The attack may be performed from remote. The exploit has been made public and… | |
| Aplazada | Media (5.5) | 0.45% | — | Netcore Power13AI | 28/9/2026 | 1/10/2026 | A security vulnerability has been detected in Netcore POWER13 2.0.240730.162638. This issue affects the function routerd.passwd_set of the file /ubus. Such manipulation leads to weak password recovery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was… | |
| Aplazada | Crítica (9.3) | 0.71% | — | Netcore Nr289 GEAI | 28/9/2026 | 28/9/2026 | A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This manipulation causes missing authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this… | |
| Aplazada | Crítica (9.3) | 2.0% | — | Netcore Nr289 GEAI | 28/9/2026 | 1/10/2026 | A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file /set_ntp_server_ip.cgi of the component CGI Handler. The manipulation of the argument ntp_ip results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. The… | |
| Aplazada | Crítica (9.3) | 2.5% | — | Netcore Nr289-geAI | 28/9/2026 | 28/9/2026 | A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of the file /location_time.cgi of the component Location Time Handler. The manipulation of the argument mac leads to os command injection. Remote exploitation of the attack is possible. The exploit has… | |
| Aplazada | Alta (8.9) | 1.3% | — | Netcore Nr289 GEAI | 28/9/2026 | 28/9/2026 | A weakness has been identified in Netcore NR289-GE 1.4.5102. The affected element is the function password-check of the file /bin/boa of the component Authentication. Executing a manipulation of the argument Username can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.63% | — | Netcore Nr289-geAI | 28/9/2026 | 1/10/2026 | A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an unknown function of the file /bin/boa of the component CGI Dispatcher. Performing a manipulation results in improper authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for… | |
| Aplazada | Crítica (9.3) | 2.0% | — | Netcore Nr289 GEAI | 28/9/2026 | 28/9/2026 | A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such manipulation of the argument ip leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The… | |
| Aplazada | Alta (8.6) | 1.7% | — | Netcore Nbr200v2AI | 28/9/2026 | 28/9/2026 | A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. Affected is the function system of the file /usr/bin/network_tools of the component Tools Ping Handler. Performing a manipulation of the argument url results in os command injection. The attack can be initiated remotely. The exploit has been… | |
| Pendiente de análisis | Crítica (9.3) | 2.6% | — | Netcore Nbr200v2AI | 28/9/2026 | 28/9/2026 | A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function eval of the file /www/cgi-bin/network_tools of the component Web Management Interface. Such manipulation of the argument QUERY_STRING leads to os command injection. It is possible to launch the attack remotely. The exploit… | |
| Aplazada | Crítica (9.3) | 0.50% | — | Netcore Nbr100v2AI | 28/9/2026 | 1/10/2026 | A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /usr/share/rpcd/acl.d/unauthenticated.json of the component ACL Handler. This manipulation of the argument section causes missing authorization. It is possible to initiate the attack remotely. The… | |
| Aplazada | Alta (8.3) | 0.24% | — | Http4k-coreAI | 27/9/2026 | 30/9/2026 | http4k (Maven artifact org.http4k:http4k-core) before 6.48.0.0, 5.42.0.0, and 4.51.0.0 ships a BasicCookieStorage (client-side cookie store used by ClientFilters.Cookies) that does not enforce RFC 6265 scoping rules for the cookie domain, path, and Secure attributes. When a single BasicCookieStorage instance is used… | |
| Pendiente de análisis | Alta (8.1) | 0.32% | — | PulpcoreAI | 24/9/2026 | 1/10/2026 | A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file repository privileges to specify a local file URL for Pulp to download and store. A URL scheme validation check uses a string prefix comparison that only rejects URLs beginning with… | |
| Pendiente de análisis | Alta (7.1) | 0.29% | — | Redhat Automation-controllerAIAnsible-coreAI | 23/9/2026 | 24/9/2026 | — | |
| Aplazada | Alta (7.1) | 0.18% | — | Core WEB Vitals AND Pagespeed BoosterAI | 23/9/2026 | 23/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions. | |
| Pendiente de análisis | Baja (3.1) | 0.21% | — | Ansible-coreAI | 23/9/2026 | 24/9/2026 | — | |
| Aplazada | Crítica (9.3) | 0.54% | — | Orval CoreAI | 23/9/2026 | 23/9/2026 | orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape multipart property names in generated template literals. Attackers can inject ${...} expressions into OpenAPI schema property names that execute as live interpolation when the generated client… | |
| Aplazada | Alta (7.5) | 0.49% | — | Fasterxml Jackson-coreAI | 23/9/2026 | 24/9/2026 | UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults… |