Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
603 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.31% | — | Dell Command Update | 19/8/2026 | 21/8/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analizada | Alta (7.8) | 0.31% | — | Dell Command Update | 19/8/2026 | 21/8/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Aplazada | Crítica (9.8) | 0.34% | — | Epson Easymp Network UpdaterAI | 18/8/2026 | 9/9/2026 | Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20. The Epson projector can be updated by encrypted firmware through USB. | |
| Analizada | Alta (7.1) | 0.24% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability within the build API. This allows the user to provide a malicious URL, causing the Quay builder to make requests to internal network addresses. Such an… | |
| Analizada | Alta (7.5) | 0.42% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs without proper authorization. While file IDs are complex, they can be intercepted from plaintext email or webhook callbacks. This vulnerability leads to information disclosure,… | |
| Analizada | Alta (7.5) | 0.23% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted JSON requests to the `/webhooks/stripe` endpoint without validating the Stripe-Signature header. Successful exploitation can lead to the unauthorized… | |
| Analizada | Alta (8.2) | 0.46% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST requests to the security scanner notification endpoint. This allows the attacker to flood the notification queue and inject path traversal characters into Clair API URL paths.… | |
| Analizada | Media (4.4) | 0.33% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (UUID), can read the notification configuration, including sensitive details like webhook URLs, Slack tokens, and email addresses. This vulnerability also allows them to… | |
| Analizada | Media (6.5) | 0.31% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When an LDAP referral is returned during authentication, the system does not properly escape the username input. This allows an attacker to inject LDAP filter metacharacters, enabling user-existence oracle… | |
| Analizada | Media (5.4) | 0.29% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related to audience verification and the enforcement of `azp` and `sub` claims were identified. These flaws could allow an attacker with a validly-signed token from… | |
| Pendiente de análisis | Alta (7.3) | 0.18% | — | Lenovo System UpdateAI | 13/8/2026 | 24/8/2026 | A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated user to execute arbitrary code with elevated privileges. | |
| Aplazada | Crítica (9.8) | 0.86% | — | Wpmudev UpdatesAI | 12/8/2026 | 26/8/2026 | The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its remote management interface, nor protect those requests against replay, allowing an attacker able to obtain or replay a valid signed management request to install and execute arbitrary code (remote… | |
| Pendiente de análisis | Baja (3.7) | 0.40% | — | Zephyr UpdatehubAI | 10/8/2026 | 26/8/2026 | The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c leaks the CoAP/DTLS socket descriptor on its connection-setup failure paths. The shared error: cleanup gated socket closing on a ret > 0 flag, but ret was set to -1 immediately after the socket was created, so when… | |
| Pendiente de análisis | Alta (7.5) | 0.47% | — | Zephyr UpdatehubAI | 10/8/2026 | 26/8/2026 | The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_probe() in subsys/mgmt/updatehub/updatehub.c) parses the JSON metadata returned by the update server into a fixed two-level nested-array struct. After parsing it validates only the outer array length (objects_len != 2) and then dereferences… | |
| Pendiente de análisis | Baja (3.7) | 0.35% | — | Zephyr UpdatehubAI | 10/8/2026 | 26/8/2026 | The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c contains an out-of-bounds / uninitialized-memory read in z_impl_updatehub_probe(). The probe response from the UpdateHub server is copied into a heap buffer (metadata) that is correctly NUL-terminated, but a second buffer (metadata_copy) is allocated with… | |
| Aplazada | Media (5.3) | 0.37% | — | Npm-check-updatesAI | 10/8/2026 | 24/9/2026 | npm-check-updates through 23.0.2, fixed in commit b554b84, contains a terminal escape sequence injection vulnerability that allows an attacker to embed arbitrary terminal control characters in a dependency's package.json homepage or repository URL fields. When a developer runs ncu with the --format homepage or… | |
| Aplazada | Baja (2) | 0.48% | — | DiscourseAIDiscourse-local-datesAI | 10/8/2026 | 8/9/2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse-local-dates plugin rendered crafted local-date format data as HTML on sites with a modified or disabled default Content Security Policy. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and… | |
| Aplazada | Alta (7.2) | 0.46% | — | Order Delivery DateAI | 6/8/2026 | 12/8/2026 | Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions. | |
| Aplazada | Alta (7.1) | 0.16% | — | Razer RzupdateserviceAI | 3/8/2026 | 12/8/2026 | A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionality of the file C:\Program Files (x86)\Razer\RzUpdateEngineService\RzUpdateService.exe of the component Named Pipe Handler. Executing a manipulation of the argument lpThreadParameter can lead to… | |
| Aplazada | Alta (8.8) | 0.21% | — | Prestashop TotadministrativemandateAI | 31/7/2026 | 31/8/2026 | PrestaShop module, totadministrativemandate <1.8.1 is vulnerable to Cross Site Request Forgery (CSRF). The payment validation controller has no CSRF token. An attacker can confirm an order in an awaiting status by hijacking a link. | |
| Aplazada | Alta (7.5) | 0.63% | — | Perl Date ManipAI | 30/7/2026 | 2/9/2026 | Date::Manip versions through 7.00 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time. _parse_time removes a time from anywhere in the string with the unanchored substitution `s/$timerx/ /`, where $timerx is an auto-generated alternation of time patterns reached… | |
| Aplazada | Alta (7.5) | 0.63% | — | Date ManipAI | 30/7/2026 | 2/9/2026 | Date::Manip versions through 7.00 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check. The parse regexes capture year, month and day with the `\d` shorthand, which on a character string matches the whole Unicode decimal digit property `\p{Nd}` and not just `[0-9]`.… | |
| Aplazada | Alta (7.8) | 0.84% | — | Tubitak Bilgem Pardus-updateAI | 23/7/2026 | 23/7/2026 | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-update allows OS Command Injection. This issue affects pardus-update: from 0.6.6 before 0.7.0. | |
| Aplazada | Alta (7.5) | 0.63% | — | Http DateAI | 17/7/2026 | 12/8/2026 | HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date. parse_date() matches the date string against a chain of alternative regexes, and str2time() delegates to it. Several of these patterns place unbounded quantifiers next to each other before a trailing `\s*$`… | |
| Aplazada | Media (5.9) | 0.15% | — | ABB KNX Update ToolAIBJE KNX Update ToolAI | 17/7/2026 | 17/7/2026 | Missing support for integrity check vulnerability in ABB KNX Update Tool (ABB), ABB KNX Update Tool (BJE). This issue affects KNX Update Tool (ABB): through 2.0.175; KNX Update Tool (BJE): through 2.0.175. |