Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
–

583 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.7)0.51%—Internlm Lmdeploy21/7/202617/9/2026
LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _load_http_url function within the connection.py media handler, where the private-IP guard validates only the original URL without re-validating hosts after HTTP redirects. An unauthenticated attacker…
AnalizadaMedia (6.5)0.38%—Hcltechsw HCL Devops DeployHcltechsw HCL Launch9/7/202613/7/2026
HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system.
AnalizadaMedia (5.5)0.15%—Hcltechsw HCL Devops DeployHcltechsw HCL Launch9/7/202610/7/2026
HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure. The application stores potentially sensitive information in log files that could be read by a local user.
AnalizadaAlta (7.5)0.26%—Hcltechsw HCL Devops Deploy9/7/202610/7/2026
HCL DevOps Deploy uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains.
Pendiente de análisisCrítica (9.3)0.22%—Cloudfoundry UAAAICloudfoundry Cf-deploymentAI9/7/20269/7/2026
A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate from any trusted CA, then harvest the LDAP bind password and every end-user password sent during simple-bind authentication, and return forged group memberships that grant themselves admin scopes. This…
ModificadaMedia (5.5)0.14%—IBM Devops DeployIBM Urbancode Deploy30/6/202630/7/2026
IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 IBM DevOps Deploy stores potentially sensitive information in log files that could be read by a local user.
AnalizadaMedia (6.5)0.38%—IBM Devops DeployIBM Urbancode Deploy30/6/20262/7/2026
IBM UCD - IBM UrbanCode Deploy 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 IBM DevOps Deploy could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system.
AnalizadaAlta (7.5)0.26%—IBM Devops Deploy30/6/20262/7/2026
IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains.
AnalizadaMedia (4.3)0.30%—Hcltechsw HCL Devops DeployHcltechsw HCL Launch29/6/20262/7/2026
HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This exposure could allow an attacker with access to the logs to potentially obtain sensitive values related to that step.
AplazadaAlta (7.3)0.18%—Papercut Print Deploy ClientAI22/6/202623/6/2026
An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows. The application, which typically operates with high-level system privileges, attempts to perform an internal validation check by invoking a secondary system utility using an…
Pendiente de análisisCrítica (9)0.16%—Cloudfoundry UAAAICloudfoundry CF DeploymentAI11/6/202617/6/2026
Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) in two SAML flows: the OAuth 2.0 SAML2 bearer grant (token endpoint) and browser SSO (ACS) when wantAssertionSigned is set to false. Assertions or…
AplazadaAlta (7.8)0.43%—Internlm LmdeployAI10/6/202631/8/2026
LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, hardcoded "trust_remote_code=True" enables HF supply-chain RCE without user opt-in. Version 0.13.0 patches the issue.
AplazadaAlta (7.8)0.20%—Internlm LmdeployAI10/6/202623/7/2026
LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, LMDeploy is vulnerable to arbitrary code execution through hardcoded "trust_remote_code=True" in multiple HuggingFace model-loading call sites. At time of publication, there are no publicly available…
AplazadaBaja (2)0.07%—Paddlepaddle FastdeployAI4/6/202622/7/2026
A weakness has been identified in PaddlePaddle FastDeploy up to 2.4.1. Affected by this issue is the function hash_features of the file fastdeploy/multimodal/hasher.py of the component MultimodalHasher. Executing a manipulation can lead to use of weak hash. The attack requires local access. A high complexity level is…
Pendiente de análisisCrítica (10)0.46%—Cloudfoundry UAAAICloudfoundry CF DeploymentAI1/6/202622/7/2026
Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vulnerability where EC (Elliptic Curve) private keys are inadvertently exposed through the public /token_keys endpoint. This endpoint is designed to provide public key material for JWT token…
Pendiente de análisisAlta (8.1)0.42%—Cloudfoundry Diego-releaseAICloudfoundry Smb-volume-releaseAICloudfoundry CF DeploymentAI1/6/202622/7/2026
Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF space developer to inject arbitrary kernel CIFS mount options via bypassing the mount-option allowlist, enabling privilege escalation and security control bypass on multi-tenant Diego cells. Affected…
Pendiente de análisisCrítica (9.9)0.44%—Fleet Helm DeployerAI13/5/202617/6/2026
Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo`.
Pendiente de análisisBaja (3.4)0.18%—SAP Hdi-deployAI12/5/202617/6/2026
SQL injection vulnerability exists in @sap/hdi-deploy package, where SQL queries are dynamically constructed using user input without proper parameterization or prepared statements. Successful exploitation could allow the high privileged users to alter the SELECT statements impacting confidentiality and availability…
AnalizadaMedia (5)0.20%—Cloudfoundry Cf-deploymentCloudfoundry Routing Release1/5/202617/6/2026
Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with access to Cloudfoundry could configure a route-service that would allow it to send requests to HTTP services on internal networks reachable by the Gorouter,…
AnalizadaAlta (7.5)1.5%—Internlm Lmdeploy20/4/202617/6/2026
LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions prior to 0.12.3 have a Server-Side Request Forgery (SSRF) vulnerability in LMDeploy's vision-language module. The `load_image()` function in `lmdeploy/vl/utils.py` fetches arbitrary URLs without validating internal/private IP…
Pendiente de análisisAlta (8.6)0.36%—Cloudfoundry UAAAICloudfoundry CF DeploymentAI17/4/202617/6/2026
Cloud Foundry UUA is vulnerable to a bypass that allows an attacker to obtain a token for any user and gain access to UAA-protected systems. This vulnerability exists when SAML 2.0 bearer assertions are enabled for a client, as the UAA accepts SAML 2.0 bearer assertions that are neither signed nor encrypted. This…
Pendiente de análisisAlta (7.5)0.20%—Cloudfoundry Capi ReleaseAICloudfoundry CF DeploymentAI17/3/202617/6/2026
Unprotected internal endpoints in Cloud Foundry Capi Release 1.226.0 and below, and CF Deployment v54.9.0 and below on all platforms allows any user who has bypassed the firewall to potentially replace droplets and therefore applications allowing them to access secure application information.
AnalizadaAlta (8.8)0.61%—Vitodeploy Vito6/3/202617/6/2026
Vito is a self-hosted web application that helps manage servers and deploy PHP applications into production servers. Prior to version 3.20.3, a missing authorization check in workflow site-creation actions allows an authenticated attacker with workflow write access in one project to create/manage sites on servers…
ModificadaMedia (6.5)0.23%—Cloudfoundry Cf-deploymentCloudfoundry Uaa-release5/3/202617/6/2026
Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.30.0 to v78.7.0 and in Cloudfoundry Deployment v48.7.0 to v54.10.0.
AnalizadaAlta (7.8)1.1%—Bleon-ethical Api-gateway-deploy24/2/202617/6/2026
bleon-ethical/api-gateway-deploy provides API gateway deployment. Version 1.0.0 is vulnerable to an attack chain involving OS Command Injection and Privilege Escalation. This allows an attacker to execute arbitrary commands with root privileges within the container, potentially leading to a container escape and…