Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
5113 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Baja (1.2) | 0.30% | 💥 PoC | Wikimedia MediasearchAI | 30/9/2026 | 1/10/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki MediaSearch extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki MediaSearch extension: 1.46, 1.45, and 1.43. | |
| Pendiente de análisis | Baja (1.1) | 0.29% | 💥 PoC | Wikimedia CommonsmetadataAI | 30/9/2026 | 1/10/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki CommonsMetadata extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki CommonsMetadata extension: 1.46, 1.45, and 1.43. | |
| Pendiente de análisis | Alta (7.4) | 0.33% | 💥 PoC | Wikimedia WikilambdaAI | 30/9/2026 | 6/10/2026 | Authorization bypass through User-Controlled key vulnerability in The Wikimedia Foundation MediaWiki WikiLambda extension allows Authentication Bypass. This issue affects MediaWiki WikiLambda extension: 1.46. | |
| Pendiente de análisis | Baja (1.2) | 0.30% | 💥 PoC | Wikimedia Page FormsAI | 30/9/2026 | 30/9/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Page_Forms extension allows Stored XSS. This issue affects MediaWiki Page_Forms extension: 1.46, 1.45, and 1.43. | |
| Pendiente de análisis | Baja (1.2) | 0.27% | 💥 PoC | Wikimedia PagetriageAI | 30/9/2026 | 30/9/2026 | Exposure of sensitive information through data queries vulnerability in The Wikimedia Foundation MediaWiki PageTriage extension allows Information Elicitation. This issue affects MediaWiki PageTriage extension: 1.46, 1.45, and 1.43. | |
| Pendiente de análisis | Baja (0.3) | 0.11% | — | Wikimedia WikbaseAI | 30/9/2026 | 30/9/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikbase extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki Wikbase extension: 1.46, 1.45, and 1.43. | |
| Pendiente de análisis | Baja (0.3) | 0.11% | — | Wikimedia WikistoriesAI | 30/9/2026 | 30/9/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikistories extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki Wikistories extension: 1.46, 1.45, and 1.43. | |
| Pendiente de análisis | Baja (1.1) | 0.30% | 💥 PoC | Wikimedia Reading ListsAI | 30/9/2026 | 30/9/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki ReadingLists extension allows Reflected XSS. This issue affects MediaWiki ReadingLists extension: 1.46 and 1.45. | |
| Pendiente de análisis | Baja (1.1) | 0.34% | — | Wikimedia WikiforumAI | 30/9/2026 | 30/9/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki WikiForum extension allows Stored XSS. This issue affects MediaWiki WikiForum extension: master. | |
| Pendiente de análisis | Baja (1.1) | 0.20% | — | Wikimedia Mediawiki CollectionAI | 30/9/2026 | 30/9/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Collection (Book) extension allows XSS Targeting Non-Script Elements. This issue affects MediaWiki Collection (Book) extension: 1.46, 1.45, and 1.43. | |
| Pendiente de análisis | Media (5.5) | 0.10% | — | Nvidia GPU Display DriverAI | 30/9/2026 | 30/9/2026 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode driver where a local user may access another process's GPU channel state due to missing authorization checks. A successful exploit of this vulnerability might lead to information disclosure. | |
| Pendiente de análisis | Media (5.5) | 0.10% | — | Nvidia GPU Display DriverAI | 30/9/2026 | 30/9/2026 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode driver where a local user may access another process's GPU channel state due to missing authorization checks. A successful exploit of this vulnerability might lead to information disclosure. | |
| Pendiente de análisis | Alta (7.1) | 0.11% | — | Nvidia GPU Display DriverAI | 30/9/2026 | 30/9/2026 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode driver where a local user can cause the driver to dereference an untrusted pointer. A successful exploit of this vulnerability might lead to denial of service and information disclosure. | |
| Pendiente de análisis | Alta (7.8) | 0.12% | — | Nvidia GPU Display DriverAI | 30/9/2026 | 1/10/2026 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel module DMA-BUF import path where an unprivileged local user could cause improper preservation of memory access permissions when importing a read-only buffer from another device's DMA-BUF exporter. A successful exploit of… | |
| Pendiente de análisis | Alta (7.8) | 0.13% | — | Nvidia GPU Display DriverAI | 30/9/2026 | 1/10/2026 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an error-handling path could operate on an improperly initialized resource. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information… | |
| Pendiente de análisis | Alta (7.8) | 0.11% | — | Nvidia GPU Display DriverAI | 30/9/2026 | 1/10/2026 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source kernel module where an unprivileged local user could cause improper preservation of memory access permissions during DMA mapping. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of… | |
| Pendiente de análisis | Alta (7) | 0.11% | — | Nvidia GPU Display DriverAI | 30/9/2026 | 1/10/2026 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source kernel module event delivery path where an unprivileged local user could cause a use-after-free through a race between asynchronous event delivery and file close. A successful exploit of this vulnerability might lead to code execution,… | |
| Pendiente de análisis | Alta (7.8) | 0.12% | — | Nvidia GPU Display DriverAI | 30/9/2026 | 1/10/2026 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel module Resource Server where an unprivileged local user could cause a use-after-free through a missing self-reference guard in the map cleanup path. A successful exploit of this vulnerability might lead to code… | |
| Pendiente de análisis | Alta (7) | 0.14% | — | Nvidia GPU Display DriverAI | 30/9/2026 | 30/9/2026 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user can write to read-only memory because the memory's permissions are not preserved. A successful exploit of this vulnerability might lead to code execution and escalation of privileges. | |
| Pendiente de análisis | Alta (7.8) | 0.11% | — | Nvidia GPU Display DriverAI | 30/9/2026 | 2/10/2026 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user can write to read-only memory because the memory's permissions are not preserved. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service,… | |
| Pendiente de análisis | Alta (7.8) | 0.12% | — | Nvidia GPU Display DriverAI | 30/9/2026 | 2/10/2026 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user may cause a use-after-free condition by issuing a sequence of driver commands. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, data tampering, and… | |
| Pendiente de análisis | Alta (7.8) | 0.13% | — | Nvidia GPU Display DriverAI | 30/9/2026 | 2/10/2026 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an unprivileged user can cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, and denial of service. | |
| Pendiente de análisis | Alta (7.8) | 0.13% | — | Nvidia GPU Display DriverAI | 30/9/2026 | 2/10/2026 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data… | |
| Pendiente de análisis | Alta (7.8) | 0.12% | — | Nvidia GPU Display DriverAI | 30/9/2026 | 2/10/2026 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could bypass read-only memory protection due to incorrect authorization, enabling write access to memory marked read-only. A successful exploit of this vulnerability might lead to code execution, denial of… | |
| Pendiente de análisis | Alta (7.8) | 0.12% | — | Nvidia GPU Display DriverAI | 30/9/2026 | 2/10/2026 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user may cause a use-after-free condition by issuing a sequence of driver commands. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, and information… |