Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1792 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.1) | 0.30% | — | Netgate PfsenseAIPfblockerngAI | 25/9/2026 | 30/9/2026 | Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows an attacker to execute arbitrary code via the pfBlockerNG package | |
| Pendiente de análisis | Alta (8.5) | 1.0% | — | Netgate Pfsense PlusAINetgate Pfsense CEAI | 25/9/2026 | 30/9/2026 | In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data handling allows an authenticated attacker to execute arbitrary PHP code. To exploit this, an attacker with privileges to modify Dashboard settings and write… | |
| Aplazada | Alta (8.7) | 0.29% | — | Hfs2AI | 24/9/2026 | 24/9/2026 | HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by sending a single crafted request. Attackers can trigger a hung serving thread that enters a busy loop, rendering the entire file server unresponsive… | |
| Aplazada | Crítica (10) | 0.32% | — | Rejetto HFSAI | 24/9/2026 | 24/9/2026 | HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside the shared folder. Attackers can exploit the macro dispatcher's lack of… | |
| Aplazada | Crítica (10) | 0.78% | — | Hfs2AI | 24/9/2026 | 29/9/2026 | HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename. Attackers can craft a filename containing a closing template quoting sequence followed… | |
| Pendiente de análisis | Alta (8.6) | 1.7% | — | Zohocorp Manageengine Adselfservice PlusAI | 22/9/2026 | 22/9/2026 | Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API. | |
| Pendiente de análisis | Crítica (9.8) | 4.6% | — | Zohocorp Manageengine Adselfservice PlusAI | 22/9/2026 | 23/9/2026 | Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client. | |
| Pendiente de análisis | Media (6.8) | 0.15% | — | WinfspAI | 18/9/2026 | 22/9/2026 | WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in the kernel driver's Fast I/O device control handler that fails to validate the volume context before use. An unprivileged local user can trigger a denial of service by opening the WinFsp control device and issuing FSP_IOCTL_TRANSACT… | |
| Pendiente de análisis | Alta (7) | 0.17% | — | Gnome GvfsAI | 10/9/2026 | 1/10/2026 | A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race… | |
| Analizada | Media (6.7) | 0.53% | — | Dell Powerscale Onefs | 9/9/2026 | 16/9/2026 | Dell PowerScale OneFS, Versions 9.5.0.0 through 9.7.1.0, Versions 9.8.0.0 through 9.10.1.0, and Versions 9.11.0.0 through 9.14.0.1, contain a command injection vulnerability. An admin privileged local attacker could potentially exploit this vulnerability, leading to elevation of privileges to root, impacting… | |
| Analizada | Baja (3.5) | 0.18% | — | Dell Powerscale Onefs | 9/9/2026 | 16/9/2026 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.7.1.15, versions 9.8.0.0 through 9.13.1.0, and versions prior to 9.15.0.0, contain an Incorrect Authorization vulnerability. A low privileged adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized modification of system logs. | |
| Analizada | Media (5.4) | 0.39% | — | Dell Powerscale Onefs | 9/9/2026 | 16/9/2026 | Dell PowerScale OneFS versions 9.12.0.0 through 9.13.1.0 contain an Insecure Temporary File vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to denial of service and information tampering. | |
| Pendiente de análisis | Media (5.1) | 0.44% | — | Amazon EFS CSI DriverAI | 4/9/2026 | 8/9/2026 | Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with PersistentVolume creation privileges to cause recursive deletion of directories on an EFS filesystem they are not authorized to access, via a… | |
| Aplazada | Media (5.4) | 0.50% | — | Netgate Pfsense PlusAINetgate Pfsense CEAI | 4/9/2026 | 14/9/2026 | Cross Site Scripting vulnerability in Netgate pfSense Plus software versions <= 26.03 pfSense CE software versions <= 2.8.1 allows a remote attacker to execute arbitrary code via the captive_portal_status.widget.php file | |
| Aplazada | Media (5.4) | 0.28% | — | Netgate Pfsense PlusAINetgate Pfsense CEAI | 4/9/2026 | 9/9/2026 | Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1) allows remote authenticated attackers to inject arbitrary JavaScript via malicious content in an RSS feed title. The injected script executes in the browser of any authenticated… | |
| Pendiente de análisis | Media (5.1) | 1.1% | — | Pfsense PlusAIPfsense CEAI | 3/9/2026 | 9/9/2026 | pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Schedules: Edit privilege to inject arbitrary JavaScript via the descr parameter in /firewall_schedule_edit.php. The schedule description is stored without HTML sanitization and subsequently inserted into an HTML attribute value… | |
| Pendiente de análisis | Media (5.1) | 1.1% | — | Pfsense PlusAIPfsense CEAI | 3/9/2026 | 9/9/2026 | pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Rules: Edit privilege to inject arbitrary JavaScript via the descr parameter in /firewall_rules_edit.php. The firewall rule description is stored in the pfSense XML configuration with only backslash-escaping applied and no HTML… | |
| Pendiente de análisis | Media (5.1) | 1.1% | — | Pfsense PlusAIPfsense CEAI | 3/9/2026 | 9/9/2026 | pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Status: Monitoring privilege to inject arbitrary JavaScript via graph configuration parameters in /status_monitoring.php. Multiple POST parameters including graph-left, graph-right, time-period, resolution, start-date, end-date,… | |
| Pendiente de análisis | Media (4.3) | 0.22% | — | Gnome GvfsAI | 1/9/2026 | 2/9/2026 | A flaw was found in the MTP backend in gvfs. When reading a file from a mounted MTP device, do_read() in gvfsbackendmtp.c trusts the data length returned by the device without limiting it to the original size requested by the client. If a malicious MTP device responds with more bytes than requested, this unrestricted… | |
| Pendiente de análisis | Media (6.5) | 0.45% | — | Gnome GvfsAI | 1/9/2026 | 4/9/2026 | A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the pre-sized reply buffer, causing the operation to access past the… | |
| Pendiente de análisis | Media (4.3) | 0.37% | — | Gnome GvfsAI | 1/9/2026 | 2/9/2026 | A flaw was found in the SFTP backend in gvfs. When mounting a share, a malicious SFTP server can cause read_string() to allocate a buffer with a certain length but the function does not verify that the buffer is completely filled, leaving the remainder of the buffer containing uninitialized heap contents. If the… | |
| Aplazada | Alta (8.8) | 0.57% | — | FS PosterAI | 1/9/2026 | 1/9/2026 | The FS-Poster plugin for WordPress is vulnerable to Remote Code Execution in versions up to and including 8.0.1. This is due to insufficient input sanitization of the FFmpeg path parameter before passing it to the exec() function, combined with missing authorization checks on the REST API endpoints. This makes it… | |
| Pendiente de análisis | Alta (8.8) | 0.36% | — | Gnome GvfsAI | 1/9/2026 | 1/10/2026 | A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to… | |
| Aplazada | Media (5.3) | 0.38% | — | Nasa CFSAI | 30/8/2026 | 1/9/2026 | A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c of the component cFE Software Bus. Performing a manipulation of the argument TotalMsgSize/HdrSize results in integer underflow. It is… | |
| Aplazada | Media (5.3) | 0.38% | — | Nasa CFSAINasa SBN TCP ModuleAI | 30/8/2026 | 1/9/2026 | A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/protocol/tcp/fsw/src/sbn_tcp_if.c of the component SBN TCP Module. Such manipulation of the argument MsgSz leads to buffer overflow. The attack must be carried out from within the local network. The vendor was… |