Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
396 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.44% | — | Simplemachines ForumAI | 14/7/2026 | 15/7/2026 | Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery vulnerability in the image proxy that allows authenticated attackers to trigger internal HTTP requests by embedding attacker-controlled URLs in BBCode image tags, which the proxy fetches without… | |
| Modificada | Alta (8.8) | 0.50% | — | Microsoft Azure Connected Machine Agent | 14/7/2026 | 18/8/2026 | Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges over an adjacent network. | |
| Aplazada | Baja (2) | 0.12% | — | Suse Virtual Machine Driver PackAI | 14/7/2026 | 29/9/2026 | A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in SUSE Virtual Machine Driver Pack allows an attacker with the ability to modify the registry to affect the integrity of the driver. We're not aware of a feasible way to exploit this currently. This issue affects Virtual Machine… | |
| Aplazada | Alta (7.5) | 1.5% | — | LibreofficeAIThecodingmachine GotenbergAI | 10/7/2026 | 13/7/2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.34.0, Gotenberg's /forms/libreoffice/convert endpoint allows a specially crafted document to cause LibreOffice to automatically retrieve external HTTP(S) resources and local file resources during document conversion, enabling blind SSRF and limited… | |
| Aplazada | Alta (7.1) | 0.47% | — | Simplemachines ForumAI | 10/7/2026 | 14/7/2026 | Simple Machines Forum 2.1 prior to commit 7d048f8 and 3.0 prior to commit a7875e8 contains an authorization bypass vulnerability in Sources/Actions/AttachmentApprove.php where a single-character operator error causes the permission check to always pass regardless of user permissions. An authenticated low-privileged… | |
| Analizada | Alta (8.8) | 0.36% | — | UI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition FirmwareUI Unifi Dream Machine PRO MAX FirmwareUI Unifi Dream Machine Beast Firmware+15 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi OS with UniFi Protect Application to escalate privileges on the host device. | |
| En análisis | Media (6.1) | 0.27% | — | UI Unifi OS ServerUI Unifi Dream Machine Beast FirmwareUI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition Firmware+26 | 2/7/2026 | 9/7/2026 | A malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharing (CORS) misconfiguration found in UniFi OS to trigger actions in UniFi OS using that user's session. | |
| Analizada | Alta (8.8) | 0.49% | — | UI Unifi Dream Machine Beast FirmwareUI Enterprise Fortress Gateway FirmwareUI Unifi Dream Router FirmwareUI Unifi Dream Wall Firmware+28 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi OS to escalate privileges within such UniFi OS devices or instances. | |
| Analizada | Alta (8.6) | 0.77% | — | UI Unifi OS ServerUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition Firmware+28 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to bypass authentication of such UniFi OS devices or instances. | |
| Analizada | Alta (8.8) | 1.8% | — | UI Unifi OS ServerUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition Firmware+28 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device. | |
| Analizada | Alta (8.8) | 0.43% | — | UI Unifi OS ServerUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO FirmwareUI Unifi Dream Machine Special Edition Firmware+28 | 2/7/2026 | 10/7/2026 | A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such UniFi OS devices or instances. | |
| Analizada | Alta (8.8) | 0.76% | — | Broadcom Spring Statemachine | 23/6/2026 | 22/9/2026 | Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to remote code execution inside the application JVM. Affected versions: Spring… | |
| Modificada | Alta (8.3) | 0.30% | — | Redhat Openshift Container PlatformRedhat Windows Machine Config Operator | 22/6/2026 | 9/9/2026 | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An adjacent-network attacker who can intercept or redirect WMCO's SSH session can capture WICD and kubelet… | |
| Modificada | Alta (8.8) | 0.11% | — | Redhat Openshift Container PlatformRedhat Windows Machine Config Operator | 22/6/2026 | 9/9/2026 | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows… | |
| Modificada | Crítica (9.3) | 1.4% | — | Fgmacedo Python Statemachine | 17/6/2026 | 28/8/2026 | Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary code by supplying malicious SCXML documents containing crafted `<data expr="...">` attributes evaluated unsafely. The SCXMLProcessor passes attacker-controlled expression strings… | |
| Aplazada | Alta (7.3) | 0.19% | — | NomachineAI | 10/6/2026 | 7/7/2026 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Nomachine allows Argument Injection.This issue affects Nomachine: before 9.5.7, before 8.23.2. | |
| Analizada | Alta (7.7) | 0.59% | — | UI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+27 | 22/5/2026 | 23/7/2026 | A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to obtain sensitive information. | |
| Analizada | Crítica (10) | 46% | ⚠ Explotación activa | UI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+27 | 22/5/2026 | 23/7/2026 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection. | |
| Analizada | Crítica (10) | 1.8% | ⚠ Explotación activa | UI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+28 | 22/5/2026 | 23/7/2026 | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account. | |
| Analizada | Crítica (10) | 15% | ⚠ Explotación activa | UI Unifi OS ServerUI Unifi Cloud Gateway Industrial FirmwareUI Unifi Dream Machine FirmwareUI Unifi Dream Machine PRO Firmware+27 | 22/5/2026 | 23/7/2026 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system. | |
| Analizada | Media (6.8) | 0.20% | — | Schneider-electric Ecostruxure Machine Expert Hvac | 14/5/2026 | 17/6/2026 | CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result in revealing protected source code and loss of confidentiality, When an authorized attacker accesses the source code for editing or compiling it. | |
| Analizada | Media (5.9) | 0.36% | — | Thecodingmachine Gotenberg | 14/5/2026 | 17/6/2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the /forms/chromium/convert/url and /forms/chromium/screenshot/url routes accept url=file:///tmp/... from anonymous callers. The default Chromium deny-list intentionally exempts file:///tmp/ so HTML/Markdown routes can load their own… | |
| Analizada | Crítica (9.4) | 1.8% | — | Thecodingmachine Gotenberg | 14/5/2026 | 17/6/2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, the default deny-lists used by Gotenberg's downloadFrom feature and webhook feature are bypassable. Because the filter is regex-based and case-sensitive, an unauthenticated attacker can supply URLs such as http://[::ffff:127.0.0.1]:... and… | |
| Analizada | Alta (8.6) | 0.42% | — | Thecodingmachine Gotenberg | 14/5/2026 | 17/6/2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, Gotenberg's Chromium URL-to-PDF endpoint (/forms/chromium/convert/url) has no default protection against HTTP/HTTPS-based SSRF. The default deny-list regex only blocks file:// URIs. An unauthenticated attacker can point Chromium at any… | |
| Analizada | Alta (7.5) | 0.38% | — | Thecodingmachine Gotenberg | 14/5/2026 | 17/6/2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the webhook middleware spawns a goroutine that holds a reference to the request's echo.Context after the synchronous handler returns ErrAsyncProcess and Echo recycles the context back to its sync.Pool. When a concurrent request claims the… |