Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
1458 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.62% | — | Dell Openmanage Server Administrator | 17/9/2026 | 6/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. | |
| Analizada | Crítica (9.8) | 0.95% | — | Dell Openmanage Server Administrator | 17/9/2026 | 1/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. | |
| Analizada | Crítica (9.8) | 0.53% | — | Dell Openmanage Server Administrator | 17/9/2026 | 1/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. | |
| Analizada | Media (5.5) | 0.11% | — | Dell Openmanage Server Administrator | 17/9/2026 | 1/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Denial of service. | |
| Analizada | Crítica (9.8) | 0.21% | — | Dell Openmanage Server Administrator | 17/9/2026 | 1/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analizada | Alta (7.8) | 0.15% | — | Dell Openmanage Server Administrator | 17/9/2026 | 1/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Media (6.5) | 0.17% | — | Dell Openmanage Server Administrator | 17/9/2026 | 1/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. | |
| Analizada | Alta (7.5) | 0.15% | — | Dell Openmanage Server Administrator | 17/9/2026 | 1/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Analizada | Alta (7.5) | 0.37% | — | Dell Openmanage Server Administrator | 17/9/2026 | 6/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. | |
| Pendiente de análisis | Alta (8.8) | 0.16% | — | Avast Sandbox Minifilter DriverAI | 16/9/2026 | 17/9/2026 | Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file isolation and escalate to SYSTEM. When the sandbox virtualizes a file it copies the original security descriptor, but the driver opened… | |
| Aplazada | Media (6.9) | 0.38% | — | Miniorange JWT Authentication FOR WP Rest ApisAI | 15/9/2026 | 24/9/2026 | miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured authentication by supplying a specific GET parameter without any capability check or nonce verification.… | |
| Pendiente de análisis | Alta (7.7) | 0.52% | — | Google Cloud Gemini Enterprise Agent Platform SDK FOR PythonAI | 15/9/2026 | 21/9/2026 | Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft. | |
| Pendiente de análisis | Alta (8.7) | 0.27% | — | Google Cloud Gemini Enterprise Agent Platform APP BuilderAIGoogle Cloud PlatformAIGoogle Compute EngineAI | 11/9/2026 | 11/9/2026 | A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token. This vulnerability was patched on 01 June 2026. Users… | |
| Aplazada | Alta (8.1) | 0.45% | — | Geminilabs Site ReviewsAI | 10/9/2026 | 10/9/2026 | The Site Reviews WordPress plugin before 8.3.0 does not prevent request data from being deserialized, and derives the key protecting that data by padding out the site's WordPress nonce key, which makes the key publicly computable on installs where that key is absent, left at its sample value, or too short to be… | |
| Aplazada | Alta (7.5) | 0.32% | — | Miniorange 2FAAI | 10/9/2026 | 10/9/2026 | The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not scope its second-factor attempt limit to the account being attacked, keying it instead to an identifier the client supplies and can change at will, allowing an attacker who already knows a victim's password to make… | |
| Aplazada | Crítica (10) | 0.44% | — | Miniorange 2FAAI | 10/9/2026 | 10/9/2026 | The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visitor to delete arbitrary options, which can lock every administrator out of the… | |
| Pendiente de análisis | Alta (7.7) | 0.38% | — | Gemini CLIAIGemini CLI Github ActionAI | 10/9/2026 | 23/9/2026 | A vulnerability in the Gemini CLI prior to version 0.39.1 allows attackers to achieve arbitrary code execution by tricking a victim into starting the CLI within an untrusted directory. The vulnerability is triggered via untrusted .env files overriding GEMINI_CLI_HOME to load malicious configuration files and bypass… | |
| Analizada | Media (5.3) | 0.33% | — | Miniorange Ldap / Active Directory Integration | 2/9/2026 | 16/9/2026 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1. | |
| Aplazada | Alta (8.1) | 0.38% | — | Miniorange Oauth Single Sign ONAI | 2/9/2026 | 3/9/2026 | The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its Steam single sign-on flow, allowing unauthenticated attackers to log in as an arbitrary non-administrator user, and to create new accounts. | |
| Aplazada | Alta (8.8) | 0.54% | — | JoomlaAIMinirange ExtensionsAI | 31/8/2026 | 8/9/2026 | Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension deinstallation via various miniOrange extensions - a missing authentication check allows unauthenticated actors to delete arbitrary installed extensions. Only the free versions of the miniOrange plugins are affected. | |
| Aplazada | Alta (7.5) | 0.41% | — | Miniorange Saml SSOAI | 29/8/2026 | 31/8/2026 | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 5.4.6. This is due to the mo_saml_login_validate() ACS handler persisting the X.509 certificate extracted from an incoming SAMLResponse into the mo_saml_required_certificate option before… | |
| Pendiente de análisis | Crítica (9.9) | 0.29% | — | IBM Administration Runtime Expert FOR IAIIBM Application Runtime Expert FOR IAI | 28/8/2026 | 31/8/2026 | IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining… | |
| Pendiente de análisis | Alta (7.5) | 0.43% | — | IBM Administration Runtime Expert FOR IAI | 28/8/2026 | 1/9/2026 | IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement. | |
| Aplazada | Crítica (9.3) | 0.41% | — | DJI NEOAIDJI NEO 2AIDJI FlipAIDJI AIR 3AI+12 | 27/8/2026 | 28/8/2026 | DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticated users to upload files without limits on file size, file count, or total storage consumed in **/blackbox/upgrade/**, as well as overwrite existing files in that directory. An attacker with access to… | |
| Aplazada | Media (5.3) | 0.48% | — | Reachy MiniAI | 25/8/2026 | 9/9/2026 | Reachy Mini is an SDK for controlling Reachy Mini robots. Prior to 1.8.2, the Reachy Mini daemon exposes the /api/media/sounds/upload endpoint implemented by the upload_sound method in src/reachy_mini/daemon/app/routers/media.py without authentication, file-extension checks, content validation, or size validation. The… |